← Back to ai.2gno.me

How we measure the way people work with AI

A measurement framework for leaders who need an evidence-based read on their workforce — not a confidence survey. Five connected domains, twenty-four components, and a self-reflection baseline that separates demonstrated judgment from self-belief — then completes the picture with feedback from peers and leadership.

Grounded in the standards US organizations actually govern by

The framework is cross-walked to the two governance standards American businesses are held to in practice:

The NIST AI Risk Management Framework (AI RMF 1.0)1 — the US reference for managing AI risk, organized around four functions (Govern, Map, Measure, Manage) and seven characteristics of trustworthy AI. Its Govern 2.2 control requires that personnel and partners receive AI risk-management training so they can act consistently with policy — and asks organizations to assess whether personnel have the necessary skills, training, and domain knowledge for their assigned responsibilities.2

ISO/IEC 42001:20234 — the certifiable AI management system standard. Clause 7.2 (Competence) requires that people whose work affects AI performance are competent, and that the organization retain documented evidence of that competence. Clause 7.3 (Awareness) requires that they understand the AI policy, their contribution to it, and the implications of not conforming.

Both standards require a competent, aware workforce, but they don’t prescribe how to measure it. That’s what this framework is for.

The core premise: AI capability cannot be inferred from AI usage. License counts and login data measure exposure, not judgment — and judgment is what fails under pressure. The only way to know where a workforce actually stands is to look, component by component, and to compare what people do against what they believe about themselves — and then against how their work lands with others.

One framework, five connected domains

AI Maturity 5 domains · 24 components D1 · AI Foundations & Reality 5 components D2 · Critical Engagement & Judgment 4 components D3 · Applied AI & Productivity 5 components D4 · Responsible & Ethical AI 5 components D5 · AI Strategy & Management 5 components
One framework, five connected domains — each unpacked into its components below.
Domain What it builds Components
D1
AI Foundations & Reality
An accurate picture of what AI is, how it works, and where the hype ends and reality begins — the shared baseline everything else rests on. 1.1 What AI is and isn't1.2 How generative AI works1.3 Capabilities & limits1.4 Myths vs. reality1.5 The AI landscape
D2
Critical Engagement & Judgment
Weighing what AI gives you — checking accuracy and bias, verifying before trusting, and knowing when not to use AI at all. 2.1 Evaluating outputs2.2 Bias & fairness awareness2.3 Verification & sourcing2.4 Knowing when not to use AI
D3
Applied AI & Productivity
Turning understanding into results — prompting, choosing the right tool, fitting AI into workflows, and co-creating while keeping quality and ownership. 3.1 Prompting & interaction3.2 Tool selection & fit3.3 Workflow integration3.4 Co-creation & review3.5 Role-based use cases
D4
Responsible & Ethical AI
Using AI safely, fairly, and within the rules — privacy and data protection, accountability, security, IP, and compliance. 4.1 Human agency & accountability4.2 Privacy & data protection4.3 Security & safe use4.4 IP, ownership & attribution4.5 Compliance & policy
D5
AI Strategy & Management
Leading with AI — spotting where it adds value, setting guardrails, guiding adoption, and measuring impact. 5.1 Identifying opportunities & ROI5.2 Governance & policy-setting5.3 Change & adoption management5.4 Delegating work to AI5.5 Measuring impact

How the domains map to US governance

This is a cross-walk, not a competing standard. Below is where each domain connects to NIST AI RMF and ISO/IEC 42001 — so a baseline speaks in terms your risk, compliance, and L&D teams already use.

Domain NIST AI RMF ISO/IEC 42001
D1 · Foundations & Reality Map. Establishing context and understanding capabilities and limitations. Underpins the valid & reliable characteristic — you cannot judge reliability without knowing how the system works. 7.3 Awareness — baseline understanding across everyone doing work under the organization's control.
D2 · Critical Engagement & Judgment Measure. Serves the valid & reliable, fair — with harmful bias managed, and explainable & interpretable characteristics. This is where hallucination and bias are actually caught, by a person. 7.2 Competence — the judgment that separates a competent operator from a merely trained one.
D3 · Applied AI & Productivity Manage. The point of the whole exercise: value realized from AI, safely. Effective human oversight depends on operators who know the tool. 7.2 Competence — people whose work affects AI performance.
D4 · Responsible & Ethical AI Govern. Maps to the privacy-enhanced, secure & resilient, and accountable & transparent characteristics. Govern 2.2 lives here: personnel trained to act consistently with policy. 7.3 Awareness — the AI policy, their contribution to it, and the consequences of non-conformance.
D5 · AI Strategy & Management Govern. Leadership accountability, risk tolerance, and measurement — the function NIST places first because nothing else holds without it. Clause 5 (Leadership), Clause 6 (Planning), Clause 9 (Performance evaluation).

