
Pinellas County put organizational readiness near the beginning of its current procurement for an enterprise-wide AI Strategic Roadmap and Governance Framework. Before establishing a three-to-five-year roadmap, the county wants an assessment of its existing technology, data governance, cybersecurity, workforce skills and AI activity.
That sequencing makes sense. A government cannot develop a credible AI roadmap until it understands its starting point.
The assessment is harder than it sounds.
Most governments can inventory their servers, software licenses and major technology contracts. AI can spread through an organization without appearing on any of those lists. Employees can open ChatGPT, Claude or Gemini and begin experimenting in minutes. Existing software vendors are adding AI features to products government already owns. Departments can develop their own practices without realizing another department is working on essentially the same problem.
That means an AI readiness assessment needs to examine both infrastructure and behavior.
At the Artificial Intelligence Center of Excellence, I would organize that assessment around five areas: technology, data, people, processes and existing AI use.
Technology establishes what systems government currently operates and how they connect. AI applications often become much more valuable when they can interact with existing systems rather than operating as standalone tools.
Data determines what those applications can know. Governments hold enormous amounts of useful information, but that information can be fragmented across departments, stored in incompatible formats or governed by different access requirements. Knowing that data exists is different from having data that an AI system can reliably use.
People reveal capabilities that an organizational chart cannot. Some employees will already be sophisticated AI users. Others may have little experience. Managers need enough understanding to evaluate opportunities and risks. Technical teams need deeper capabilities to deploy, evaluate and maintain systems.
Processes show where AI can create operational value. A readiness assessment should map how work actually gets done, particularly repetitive processes involving research, documents, forms, communication and information transfer. AI strategy becomes much more concrete when a government can identify a process that consumes 500 staff hours a month and understand why.
Then comes the most difficult inventory: existing AI use.
I would approach this with a temporary AI amnesty and discovery period.
Employees should be asked to disclose the AI tools, prompts, workflows, experiments and AI-enabled vendor products they are already using. The purpose should be explicit: understand what is happening, identify risks and find practices worth expanding. Disclosure itself should not create a compliance problem. Serious privacy, security or legal issues would still require intervention.
A punitive approach creates an obvious incentive to keep experimentation hidden. That costs the organization valuable information.
Consider an employee who has independently used AI to reduce a repetitive four-hour process to 30 minutes. The workflow may need security review, better quality controls or approved technology. It may also contain an important operational innovation that could save hundreds of hours if adopted across the department.
Government needs to find both sides of that equation.
This discovery process can also expose another problem: employees performing similar jobs through increasingly different processes. One employee may use AI extensively while another performs the same work manually. Over time, their speed, output and methods can diverge significantly.
That makes readiness a prerequisite for workforce planning and governance. Leaders need to know where capability already exists before deciding where training is needed. They need to understand actual AI behavior before writing policies intended to govern it.
The result of a readiness assessment should be a map of the institution as it currently operates: what technology it has, what data it can use, what its people know, how important processes work and where AI has already entered those processes.
Only then can government sensibly decide where it wants to go.
A Practical Model for Assessing Civic AI Readiness
Inventory the foundation. Map technology, data, integrations, cybersecurity constraints and existing vendor capabilities.
Map the work. Identify important workflows, bottlenecks, repetitive tasks and processes where information moves between people or systems.
Run an AI discovery period. Give employees a defined opportunity to disclose existing tools, prompts, workflows and experiments without penalizing disclosure itself.
Capture capability. Identify risks that require intervention and successful practices that deserve testing, standardization and wider adoption.
