How we measure the way people work with AI
A measurement framework for leaders who need an evidence-based read on their workforce — not a confidence survey. Five connected domains, twenty-four components, and a self-reflection baseline that separates demonstrated judgment from self-belief — then completes the picture with feedback from peers and leadership.
Grounded in the standards US organizations actually govern by
The framework is cross-walked to the two governance standards American businesses are held to in practice:
The NIST AI Risk Management Framework (AI RMF 1.0)1 — the US reference for managing AI risk, organized around four functions (Govern, Map, Measure, Manage) and seven characteristics of trustworthy AI. Its Govern 2.2 control requires that personnel and partners receive AI risk-management training so they can act consistently with policy — and asks organizations to assess whether personnel have the necessary skills, training, and domain knowledge for their assigned responsibilities.2
ISO/IEC 42001:20234 — the certifiable AI management system standard. Clause 7.2 (Competence) requires that people whose work affects AI performance are competent, and that the organization retain documented evidence of that competence. Clause 7.3 (Awareness) requires that they understand the AI policy, their contribution to it, and the implications of not conforming.
Both standards require a competent, aware workforce, but they don’t prescribe how to measure it. That’s what this framework is for.
The core premise: AI capability cannot be inferred from AI usage. License counts and login data measure exposure, not judgment — and judgment is what fails under pressure. The only way to know where a workforce actually stands is to look, component by component, and to compare what people do against what they believe about themselves — and then against how their work lands with others.
One framework, five connected domains
| Domain | What it builds | Components |
|---|---|---|
| D1 AI Foundations & Reality |
An accurate picture of what AI is, how it works, and where the hype ends and reality begins — the shared baseline everything else rests on. | 1.1 What AI is and isn't1.2 How generative AI works1.3 Capabilities & limits1.4 Myths vs. reality1.5 The AI landscape |
| D2 Critical Engagement & Judgment |
Weighing what AI gives you — checking accuracy and bias, verifying before trusting, and knowing when not to use AI at all. | 2.1 Evaluating outputs2.2 Bias & fairness awareness2.3 Verification & sourcing2.4 Knowing when not to use AI |
| D3 Applied AI & Productivity |
Turning understanding into results — prompting, choosing the right tool, fitting AI into workflows, and co-creating while keeping quality and ownership. | 3.1 Prompting & interaction3.2 Tool selection & fit3.3 Workflow integration3.4 Co-creation & review3.5 Role-based use cases |
| D4 Responsible & Ethical AI |
Using AI safely, fairly, and within the rules — privacy and data protection, accountability, security, IP, and compliance. | 4.1 Human agency & accountability4.2 Privacy & data protection4.3 Security & safe use4.4 IP, ownership & attribution4.5 Compliance & policy |
| D5 AI Strategy & Management |
Leading with AI — spotting where it adds value, setting guardrails, guiding adoption, and measuring impact. | 5.1 Identifying opportunities & ROI5.2 Governance & policy-setting5.3 Change & adoption management5.4 Delegating work to AI5.5 Measuring impact |
How the domains map to US governance
This is a cross-walk, not a competing standard. Below is where each domain connects to NIST AI RMF and ISO/IEC 42001 — so a baseline speaks in terms your risk, compliance, and L&D teams already use.
| Domain | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|
| D1 · Foundations & Reality | Map. Establishing context and understanding capabilities and limitations. Underpins the valid & reliable characteristic — you cannot judge reliability without knowing how the system works. | 7.3 Awareness — baseline understanding across everyone doing work under the organization's control. |
| D2 · Critical Engagement & Judgment | Measure. Serves the valid & reliable, fair — with harmful bias managed, and explainable & interpretable characteristics. This is where hallucination and bias are actually caught, by a person. | 7.2 Competence — the judgment that separates a competent operator from a merely trained one. |
| D3 · Applied AI & Productivity | Manage. The point of the whole exercise: value realized from AI, safely. Effective human oversight depends on operators who know the tool. | 7.2 Competence — people whose work affects AI performance. |
| D4 · Responsible & Ethical AI | Govern. Maps to the privacy-enhanced, secure & resilient, and accountable & transparent characteristics. Govern 2.2 lives here: personnel trained to act consistently with policy. | 7.3 Awareness — the AI policy, their contribution to it, and the consequences of non-conformance. |
| D5 · AI Strategy & Management | Govern. Leadership accountability, risk tolerance, and measurement — the function NIST places first because nothing else holds without it. | Clause 5 (Leadership), Clause 6 (Planning), Clause 9 (Performance evaluation). |
The practical consequence: a baseline against this framework produces exactly what ISO/IEC 42001 Clause 7.2 asks organizations to retain — documented evidence of workforce competence — and exactly what NIST Govern 2.2 asks them to assess. It also tells you where to spend the training budget, which neither standard does.
Want this for your own organization? We're running free pilots with a small number of design-partner companies — a full baseline for your team, in exchange for honest feedback.
Request a pilot →Self-awareness, seen from three angles
The AI Maturity baseline is built on self-reflection — every component is read through two lenses: what a person does, and how they see themselves. A third lens, feedback from peers and leadership, is included with the portal and layered in after the self-reflection step, for a complete and balanced view of self-awareness.
