The GenAI Governance Maturity Model
Five levels across three domains, for organisations that need to know where their generative-AI governance actually stands — and what the next stage would require.
Five levels across three domains, for organisations that need to know where their generative-AI governance actually stands — and what the next stage would require.
Most organisations govern generative AI the way they govern a procurement risk: a policy is written, a committee reviews it, and the document is filed. The model described here starts from the observation that this does not work, and cannot, because the thing being governed does not hold still.
Generative systems are emergent. Their capabilities change between releases, their failure modes are discovered in use rather than in specification, and the uses employees find for them are not the uses that were approved. A static control written against last quarter's system governs a system that no longer exists.
The paper's argument is that governance must therefore become an organisational capability that adapts — what it calls a shift from static control to reflexive capability — and that capability, like any other, has stages of development that can be described and assessed.
This page summarises the model. It is not the paper; the paper is linked above and is the citable source. It is also honest about what the model does not yet contain — see the open work.
The model divides governance into three domains that are usually run by different people, in different parts of an organisation, who rarely meet. Naming them separately is most of the model's practical value, because it makes visible which one an organisation has neglected.
Model Stewardship — technical oversight across the whole lifecycle, from acquisition to retirement. Due diligence before adoption, model cards and datasheets, governance of fine-tuning with domain experts in the process rather than consulted afterwards, and regular audits and performance monitoring once a system is live.
Operational Alignment — governance where the work actually happens. Explicit protocols for human–AI interaction, feedback loops strong enough to surface drift and staff concern, transparency about where a system is in use, and critical AI literacy across the workforce rather than in a specialist pocket of it.
Strategic Guardrails — the institutional layer. Dedicated bodies with real mandates — ethics review boards, AI use councils — bias detection, what the paper calls trajectory alignment (anticipating how a deployed capability will evolve rather than only what it does today), and engagement with customers, regulators and civil society.
The paper is direct about why all three are needed: "Governance cannot be confined to an ethics committee. It must be an enterprise-wide, multi-layered concern, encompassing the technical, organizational, and institutional levels."
Each domain matures through the same five stages.
Five levels across three domains. The paper describes the levels and the domains separately; what distinguishes, say, a Level 3 Model Stewardship practice from a Level 3 Strategic Guardrail is not yet written down. That gap is the open work.
Level 1 — Ad hoc / experimental. The paper calls this the "Wild West" stage: experimentation is scattered and uncoordinated, happening in isolated pockets. There is no formal governance, no central model inventory, and most employees are unaware that an acceptable-use policy exists. It permits genuine creativity, and it carries hidden risk — data leakage and reputational exposure that nobody is positioned to notice.
Level 2 — Awareness / initiation. The organisation begins to recognise that generative AI carries strategic and ethical weight. Effort is real but fragmented: draft policies, informal working groups, the beginnings of a model registry that is probably incomplete. Discussions stay siloed in legal, IT or ethics, which is why they rarely change what anyone does.
Level 3 — Defined / developing. Chaos begins to give way to order. Core policies are formalised and communicated, approval workflows exist for new models, and the first human-in-the-loop protocols appear alongside practical instruments — bias audits, early monitoring dashboards. Coverage is uneven, concentrated on a few high-risk use cases while the rest of the estate runs ungoverned.
Level 4 — Managed / integrated. The paper locates the real transformation here. Governance stops being a set of documents and becomes embedded in work processes: mandatory AI literacy training, enterprise platforms with governance built in rather than bolted on. It stops reading as a bureaucratic hurdle and starts functioning as a source of competitive advantage and resilience.
Level 5 — Optimized / reflexive. Governance becomes predictive rather than merely adaptive, and sits in the organisation's culture and strategy rather than in its policy library. Governance sandboxes, red teaming, governance-by-design, and active participation in shaping public AI policy. The paper names the end state epistemic coherence — a condition in which an organisation's understanding of what its AI can do, what it believes is right, and how it actually controls the system stay aligned as all three change.
Cutting across the domains and levels are four capabilities that deepen as an organisation matures.
Score the three domains separately, and expect them to disagree. The common pattern in mid-sized organisations is Level 3 Model Stewardship — because IT owns it, and IT is used to lifecycle discipline — alongside Level 1 Operational Alignment, because nobody owns what staff actually do with these tools day to day. An organisation reporting a single overall maturity number has usually averaged away the finding.
Two cautions worth stating plainly. A level is a description, not a target: Level 5 is not the right answer for every organisation, and a small firm with three approved use cases may be correctly and permanently at Level 3. And a maturity rating is a claim like any other. Ours is that a claim without a measured baseline underneath it is not evidence — which applies to governance maturity exactly as it applies to the return on an automation project.
The paper describes five levels and three domains, and states that the four capabilities map across both. It does not contain a completed matrix: there is no per-cell description of what Level 2 Operational Alignment looks like as distinct from Level 2 Model Stewardship.
That distinction is what would turn a conceptual model into an assessable instrument, and writing it is applied work rather than theoretical work — it requires observing real organisations at each stage in each domain and recording what actually distinguishes them. It is the natural next piece of research for an applied centre, and it is the piece the Foundation intends to publish.
Until it exists, this model is a diagnostic vocabulary rather than a scoring rubric. That is a real limitation and we would rather state it than let the shape of the grid imply a precision the source does not support.
Published by the CCAIE Foundation, the non-commercial arm of the Canadian Center for AI Entrepreneurship. The Foundation holds academic partnerships, applied research, and published frameworks, and takes no commercial engagements. Where a framework published by the Foundation is implemented by a commercial supplier — including suppliers in which the Foundation's director has an interest — that relationship is disclosed on the face of the document.