Is Your Infrastructure Ready for AI? A Platform-by-Platform Check

A Black woman engineer and a friendly robot assistant inspecting glowing server blocks and small cloud shapes with a flashlight

Say “AI infrastructure” to most people and they picture racks of GPUs. For a handful of organizations, that’s the right picture. For a mid-size IT team, it almost never is. Your AI will run on someone else’s GPUs, delivered through SaaS assistants and cloud AI services. What you need to be ready is much less glamorous: identity that works in the cloud, a governed place to build, controls on usage-based spend, and logs that show what your AI is doing.

That’s what AI infrastructure readiness means for most teams, and the good news is that most of it builds on platforms you already run. This post walks through the four infrastructure questions in the AI Readiness assessment, then gives you a platform-by-platform check for the environments mid-size organizations most often use.

The four infrastructure questions

The infrastructure dimension of the assessment asks four questions. Each has its own detailed guide in this series.

  1. Infrastructure posture: are you mostly on premises, hybrid, or cloud-first? You don’t need to migrate for AI, but you do need cloud identity and a governed landing zone before anyone builds. See cloud readiness for AI workloads.
  2. Access to enterprise AI: do people have a governed AI assistant, or only consumer tools? Getting one department onto an enterprise assistant is the most valuable single move. See consumer AI vs. enterprise AI.
  3. Operations automation: are your operations scripted, version-controlled, and documented? The same discipline is what lets you see and control what AI does. See observability for AI.
  4. Cost visibility: can you see and control cloud and SaaS spend before the invoice? Usage-based AI needs budgets and alerts from day one. See budgets and alerts for usage-based AI spend.

The pattern I see most often

The typical mid-size profile on these four questions: hybrid infrastructure with key SaaS apps, a consumer-only or pilot-stage AI assistant, operations that depend on a few people’s unshared scripts, and cost visibility that stops at the monthly invoice. None of that blocks AI. It does mean the first ninety days should focus on a governed assistant, a governed place to build, and budgets with alerts, in roughly that order.

The platform-by-platform check

Most mid-size organizations run on one main productivity suite, one or two clouds, and some remaining on-premises systems. Here’s what to check on each. Feature names and license requirements change often, so confirm current details in each vendor’s own documentation.

Microsoft 365 and Azure

  • Identity: users synchronized to Entra ID, MFA enforced, SSO for AI tools, and conditional access if your licenses include it.
  • Content permissions: SharePoint and OneDrive sharing reviewed, with no sensitive sites open to everyone. This is the big one before any Copilot rollout.
  • Data protection: Purview sensitivity labels and DLP in place, and audit logging on and retained.
  • A place to build: a separate Azure subscription for AI work, with policy guardrails, approved regions, and logging.
  • Cost: Azure budgets and alerts on the AI subscription, and usage reports for any per-seat AI licenses.

Google Workspace and Google Cloud

  • Identity: 2-step verification enforced, SSO for AI tools, and admin control over which third-party apps can access Workspace data.
  • Content permissions: Drive sharing defaults and shared drives reviewed, with link sharing restricted for sensitive content.
  • Data protection: Drive labels and DLP rules for your most sensitive data types.
  • AI controls: Gemini features reviewed in the admin console, enabled for the groups you’ve approved.
  • A place to build: a separate Google Cloud project or folder for AI work, with organization policies, budgets, and audit logs.

AWS

  • Identity: console access through SSO, with no day-to-day use of root credentials.
  • A place to build: a separate account for AI work within your AWS organization, with guardrails on services and regions.
  • Model access: which models on Amazon Bedrock may be used, controlled through IAM policies and approved deliberately.
  • Logging: CloudTrail enabled for the account, with logs sent to your central platform.
  • Cost: AWS Budgets with alerts on the AI account, and tags for owner and project.

