What an AI readiness assessment measures, and what it must never claim
More than half of employees say they conceal their AI use. That turns every figure built on asking into a floor rather than a level, and it is the whole difference between a diagnosis and a score.

Key insights
- More than half of employees report concealing their AI use. Every measurement built on asking is therefore a floor rather than a level, and should be labelled as one.
- Managers and employees are four percentage points apart on whether staff were informed about AI at work. The gap the field assumes does not exist on that question.
- 38 per cent say they have shared sensitive work information with AI without their employer knowing, and just over half have never had training in safe use.
- A readiness assessment measures what leaves a trace: what is written down, what is paid for and logged into, and where the work actually takes time.
In the largest global study of attitudes to AI at work, 57 per cent of employees say they avoid revealing when they have used AI, and present AI-generated content as their own. The base is more than 48,000 people across 47 countries, collected between November 2024 and January 2025 by KPMG and the University of Melbourne.
That sentence is a problem for any measurement built on asking. If a majority conceals, a survey about AI use does not measure the use. It measures the willingness to talk about it.
It is also the whole difference between a diagnosis and a score. A readiness assessment that consists of a questionnaire and ends in a radar chart measures the willingness to talk. One that counts what leaves a trace in the business measures the business. Both are sold under the same name, and they are not the same thing.
The gap is not where it is assumed to be
The assumption is familiar from almost every change programme: leadership believes it has communicated, and staff feel nobody told them anything.
That question has actually been put to both sides in the same survey. Special Eurobarometer 554, fielded in April and May 2024 with 26,415 respondents across all 27 member states, asked employees whether their employer had informed them about the use of digital technologies including AI to manage work, and asked managers whether they had ensured the people they manage were informed.
Four percentage points apart. The gap usually assumed between leadership's picture and the workforce's does not exist on this question.
Source: Special Eurobarometer 554, fieldwork April to May 2024, 26,415 respondents across 27 member states
Four percentage points. The two sides broadly agree. That is a result in itself, and an uncomfortable one for the kind of maturity work that begins from the premise that leadership is wrong about its own organisation.
The gap is somewhere else
It does not run between leadership's picture and the workforce's picture. It runs between what anyone reports at all and what is actually happening.
In Oh, Behave!, the annual survey from the National Cybersecurity Alliance and CybSafe with more than 7,000 respondents across seven countries, 38 per cent say they have shared sensitive work information with AI tools without their employer knowing. These are people reporting on their own behaviour, on a question where nobody has anything to gain by overstating.
The same survey suggests why.
- Have had training48%
- Have had no training52%
In the same survey, 38 per cent say they have shared sensitive work information with AI without their employer knowing.
Just over half have never had any training in safe AI use. The KPMG study lands independently at roughly the same level: 47 per cent say they have received AI training. Two different surveys, different populations, different question wording, and both come out around half.
Why a self-report is a floor and not a level
Here the three surveys combine into something none of them says on its own.
The KPMG study reports that almost half admit to using AI in ways that contravene their organisation's policies, that over half say they have made mistakes at work because of AI, and that only two in five say a policy governing generative AI use exists at all.
Each of those is uncomfortable. But it is the first figure in this article that decides how they should be read.
When the same population tells you it conceals, every admission is a lower bound.
38 per cent is at least 38 per cent. Almost half is at least almost half.
That is no reason to distrust the surveys. It is a reason to read them as floors, and to stop treating a survey answer about rule-breaking as a measurement of rule-breaking.
Nor is it a reason to stop asking. A floor is useful as long as it is labelled as a floor, and it rises the wider it is collected. Concealment is presumably not evenly distributed. It is greatest where the perceived risk of admitting is greatest, which is closest to whoever set the rule. A measurement that reaches only the leadership team is therefore asking the group with the least to disclose. The same questions put across several functions, right out to the people doing the work, produce a higher floor and a truer picture.
Netskope measured where the work happens instead of asking
The floor can be tested against something other than more questions. The Netskope AI Report: 2026 does not rest on what anyone reports. It rests on aggregated usage data from Netskope's own platform, collected between June 2025 and July 2026. It finds that 56 per cent of AI users work only in AI applications the organisation manages, 14 per cent use both organisation-managed and personal apps, and 30 per cent use personal apps only.
So 30 per cent of the users measured work entirely in accounts the organisation does not own, and a further 14 per cent work in both. That is not a question of what anyone is willing to say. It is a record of where the work happens.
The figure has to be read for what it is. Netskope does not state how many organisations or users are covered, and the report does not specify whether the measurement reaches beyond managed devices. It is an observation drawn from a customer base of unstated size, not a representative share of working life in Sweden or the Nordics.