The practical consequence: a baseline against this framework produces exactly what ISO/IEC 42001 Clause 7.2 asks organizations to retain — documented evidence of workforce competence — and exactly what NIST Govern 2.2 asks them to assess. It also tells you where to spend the training budget, which neither standard does.

Want this for your own organization? We're running free pilots with a small number of design-partner companies — a full baseline for your team, in exchange for honest feedback.

Request a pilot →

Self-awareness, seen from three angles

The AI Maturity baseline is built on self-reflection — every component is read through two lenses: what a person does, and how they see themselves. A third lens, feedback from peers and leadership, is included with the portal and layered in after the self-reflection step, for a complete and balanced view of self-awareness.

The self-reflection baseline

Lens 1

Actions — what you'd actually do

Short, realistic situations ask you to choose the response closest to what you would most likely do. Each option reflects a level of practice and maps to a 1–10 scale, so choices become an evidence-based read of demonstrated judgment — not a self-estimate. Questions and answer order are randomized to keep the read honest.

Lens 2

Self-Perception — how you see yourself

One statement per component (for example, “My knowledge of how generative AI works is…”) is rated on a five-point slider from far below to far exceeds my expectation. This captures confidence and self-awareness alongside the behavioral measure.

Actions
 
7.2
Self-Perception
 
4.4

The distance between the two tracks is the coaching signal — the fastest read on where confidence and capability disagree.

Completing the picture

Lens 3 · included in the portal, after self-reflection

Feedback — how others see your work

Once self-reflection is complete, the same components can be opened to structured input from peers and leaders. Because the feedback items mirror the self-reflection items one-to-one, a person's own read sits directly alongside how their work actually lands with others — turning a private baseline into a rounded, 360° view of self-awareness. This lens always follows self-reflection; it never replaces it.

The practice rubric (Actions)

Within each situation, the response options ladder across four levels of practice, spread along the 1–10 scale:

Level What it looks like
Not yet No working approach yet, or holds a misconception.
Foundational Aware and safe; understands the basics.
Practitioner Applies it correctly and confidently in real work.
Leader Fluent and anticipatory; extends the practice and guides others.

The self-perception scale

Slider position Meaning
Far below My knowledge is far below my expectation.
Below Below my expectation.
Meets Meets my expectation.
Exceeds Exceeds my expectation.
Far exceeds Far exceeds my expectation.

Where the lenses diverge is where the work is

After a domain is complete, the Awareness Summary shows, for each component, the Actions result beside Self-Perception — and where the two diverge. That gap is the coaching signal:

Pattern What it suggests
Actions above Self-Perception People handle these situations more capably than they give themselves credit for — build confidence and stretch toward the next level.
Actions below Self-Perception There is more room to grow here than it feels — a good place to focus first.
Aligned Self-view matches demonstrated practice — confirm the level and choose the next goal.

When the Feedback lens is added, the same comparison runs against how others see the work — and a third pattern emerges: capability that a person cannot see in themselves, and confidence that others do not share.

At the organization level, these gaps aggregate into the finding leaders act on: where confidence outruns capability, and whether a healthy average is concealing a group that is struggling. From there, the framework points to targeted learning matched to each component and level, so a reflection ends in a plan, not just a score.

How scores roll up

Scores aggregate from the bottom up: individual responses form a rating for each component, components combine into a domain rating, and the five domains form an overall AI-maturity profile.

Responses Component Domain AI-maturity profile

Within a domain, components are weighted to total 100%; within a component, situational items are weighted to total 100%. Weights and emphasis can be tuned to an organization's priorities — a regulated firm may weight D4 more heavily than a design studio would — without changing the structure. The same engine scores every lens; it is signal-agnostic.

The US regulatory context

Current as of July 2026. The US AI statutory layer moves quickly and varies by state. In May 2026, Colorado repealed and replaced its own landmark AI Act (SB 24-205) with a narrower automated-decision statute before the original ever took effect.5 That is precisely why this framework is anchored on capability and the durable voluntary standards, not on any single law. Capability is what every one of these regimes presupposes — and it is the part that does not get repealed.

