Skip to main content
All resources

AI readiness for SMEs: how to work out where to start

Before adopting AI, an SME needs to know where it stands. How maturity models and AI-readiness scorecards work, why for an Italian SME the constraint is strategy and not infrastructure, and which department is best to start from.

Method 8 min read
Updated Written by the Innesti Digital team
In this article

The first question almost all SMEs ask themselves about artificial intelligence is "which tool do I buy?". It's the wrong question, or rather: it's the second. The first is "where are we now?". Without that answer, every tool is a gamble — and AI projects abandoned in the first ninety days almost always start here: they began from the tool, not from the starting point.

The good news is that "where we are" isn't a feeling: it can be measured. For years analysts and vendors have built AI readiness models — an organisation's readiness to adopt AI usefully and sustainably. It's worth understanding how they work, because for an Italian SME the result is almost always counterintuitive.

Two ways of measuring AI maturity

The assessment tools split into two families, which answer two different questions.

1. Maturity models: "what stage are we at, overall"

They give a shared vocabulary and a one-line answer. The Gartner AI maturity model describes five stages: Awareness (occasional experimentation, no coordination), Active (first pilots, growing leadership interest), Operational, Systemic, up to Transformational (AI is embedded in the way the company works).

The five stages of AI maturity — Gartner model
  1. Awareness

  2. Active

  3. Operational

  4. Systemic

  5. Transformational

Source: Gartner's AI maturity model. Most Italian SMEs sit between Awareness and Active: the goal isn't to reach the top, but to take the right next step.

The Deloitte maturity framework uses five similar stages, but with one extra idea that for an SME is precious: it separates the score into two domains — the AI foundations (data, technology, skills) and the AI strategy (governance, risk, KPIs, culture of innovation). Splitting the score into these two axes surfaces why a company is stuck, not just a number: it often happens to have decent foundations and non-existent strategy. A single score would hide it.

2. Weighted scorecards: "where exactly the gap is"

Cisco's AI Readiness Index measures six pillars with different weights — infrastructure (25%) and data (20%) are the two heaviest, followed by strategy, governance, talent and culture — and places the company on a scale: Pacesetter (fully ready), then Chaser, Follower, down to Laggard (unprepared). The merit of a scorecard is that it doesn't just say "you're behind": it says on which lever you're behind.

For an Italian SME the constraint is strategy, not infrastructure

Here comes the figure that upends the instinct. In its 2025 index Cisco observes that 75% of Pacesetters report staff with adequate AI skills, against just 16% of all the others. What separates those who make it from those who fall behind isn't the technology estate: it's the skills and culture gap.

There's a detail to read critically, though. Cisco's weighting — infrastructure plus data make up 45% of the score — reflects an enterprise perspective, where the bottleneck is often infrastructure. For an Italian SME the reality is almost the opposite: infrastructure is rarely the constraint. The tools that are useful today are largely cloud-based, consumption-priced, accessible without a data centre. The real constraint is upstream: undefined objectives, no project owner, processes not ready. In a word, strategy and governance — not hardware.

Translated: if you adapt a model designed for large enterprises, shift the weight from infrastructure and data towards strategy, governance and culture. For an SME that's where it's won or lost.

A short tool, not an audit

You don't need a big-consultancy assessment. For an SME the right format is short — ten, fifteen questions — and combines the two families seen above:

  • One stage question per domain (Deloitte style, two domains: foundations and strategy): it gives a plain-language answer — "you're at stage X of 5" — on each axis, instead of a single opaque score.
  • A scorecard weighted on the dimensions (Cisco style, but reweighted for SMEs: strategy, governance and culture weigh as much as or more than infrastructure and data): it indicates which function is the real bottleneck.

The result isn't a number to frame: it's a direction. It tells you which department is best to start from and with what level of attention to compliance.

