Three scores, kept separate
Maturity, Risk Exposure and Compliance Gap. They are never added together, because a legal duty is not a capability and mixing them lets good controls hide an unmet obligation.
Most businesses adopted AI faster than they wrote any rules for it. We tell you exactly how much risk that created, where your controls fall short of it, and what to fix in the next ninety days — measured against every regulation that actually reaches you.
The Atolus AI Maturity Index scores how responsibly your business runs AI. Not an opinion, not a checklist — three independent scores, each traceable to a named clause in real law.
Maturity, Risk Exposure and Compliance Gap. They are never added together, because a legal duty is not a capability and mixing them lets good controls hide an unmet obligation.
The assessment works out which regulations actually bind your business — from your jurisdiction, sector, data and what your AI does — and scores you against those. Most owners are surprised by the answer.
You finish the readout already holding a prioritized roadmap: what to fix first, who owns it, and roughly what it takes. Not a report that ends in a proposal.
No long discovery phase, and nothing that needs a committee to approve.
Tell us what prompted this — a customer questionnaire, an insurance renewal, a near-miss, or just a nagging feeling. We tell you honestly whether you need us.
A working session to find the AI tools actually in use across your business. It almost always surfaces something management did not know about, and you keep the list either way.
Two to three weeks. A few hours of your time, plus short sessions with whoever owns the relevant areas. We do the rest.
Your three scores, every finding with the clause behind it, and a costed 30/60/90 plan — delivered in the room, not sent on later.
AI in hiring sits in the highest-risk tier almost everywhere it is regulated — NYC Local Law 144, Illinois HB 3773, the EU AI Act. Your core product is the thing the rules are aimed at.
Confidentiality and privilege make staff use of public AI tools an immediate problem, and client contracts increasingly say so explicitly.
Sensitive data by default, high harm severity, and owners who already understand what a regulator looks like. HIPAA and state privacy law both reach AI use.
Credit, underwriting and advice decisions made or assisted by AI carry specific duties — plus an existing compliance culture and a board that asks.
Your enterprise customers now send AI questions in every security review. The fastest-moving trigger there is, and the one with a deadline attached.
Selling into large accounts means inheriting their compliance requirements. AI governance is turning up in supplier questionnaires alongside cyber.
Law firms deliver memos. Compliance platforms deliver checklists. We deliver a defensible score you can compare against last year and against your sector — with the arithmetic written down rather than left to judgement.
Enterprise AI governance programmes take a year and a department. Ours is scoped for a business of twenty to two hundred people, where one or two people can say yes and nobody has a compliance team.
An assessment that ends at findings leaves you stuck. Ours ends with a sequenced plan, and we can carry it out — write the policies, build the inventory, train the team, and re-score you afterwards.
Governance work usually turns up practical gaps. These are the engagements that close them — and the AI implementation work that follows once the guardrails exist.
Strategic guidance to identify where AI creates the most value for your business — without the jargon.
Purpose-built AI tools and automations designed around your specific workflows and systems.
Hands-on training that gets your team confident using AI tools — from day one.
Ongoing AI support and optimization so your tools keep working as your business evolves.
A free 30-minute call. We will walk through which regulations reach your business, what an assessment would cover, and whether it is worth doing at all right now.