The self-reflection baseline
Lens 1
Actions — what you'd actually do
Short, realistic situations ask you to choose the response closest to what you would most likely do. Each option reflects a level of practice and maps to a 1–10 scale, so choices become an evidence-based read of demonstrated judgment — not a self-estimate. Questions and answer order are randomized to keep the read honest.
Lens 2
Self-Perception — how you see yourself
One statement per component (for example, “My knowledge of how generative AI works is…”) is rated on a five-point slider from far below to far exceeds my expectation. This captures confidence and self-awareness alongside the behavioral measure.
The distance between the two tracks is the coaching signal — the fastest read on where confidence and capability disagree.
Completing the picture
Lens 3 · included in the portal, after self-reflection
Feedback — how others see your work
Once self-reflection is complete, the same components can be opened to structured input from peers and leaders. Because the feedback items mirror the self-reflection items one-to-one, a person's own read sits directly alongside how their work actually lands with others — turning a private baseline into a rounded, 360° view of self-awareness. This lens always follows self-reflection; it never replaces it.
The practice rubric (Actions)
Within each situation, the response options ladder across four levels of practice, spread along the 1–10 scale:
| Level | What it looks like |
|---|---|
| Not yet | No working approach yet, or holds a misconception. |
| Foundational | Aware and safe; understands the basics. |
| Practitioner | Applies it correctly and confidently in real work. |
| Leader | Fluent and anticipatory; extends the practice and guides others. |
The self-perception scale
| Slider position | Meaning |
|---|---|
| Far below | My knowledge is far below my expectation. |
| Below | Below my expectation. |
| Meets | Meets my expectation. |
| Exceeds | Exceeds my expectation. |
| Far exceeds | Far exceeds my expectation. |
Where the lenses diverge is where the work is
After a domain is complete, the Awareness Summary shows, for each component, the Actions result beside Self-Perception — and where the two diverge. That gap is the coaching signal:
| Pattern | What it suggests |
|---|---|
| Actions above Self-Perception | People handle these situations more capably than they give themselves credit for — build confidence and stretch toward the next level. |
| Actions below Self-Perception | There is more room to grow here than it feels — a good place to focus first. |
| Aligned | Self-view matches demonstrated practice — confirm the level and choose the next goal. |
When the Feedback lens is added, the same comparison runs against how others see the work — and a third pattern emerges: capability that a person cannot see in themselves, and confidence that others do not share.
At the organization level, these gaps aggregate into the finding leaders act on: where confidence outruns capability, and whether a healthy average is concealing a group that is struggling. From there, the framework points to targeted learning matched to each component and level, so a reflection ends in a plan, not just a score.
How scores roll up
Scores aggregate from the bottom up: individual responses form a rating for each component, components combine into a domain rating, and the five domains form an overall AI-maturity profile.
Within a domain, components are weighted to total 100%; within a component, situational items are weighted to total 100%. Weights and emphasis can be tuned to an organization's priorities — a regulated firm may weight D4 more heavily than a design studio would — without changing the structure. The same engine scores every lens; it is signal-agnostic.
References
- National Institute of Standards and Technology (NIST). Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023. The US reference framework for trustworthy AI; a living document currently under revision. nist.gov/itl/ai-risk-management-framework · NIST AI 100-1 (PDF)
- NIST AI RMF Playbook — Govern. Govern 2.2: personnel and partners receive AI risk-management training; organizations assess whether personnel have the necessary skills, training, and domain knowledge for their responsibilities. airc.nist.gov · Playbook · Govern · AI RMF Core
- NIST. Generative AI Profile (NIST AI 600-1), 2024 — a companion profile addressing risks unique to generative AI. NIST AI 600-1 (PDF)
- ISO/IEC 42001:2023 — Artificial intelligence management system. Clause 7.2 (Competence): ensure personnel affecting AI performance are competent and retain documented evidence of competence. Clause 7.3 (Awareness): the AI policy, individual contribution, and implications of non-conformance. Requirement 7 · Support · clause-by-clause summary
- Cooley LLP. “State AI Laws — Where Are They Now?”, April 2026. On Colorado's repeal-and-replace of SB 24-205 and the current state landscape. cooley.com · State AI Laws
- Baker Botts, “US AI Law Update,” January 2026; and King & Spalding on the state AI laws effective January 1, 2026 (Illinois HB 3773, California ADMT, Texas TRAIGA). bakerbotts.com · kslaw.com
Framework, rubric, and methodology © 2gnoMe. Cross-walked to the NIST AI Risk Management Framework (AI RMF 1.0) and ISO/IEC 42001:2023 workforce competence and awareness requirements; alignment reviewed as those standards evolve. Regulatory context current as of July 2026 and reviewed quarterly. Nothing here is legal advice.
Free for a limited number of design partners, in exchange for structured feedback. Individual results stay private to each person; the organization sees only anonymized team patterns.
Start your own baseline · How we compare · ← Back to ai.2gno.me