From the score to the first department

A useful assessment ends with an operational direction, not with a diagnosis. In practice:

  • If a function with repetitive, high-frequency processes emerges — typically sales, marketing or operations — that's where a first pilot has the best value/risk balance.
  • If instead the weak point is governance, the first step isn't a tool: it's making the risks clear. First you look at the compliance overlay — EU AI Act, GDPR, risk taxonomy — and then you choose what to automate. The order matters: automating without controls is the fastest way to have to stop later.

It's exactly the scheme we work with: first understand where you are, then graft AI in at the right point of your business, with the right controls around it. Not a tool imposed from above, but a graft that takes.

Where to really start

If you had to remember one thing: don't start from the tool, start from the position. Measure which stage you're at on the foundations and on the strategy, identify the department with the most useful gap to close, and assess the risk before choosing the technology. It's a two-minute journey for the first answer, not a two-month one.

We've turned this method into a self-serve, free assessment: answer a few questions and get an indication of which department is best to start from in your company. Take the AI-readiness assessment — then, if it makes sense, let's talk.

The data cited come from the methodologies published by Cisco, Gartner and Deloitte, are aggregated and self-reported by the respective sources, and should be read as direction, not as a promise of results. This article is for orientation and does not constitute legal advice or a compliance assessment.

Method Written by the Innesti Digital team

Every resource grows out of the research we do for SMEs and the products we build ourselves: cited sources, a method we state openly, no claim you cannot check.

The sources are cited in the text. We encourage you to always check them directly at the original source.

Put it into practice

Where this analysis becomes work.

More deep-dives on AI adoption in an SME.

  1. Publishing with AI in five languages: what actually breaks, and how you catch it before the reader does This site ships in Italian, English, French, Spanish and Dutch through an AI transcreation pipeline: here is the defect register that came out of it, with names and causes. Five real classes — the French verb that, on a legal subject, turns a statement of fact into something very close to an accusation; the substantive error propagated identically across all five languages because it sat upstream of the per-locale pass; datelines written in a format none of the five languages actually uses; the missing revision marker visible to the reader (that one is already fixed and in production); and the best of the lot, the only class where the copy is right and the code is wrong — two components searching the headline for the string "AI" and never finding "IA", leaving French and Spanish with a flat title while raising no error and leaving no translation key missing. Then the controls the localization industry already runs, any of which would have caught them: the MQM taxonomy with its seven dimensions across three severity levels, the structure underneath ISO 5060:2024 and ISO 11669:2024; back-translation, which is not round-trip machine translation but an independent linguist retranslating without ever having seen the original; the three-tier glossary enforced before the text reaches a reviewer, with a named owner and a review calendar; the 10% native-reviewer sample, raised on high-risk content instead of held flat; language-aware date, number and currency formatters, and pseudolocalization. It closes with a checklist ordered by risk and the rule that cost us most to skip: a pattern defect is closed on the repository, not on the file. 10 min
  2. You don't need more AI: you need to redesign a department The reason almost no AI project reaches the P&L isn't the model: it's that companies gave everyone access to the tools without redesigning the processes around them. With data from Deloitte (State of AI in the Enterprise 2026), MIT NANDA (The GenAI Divide) and McKinsey (State of AI 2025) as third-party evidence of the gap, and why for an SME redesigning a single department is genuinely within reach today. 6 min
  3. How to spot a design made by AI (and the questions to ask before you sign) Three agencies, three proposals, the same site: purple gradient, blurred glass, a headline a competitor could paste verbatim. It isn't copying: it's the default setting of a generative tool, and the cause is documented. Here is how to spot it at a glance, and eight questions to put to the vendor before you sign, none of which requires technical knowledge. 9 min

From theory to your business. We graft AI in.

Want to know which department to start from in your company? The free assessment gives you a first answer in two minutes — then, if it makes sense, we talk.

32
Operational AI guides, free and no sign-up
5
Languages localized across the EU

We use cookies and similar technologies to improve your experience, analyse traffic and personalise content.

Cookie preferences

Necessary cookies Always on

Essential for the site to work. They cannot be disabled.

They help us understand how you use the site so we can improve your experience.

Used to show you relevant ads and measure campaigns.

They let us personalise content and features.