AI in ITSM and ITOM maturity: readiness is a data, process and control question
Virtual agents, intelligent triage and AIOps are now standard items on vendor roadmaps. Whether they help you depends less on the model and more on the quality of your knowledge and data, your process discipline, and the controls around the system. This domain measures that readiness.
Most AI problems in service operations are foundation problems
The early results are mixed. Gartner’s survey of 782 infrastructure and operations leaders, run in late 2025, found that only 28% of AI use cases fully succeed and meet ROI expectations, while 20% fail outright. Gartner also reports that 38% of leaders who faced setbacks cited persistent skill gaps, and that 38% of leaders named poor data quality or limited data availability as a direct cause of AI project failure.
Data readiness is the common thread. A separate Gartner survey of 1,203 data management leaders found that 63% either lack, or are unsure they have, the right data management practices for AI. Gartner predicts that through 2026, organizations will abandon 60% of AI projects that are not supported by AI-ready data. That last figure is a forecast, not a measurement.
For a service organization this turns into specific questions. Is the knowledge base current enough to ground a virtual agent? Are categories and resolution notes consistent enough to train triage? Does the CMDB describe services accurately enough for AIOps to correlate events? Is there a person with the authority and the means to stop an automated action that goes wrong? Those are maturity questions, and they can be answered before you buy a feature.
Outcomes of AI use cases in infrastructure and operations
Seven things we look at in the AI domain
We assess readiness for the AI capabilities you already have in your platforms as well as those you are planning, because many arrive through routine vendor updates.
- Virtual agents and self-serviceWhere conversational and self-service channels are used, how well they resolve requests, and what happens when they cannot.
- Intelligent triage and classificationWhether categorization, prioritization and routing are supported by models, and how accuracy is checked against human decisions.
- Knowledge generation and qualityThe currency and structure of the knowledge that AI answers are grounded on, and who reviews generated content.
- Predictive problem and change riskUse of historical data to flag recurring problems and risky changes, and whether findings feed real decisions.
- AIOps and event noise reductionWhether event correlation depends on a service model and CMDB accurate enough to be trusted.
- Data quality and readinessCompleteness and consistency of tickets, assets and relationships, and named owners for each data set.
- Security, responsible use and human oversightPolicy, access control, accuracy monitoring and a human override path, aligned where relevant to the NIST AI Risk Management Framework and ISO/IEC 42001.
Three points on the scale for AI
Every domain is scored on the same five levels. These are the anchor points we use most often when we talk with clients about where they are and where they should aim.
Individual or shadow use of AI tools with no inventory. Knowledge and ticket data are inconsistent, and nobody owns accuracy.
Approved use cases with data readiness checks, accuracy measures and human approval for risky actions. A written policy covers use and access.
AI is monitored and audited, aligned to a management system such as ISO/IEC 42001 or the NIST framework, with tested stop controls and autonomy earned through evidence.
Three patterns we see again and again
AI switched on over stale knowledge
A virtual agent is enabled over an out-of-date knowledge base and inconsistent categories. Answers are poor, trust collapses, and the feature is quietly dropped.
Vendor AI features with no register
Features arrive in platform updates and are enabled without a use-case list, an owner or an accuracy measure. Nobody can say what the AI is doing.
No override path
There is no monitoring for drift or wrong actions, and no agreed way to stop an automated action quickly when it misbehaves.
These are practitioner observations from assessment and implementation work, not survey findings. Regulatory obligations depend on the use case and the jurisdiction, so confirm current requirements with your legal and compliance teams.
One domain of six, scored on the same 0 to 5 scale
AI readiness is scored from questions on use cases, data and knowledge quality, controls and human oversight. It is the domain that depends most on the other five, which is why it is scored alongside them and not on its own. See how the numbers are produced on our scoring methodology page, or read the other domain guides.
Find out how ready your organization really is for AI.
No sales call required to get your first read, just the assessment.
Start free trial assessmentSources. Gartner, AI Projects in I&O Stall Ahead of Meaningful ROI Returns (April 2026). Gartner, Lack of AI-Ready Data Puts AI Projects at Risk (February 2025). NIST, AI Risk Management Framework 1.0 (2023). ISO, ISO/IEC 42001:2023 (2023). Survey figures are reported as published by each source. One figure is a forecast and is labeled as such.
