Level 1 — Experiment
Individuals use external tools and local sandboxes without defined data ownership, economics or rules. Inventory use cases and stop uncontrolled sensitive-data transfer first.
Level 2 — Governed pilot
One bounded use case has an owner, data set and success criteria. Build a reproducible environment, version registry and regression suite next.
Level 3 — Repeatable service
Deployment is automated, data is classified, RAG and models are versioned, and actions are logged. Several teams can reuse the pattern. Add shared platform controls, budgets and support.
Level 4 — Platform
Teams receive standard hosting, model access, observability, evaluation and safe tools. Providers are compared against the same tests. Move to portfolio-level value and risk decisions.
Level 5 — Adaptive system
Cost, quality, risk and process impact are visible in production. Model changes trigger tests and critical deviation moves the service to a safe mode.
Five assessment axes
- Data: permission, quality, provenance, refresh and deletion.
- Compute: capacity, hosting, resilience and cost.
- Quality: reference sets, regression, human review and feedback.
- Security: identity, tool access, logs and incidents.
- Operations: owners, versions, monitoring, support and provider substitution.
Assess each use case separately, then improve the weakest axis that limits a safe release.

