Insight · AI Solutions · Microsoft Fabric

    Is Your Data Estate AI-Ready? The Checklist We Actually Use

    Before Copilot, agents or any AI over your data: the readiness checklist we run with clients across data foundations, semantic quality, security, governance and operations.

    Nick de Vrye, CTOPublished 7 September 20267 min read read
    Navy Solv Systems title card reading 'Is Your Estate AI-Ready?' with a checklist grid motif.

    In Short: Readiness Is a Property of the Estate

    Every failed AI rollout we have reviewed failed below the AI: data nobody verified, models machines could not read, permissions nobody tested, operations nobody owned. So before Copilot, before agents, we run one checklist across five areas, domain by domain. A domain that passes can face AI; a domain that fails has its remediation list. This post is that checklist, slightly compressed: twenty-five checks across the five areas.

    Run it honestly against two or three domains that matter and you will know more about your AI readiness than most strategy decks deliver.

    Area 1: Data Foundations

    • Is the domain's data in a governed platform with a single authoritative copy, rather than competing extracts?
    • Do the core tables have owners who would notice and act if the data broke?
    • Has the domain been profiled - nulls, ranges, duplicates, integrity - within the last quarter?
    • Are freshness and completeness monitored automatically, with alerts that reach a human?
    • Is refresh reliability boring? Chronic refresh failures disqualify a domain on their own

    Pass looks like: one source of truth, owned, profiled, monitored, reliable. The details of why each matters for AI are in our data quality for AI piece.

    Area 2: Semantic Quality

    • Are tables, columns and measures named in the business's own language?
    • Does every measure that matters carry a description stating meaning and calculation?
    • Is the model a proper star schema with verified relationships, per our star schema guide?
    • Are technical objects hidden, duplicates retired, and the authoritative model endorsed?
    • Has a bank of real business questions been tested against the model with scored answers?

    This area is the ceiling on answer quality, and the full method is in preparing your semantic model for AI.

    Area 3: Security Under AI Access

    • Has row-level security been tested with representative accounts asking conversational questions?
    • Are workspace and item permissions reviewed, with the over-shared cleaned up?
    • Are sensitivity labels applied to the domains that would make headlines - finance, HR, personal data?
    • Has an oversharing assessment run across the document estate, per our Purview DSPM for AI guide?
    • Do agents and service identities follow least privilege, inventoried and owned, per agent governance?

    The recurring failure: security that was probably fine under report access, never verified under AI access. Probably is not a pass.

    Area 4: Governance and Accountability

    • Is there a decision record of which domains are AI-enabled and who approved them?
    • Does every AI surface - Copilot scope, each data agent - have a named owner accountable for answer quality?
    • Are definitions for contested metrics agreed and written down, so AI has one truth to repeat?
    • Is there a review cadence where usage, wrong answers and expansion requests get decided?
    • Do users know what the AI can answer, what it cannot, and where to report a bad answer?

    Area 5: Operations and Cost

    • Is capacity sized for AI consumption on top of existing workloads, with Copilot consumption visible in monitoring?
    • Are AI costs attributed - by capacity, workspace or agent - so growth is a decision, not a surprise?
    • Is there monitoring on the AI layer itself: usage volumes, failure rates, latency?
    • Is there a rollback plan: can a domain's AI access be switched off cleanly if quality collapses?
    • Is someone reading the telemetry monthly and feeding it back into the remediation list?

    Using the Checklist Without Boiling the Ocean

    The point is sequencing, not perfection. Score two or three decision-critical domains, enable AI where they pass, remediate the specific failures where they do not, and expand on evidence. Developer-facing assistance can start immediately; viewer-facing answers and agents wait for their domain's pass. A quarter of focused work typically gets the first domains through, and the same work - quality, models, security, governance - improves ordinary BI whether or not the AI ambitions survive contact with the budget. That is what makes readiness the rare programme with no wasted branch.

    Sources and Further Reading

    Frequently asked

    That AI features can be enabled without producing wrong, leaked or ungoverned answers: governed data with known quality, semantic models machines can read correctly, security that holds under conversational access, and operations that notice when something breaks. It is a property of the estate, not of the AI.

    Scoped sensibly, a quarter: two or three decision-critical domains brought to pass across the checklist. Estate-wide readiness is a programme, not a prerequisite - the mistake is boiling the ocean before enabling anything, or enabling everything before checking anything.

    The checklist is platform-honest: most items apply to any modern estate. In the Microsoft stack, Fabric supplies the pieces the checks assume - OneLake as the governed foundation, semantic models as the AI-readable layer, Purview for labels and policy - which is why readiness and Fabric adoption often travel together.

    Row-level security verified under AI access. Most estates assert RLS is correct; few have tested it with representative accounts asking conversational questions. Second place: semantic models whose names and descriptions a machine could not possibly resolve correctly.

    No. Authoring assistance for developers is low-risk immediately. The checklist gates viewer-facing answers and agents, domain by domain: enable where the domain passes, remediate where it fails, and let evidence drive the expansion order.