· Mohamed Ben Haddou · AI readiness · 7 min read
Are you AI-ready? Part 5 — People & Operating Model: if an AI tool misbehaved tomorrow, who would act?
Ask that question in a leadership meeting and count the seconds of silence. The fifth dimension of AI readiness is the one organisations skip because it is not technical: who owns AI, what skills exist beyond the enthusiasts, and why AI literacy stopped being optional in February 2025.

Fifth of six articles on the dimensions of the Mentis READY Framework. So far: what AI is for, whether your data is ready, where it will run, and what the law requires. This one is about the people who have to make all of that true.
The eight-second silence
There is a question we ask in every assessment, and we have learned to let the silence run: “If an AI tool misbehaved tomorrow — wrong answers to customers, a discriminatory pattern in screening, confidential data where it should not be — who would act?”
The answers, in ascending order of maturity: nobody is defined; whoever bought the tool; IT, informally; a named owner per system; an operating model with clear decision rights. Most organisations we meet are at “whoever bought the tool” — which means accountability is distributed by procurement accident. The tool bought by marketing is marketing’s problem, the one in the HR suite is HR’s, and the one everyone uses belongs to no one.
Strategy, data, architecture and governance — the four dimensions before this one — are all documents until someone owns them. That is why weakness on People & Operating Model is the most expensive kind: it silently caps the value of everything else.
What the dimension actually covers
Three things, none of them a hiring spree:
- Skills. Not “do we employ data scientists?” but: can the people who buy, use and supervise AI tell a good system from a confident one? Judgement is the scarce skill, and it is trainable.
- Ownership and decision rights. One accountable person for AI direction; a named owner per system; clarity on who decides tool adoption, vendor selection, and escalation. One accountable person beats a committee of enthusiasts — a committee is where accountability goes to be shared until it disappears.
- Change readiness. Whether the people whose work changes are being brought along — trained, consulted, given time — or presented with a tool and a memo. Most “AI failures” reported as technical were adoption failures with a technical alibi.
The five maturity levels of People & Operating Model
| Level | What it looks like in practice |
|---|---|
| 1 · Ad hoc | No AI skills in-house; nobody defined for incidents; resistance or fear, not addressed. |
| 2 · Experimenting | A few self-taught enthusiasts; accountability sits with whoever bought each tool; curiosity but no support. |
| 3 · Structured | Pockets of expertise in IT or data teams; IT acts informally when things break; some training has happened. |
| 4 · Managed | Defined roles and a training plan; a named owner per system; a structured enablement programme. |
| 5 · Optimised | AI skills spread across business functions; an operating model with clear decision rights; adoption measured and managed. |
The pattern worth naming: organisations routinely rate themselves higher here than the evidence supports, because enthusiasm reads as capability from a distance. Three power users and a supportive CEO feel like momentum; they are level 2.
Three questions that tell you where you are
These are the three the scorecard asks for this dimension.
AI skills in the organisation? “A few self-taught enthusiasts” is where nearly everyone starts, and it is genuinely valuable — enthusiasts find the use cases. The trap is mistaking them for an operating model: enthusiasm concentrates in volunteers, leaves with them, and skips exactly the functions where AI decisions carry the most risk — HR, finance, legal. Level 4 is not more enthusiasts; it is defined roles and a training plan that reaches the sceptics.
If an AI tool misbehaved tomorrow, who would act? The eight-second question. A named owner per system is the level that matters, and it is cheap: a column in the inventory you built in Part 4. The last level — an operating model with decision rights — adds the part that prevents the next incident instead of merely responding to this one: who approves new tools, who reviews them, who can say stop.
How change-ready are your teams? “Resistance or fear, not addressed” deserves more respect than it gets: the fear is usually rational, and unaddressed fear does not block AI — it drives it underground, which is where Part 6 picks up the story. The maturity ladder here is about support, not sentiment: from curiosity without support, through training, to a structured enablement programme, to adoption actually measured.
Who should own AI in a mid-market organisation?
The large-enterprise answers — a Chief AI Officer, a centre of excellence — mostly do not transpose. A CoE needs a critical mass of projects to justify itself; a full-time CAIO needs a full-time job. What works at mid-market scale is simpler:
- One accountable owner for AI direction — a person, not a committee. Senior enough to say no to a vendor and to a board member; close enough to operations to know what the tools actually do. Often this is a mandate added to an existing role (COO, CIO, a business-line head) rather than a new chair.
- A named owner per system, drawn from the function that uses it — because the HR suite’s AI is an HR responsibility, whatever the logo on the invoice says.
- A small champions network — the enthusiasts, given structure: first look at new tools, first line of peer support, honest feedback channel.
Where the accountable-owner role has no natural home — no CIO, an IT function busy running IT — organisations increasingly rent the role rather than leave it empty: senior AI leadership a few days a month, until an internal owner is obvious and ready. That is exactly the gap our fractional AI lead offer exists to close; the honest version of that arrangement has a built-in ending, because reducing your dependence on the outsider is part of the job.
Where the law lands on people
Since February 2025, Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy in the staff who operate and use AI systems — proportionate to their role, the context, and the people affected. It is one of the Act’s quietest obligations and one of the broadest: it does not wait for you to deploy a high-risk system, and “we sent a newsletter” is not a training plan.
The high-risk provisions reinforce it from the other side: human oversight under the Act must be exercised by people with the competence, training and authority to intervene. Oversight, in other words, is a staffing decision. Assigning a supervisor who cannot understand or override the system satisfies an org chart, not the regulation.
Both point the same way: structured, role-appropriate training is now table stakes. (It is also the fastest cultural intervention we know — a workforce that understands what AI can and cannot do generates better use cases and fewer incidents. That conviction is why we run AI-literacy training as a standing offer.)
What to do in the next 30 days
If you recognise yourself at level 1 to 3:
- Name the owner. One person, accountable for AI direction, announced out loud. Imperfect and named beats ideal and vacant.
- Add an owner column to the AI inventory. Every system from the Part 4 register gets a name from the function that uses it. An hour of work; it converts the register from a document into an operating model.
- Run a literacy baseline. A short survey: who uses what, how confidently, with what worries. It sizes the training need, surfaces the shadow usage (Part 6), and doubles as your Article 4 starting evidence.
- Give the enthusiasts a job description. Champions network, first-look duty, feedback channel. Volunteers with a mandate outperform a programme without one.
Where this sits in the bigger picture
People & Operating Model is the fifth of six dimensions. The final article covers Security & Trust — shadow AI, data-leakage vectors, model risk, and why “do you know which AI tools your employees already use?” is the question with the most uncomfortable honest answer. Together the six produce the maturity radar at the heart of the AI Readiness Assessment, our four-week, fixed-price diagnostic for mid-market organisations in regulated sectors.
Want your own reading? The free AI Readiness Scorecard asks the three people questions above — and fifteen more across the other dimensions — and gives you your maturity radar in four minutes. No account, no sales call attached; if you want a second opinion on your results, leave an email and we will write back within a business day.
Mohamed Ben Haddou is the founder of Mentis Consulting (Brussels, ULB spin-off, since 2005) and an Independent AI Expert for the European Commission.
