Agentic AI readiness self-assessment

A Self-Assessment Framework for Leadership and Technical Teams

Sixteen questions, organized across four domains, to help you locate your institution's actual exposure — before an incident does it for you.

Discuss Your Answers With Us
Monochrome research computing control room
A useful question can reveal an architectural gap.

How to use this assessment

How to Use This Assessment

This isn't a scored quiz — it's a structured conversation starter. Work through each domain with the right stakeholders: compute and infrastructure, data governance, security, and research leadership. Anywhere the honest answer is “we don't know” or “not yet,” that's a priority area.

01

Domain 1: Compute Readiness

  • Do we know how many autonomous agents — not just human users — our infrastructure is currently supporting?
  • Have we modeled GPU, power, and thermal demand for agent-driven workloads specifically — not just projected human growth?
  • What happens to our capacity plan if agent activity doubles in the next six months?
  • Do we have a process to detect and respond to unplanned compute drift before it becomes a budget or reliability crisis?

02

Domain 2: Data Governance

  • Does our data classification travel with data when an agent copies, derives, or moves it into a new pipeline?
  • Do our data policies explicitly address autonomous agent access, or only human researcher access?
  • Can we trace, end-to-end, what happens to a sensitive dataset once an agent begins working with it?
  • Who is accountable if an agent surfaces or exposes data it shouldn't have accessed?

03

Domain 3: Governance & Approval Workflows

  • Do our approval workflows have a defined path for machine-initiated requests, not just human ones?
  • Can we produce an audit trail for agent-to-agent or agent-to-service activity today?
  • If an autonomous action produces an unintended outcome, do we know who owns the response?
  • Have we updated policy documentation to reflect agentic AI activity, or is it still silent on the topic?

04

Domain 4: Security & Runtime Behavior

  • Is our security monitoring tuned to detect anomalous agent behavior, or only anomalous human behavior?
  • Have we mapped cross-service data access paths that agents can traverse, end-to-end?
  • Does our incident response plan account for scenarios where an agent — not a person — is the source of an incident?
  • Have we stress-tested what happens when an agent has broader access than intended?

Next step

Ready to Talk Through What You Found?

If several of these questions surfaced gaps, the next step is a conversation about defense-in-depth direction — and, where it fits, an introduction to the right specialists.