The value lies in the method. The survey says a majority conceals. The usage data says a substantial part of the work sits in accounts the organisation cannot see. Two different routes to the same question point the same way, and whatever number an organisation produces about itself is therefore a floor however honestly its people answer. That is the argument for measuring in more than one place.
What a readiness assessment measures
Three things, and what they have in common is that they leave traces which do not depend on anyone volunteering anything.
What is written down. Is there a policy, and what does it say? Only two in five report that one exists at all. It is a question with a checkable answer, and the answer is surprisingly often no.
What is paid for, and what is actually used. Licences, accounts and logins can be counted without asking anyone. It is the same measurement behind the question of which AI tools are actually being used, and it is honest for the same reason: a login is not an opinion.
Where the work takes time. Measured on the work, not on the person. How long a case takes from arrival to closure, how many times it changes hands, where it stands still. That measurement does not care who used which tool, which is exactly why there is nothing in it to conceal.
What every number in the report should be labelled with
The label has to say what the number is, and three confusions are what the labelling exists to prevent.
An industry figure as your level. The KPMG study reports 58 per cent intentionally using AI at work, 31 per cent of them weekly or more often. EY's Work Reimagined 2025, covering 15,000 employees and 1,500 employers across 29 countries in August 2025, reports 88 per cent using AI at work to some degree. Nine months apart, different populations, different question wording. The difference is not a trend anyone can extrapolate, and neither figure is yours. A benchmark is good for framing a question, not for answering one.
A self-assessed value as a measured one. How AI-literate someone judges themselves to be says something real about confidence, and confidence is useful in itself, particularly where it differs sharply between functions in the same organisation, because that difference points to where the friction sits. But it is not capability, and a report that lets the two stand in the same column has done its reader a disservice.
A survey answer about compliance as a measurement of compliance. You can ask, and the answer is a floor. You can measure it technically in some systems, and then you have measured the systems that keep logs.
What follows from it
EY's survey notes that between 23 and 58 per cent bring their own AI tools to work depending on sector, while only 28 per cent of organisations are judged to have what it takes to turn deployment into anything of value. The picture of an organisation where use is already under way and governance has not caught up is therefore not a guess.
The practical consequence is simpler than it is usually made to sound. If just over half have never had training in safe use, then a new rule is aimed at people who do not know what the risk consists of. A rule that cannot be followed knowingly produces mainly silence, and silence is precisely what makes the next measurement useless.
Training before policy, then. Not because training is the nicer of the two, but because it is the only one of them that makes the measurement which follows it honest.
And when that measurement is made: count what leaves a trace, put the questions across the organisation rather than only at the top, and state for every figure in the report which of the two it is. That is different work from sending out a questionnaire, and it is the work that makes the numbers usable.
A readiness assessment that does not draw that line gives you a score. One that does gives you something you can decide on.
Common questions
It measures what leaves a trace in the business: which rules are written down and what they say, which tools are paid for and actually logged into, and where the time goes in the work itself. None of that depends on anyone volunteering anything, which is why it can be trusted. To that is added what employees describe about their own work, read as a lower bound.
Not by asking an industry. Surveys of the same question land on 58 and 88 per cent nine months apart, with different populations and different question wording. Licences, accounts and logins can be counted inside your own organisation, and that figure is yours.
Because 57 per cent of employees in the KPMG and University of Melbourne global study say they avoid revealing when they have used AI. When the same population tells you it conceals, every admission is a lower bound rather than a level. That still makes the answers useful, but only if they are labelled as floors.
No. A floor is useful as long as it is labelled as a floor, and it rises the wider it is collected. Concealment is greatest where the perceived risk of admitting is greatest, which is closest to whoever set the rule. A measurement that reaches only the leadership team is asking the group with the least to disclose.
A questionnaire that ends in a radar chart measures the willingness to talk and reports it as a level. A readiness assessment counts what leaves a trace, collects what is said across several functions, and states for every figure which of the two it is. Both are sold under the same name and they are not the same thing.
No, but it should not be confused with capability. Confidence is a useful signal, particularly where it differs sharply between functions in the same organisation, because the difference points to where the friction sits. The error appears only when a self-assessed value is reported in the same column as a measured one.
Training. Just over half of working people have never had training in safe AI use. A rule aimed at people who do not know what the risk consists of produces mainly silence, and silence is what makes the next measurement useless.
Because every figure in the report is labelled with what it is: counted from a system, or reported by a person. The first is a measurement. The second is a lower bound. A report that does not draw that line gives you a score rather than something you can decide on.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.