The direction of travel is nonetheless consistent, and it lands on the same place: organizations are increasingly accountable for what their people do with AI — particularly where AI touches employment, credit, housing, healthcare, insurance, or other consequential decisions about individuals.6

  • Employment discrimination law already applies. Title VII, the ADA, and the ADEA reach algorithmic decisions; using a tool does not transfer the liability. Illinois HB 3773 (Public Act 103-0804, effective January 2026) amends the Illinois Human Rights Act to bar discriminatory employer use of AI, and applies to employers with as few as one employee in the state.
  • Notice and audit duties are spreading. NYC Local Law 144 requires bias audits and candidate notice for automated employment decision tools. California's ADMT regulations (in force January 2026) add an automated-decision layer on top of the CCPA/CPRA, alongside the Transparency in Frontier AI Act and AB 2013. Colorado's replacement statute (SB 26-189, effective January 2027) centers on pre-use notice, adverse-outcome explanations, and a right to meaningful human review.
  • Some states legislate conduct, not process. Texas TRAIGA (HB 149, effective January 2026) took a narrow route: a short list of prohibited uses plus rules for state-government AI.

Across all of them, the same human requirement recurs: a person has to exercise meaningful oversight, catch the bias, honor the notice, and explain the outcome. A policy document cannot do any of that. Only a capable workforce can — which is the thing this framework measures.

Identified gap · planned

Component 4.6 — Transparency & disclosure to affected people

Our 24 components cover bias awareness (2.2) and human accountability (4.1), but not the duty running through nearly every US regime above: telling people when AI shaped a decision about them, and being able to explain it. Candidate notice under NYC LL144, pre-use notice under California's ADMT rules, and adverse-outcome explanation and human-review rights under Colorado SB 26-189 all turn on this single human capability, and we do not yet measure it. It is documented here as a planned addition to D4; the framework remains at 5 domains and 24 components until it ships.

Principles

  • A reflection, not a test. There are no right or wrong answers — only an honest picture of where a person is.
  • No AI scoring of the person. Results come from a person's own responses against a human-designed rubric; AI never judges or labels anyone.
  • Private and yours. Individual results belong to the individual; the organization sees only aggregated, anonymized team patterns — never a name against a score, and never shared or sold.
  • Human-in-control. The result is a mirror and a map. The person — and the organization — decide what to do with it.
  • Anchored to capability, not to a statute. Laws change; the human capability they all depend on does not. We build for the latter.

What's ours, and what it's grounded in

The domain architecture, the Actions / Self-Perception / Feedback lens construct, and the four-level practice rubric are 2gnoMe's own design. They are deliberately cross-walked to recognized US and international standards, so results speak a language leaders, boards, and auditors already use — and so an AI-maturity baseline connects directly to governance, risk, and workforce-readiness obligations.

Because these standards are actively evolving, we review alignment as they change.

References

  1. National Institute of Standards and Technology (NIST). Artificial Intelligence Risk Management Framework (AI RMF 1.0), 2023. The US reference framework for trustworthy AI; a living document currently under revision. nist.gov/itl/ai-risk-management-framework · NIST AI 100-1 (PDF)
  2. NIST AI RMF Playbook — Govern. Govern 2.2: personnel and partners receive AI risk-management training; organizations assess whether personnel have the necessary skills, training, and domain knowledge for their responsibilities. airc.nist.gov · Playbook · Govern · AI RMF Core
  3. NIST. Generative AI Profile (NIST AI 600-1), 2024 — a companion profile addressing risks unique to generative AI. NIST AI 600-1 (PDF)
  4. ISO/IEC 42001:2023 — Artificial intelligence management system. Clause 7.2 (Competence): ensure personnel affecting AI performance are competent and retain documented evidence of competence. Clause 7.3 (Awareness): the AI policy, individual contribution, and implications of non-conformance. Requirement 7 · Support · clause-by-clause summary
  5. Cooley LLP. “State AI Laws — Where Are They Now?”, April 2026. On Colorado's repeal-and-replace of SB 24-205 and the current state landscape. cooley.com · State AI Laws
  6. Baker Botts, “US AI Law Update,” January 2026; and King & Spalding on the state AI laws effective January 1, 2026 (Illinois HB 3773, California ADMT, Texas TRAIGA). bakerbotts.com · kslaw.com

Framework, rubric, and methodology © 2gnoMe. Cross-walked to the NIST AI Risk Management Framework (AI RMF 1.0) and ISO/IEC 42001:2023 workforce competence and awareness requirements; alignment reviewed as those standards evolve. Regulatory context current as of July 2026 and reviewed quarterly. Nothing here is legal advice.

Free for a limited number of design partners, in exchange for structured feedback. Individual results stay private to each person; the organization sees only anonymized team patterns.

Start your own baseline  ·  How we compare  ·  ← Back to ai.2gno.me