On-premises and hybrid

  • Identity: on-premises directory synchronized to your cloud identity provider, so AI tools can use SSO.
  • Data reach: connectors or gateways that let approved AI tools reach on-premises systems without exposing them publicly.
  • Network: bandwidth and egress costs checked if you plan large-scale document ingestion.
  • Self-hosted models: only if a specific need justifies it, such as data that can’t leave your premises or edge latency requirements.

Your major SaaS applications

  • AI features: which are available, which are on by default, and whether an administrator can turn them off.
  • Data terms: whether the vendor uses your data to train models, and where that’s stated in the contract.
  • Inventory: each AI feature recorded in your AI inventory.

The asset: a one-page infrastructure readiness summary

After working through the platform checks, summarize them on one page for leadership. For each platform you run, record:

  • Identity ready: yes, partly, or no.
  • Permissions reviewed: yes, partly, or no.
  • Governed place to build: yes, partly, or no.
  • Cost controls in place: yes, partly, or no.
  • Logging on and central: yes, partly, or no.
  • Top gap and owner.

A table with your platforms down the side and those five checks across the top fits on one slide, and it answers the question leadership actually has: “Can we start?”

A decision rule for starting

You can start with a licensed AI assistant as soon as identity and permissions are ready on that platform. You can start building on cloud AI services as soon as you have a governed place to build with cost controls and logging. The other gaps can close in parallel. That rule stops infrastructure work from becoming a reason to delay indefinitely, while making sure the few prerequisites that genuinely matter are in place.

A 90-day infrastructure plan

Days 1 to 30: confirm cloud identity and SSO on your main platform, review content permissions, and license a governed AI assistant for one department.

Days 31 to 60: stand up a separate, governed account or subscription for AI building, with budgets, alerts, tagging, and logging from the start. Move existing scripts and automations into a shared repository.

Days 61 to 90: connect your first use case’s systems through dedicated identities, route AI logs to your central platform, and write the runbooks for an AI incident and a cost spike. At the end, fill in the one-page summary again and compare it with where you started.

What AI infrastructure readiness is not

It’s not a GPU purchase. For most mid-size organizations, owning AI hardware is a later decision, if it’s ever needed at all.

It’s not a migration. AI is a good reason to finish a cloud strategy you already have, and a poor reason to start a lift-and-shift you weren’t planning.

It’s not a new platform. Most of what you need is already in the licenses and clouds you run. It’s configuration and discipline more than purchasing.

How infrastructure fits with the other five dimensions

Infrastructure is one of six dimensions in the AI Readiness framework. It overlaps with security through identity, with skills because someone needs to know the platforms well, and with governance through cost and logging. For the whole framework, see the 6-dimension AI readiness framework, explained.

Where does your team actually stand?

The free AI Readiness Score includes infrastructure questions alongside the other five dimensions. It’s 10 questions and gives you a score in a few minutes.

Get your free AI Readiness Score →

Want to see what the full assessment covers first? Flip through a complete 38-page sample report.

Related guides

Frequently asked questions

What does AI infrastructure readiness mean for a mid-size organization?

Not buying GPUs. It means cloud identity that works with AI tools, a governed place to build, controls on usage-based spending, and logs that show what AI is doing. Most of it builds on platforms you already run.

When can we start using an AI assistant?

As soon as identity and permissions are ready on the platform the assistant runs on. Building on cloud AI services can start once you have a governed place to build with cost controls and logging. Other gaps can close in parallel.

What should we check on our main platform before using AI?

Identity with MFA and SSO, reviewed content permissions, data protection such as labels and DLP, a separate governed account or subscription for building, budgets with alerts, and logging sent to your central platform. Confirm current feature and license details in your vendor's own documentation.

Is infrastructure usually the strongest or weakest readiness dimension?

In the mid-size organizations I assess, it's often the strongest: a clear main platform and hybrid experience. That's why infrastructure work rarely needs to delay AI, and why strong infrastructure can't make up for weak security or governance.

Scroll to Top