Where Does Your AI Program Actually Stand?
Your teams are already using AI. Legal drafts with it, finance models with it, engineering ships with it. You know that carries risk. What most leaders cannot do is point to where the risk actually sits: which model is holding trade secrets, which autonomous agent is acting under an identity no one inventoried, or which team pasted client data into a public tool. The AI Altitude Assessment, a 40-question diagnostic from JetStream, is built to find those answers before they find you.
The blind spots are structural, not careless. When adoption is mandated from the top, usage spreads faster than any control built to govern it. Risk then scatters across areas that no single owner tracks: who sanctioned which tool, which identities the agents run under, what data left the building, and whether anyone can prove it later. You cannot manage a risk you have never named.
These are not hypothetical concerns. A general counsel who pastes a litigation strategy memo into a public model may waive attorney-client privilege over that document, a risk we mapped in The AI Risks Your Enterprise Isn’t Seeing. A Nevada federal court has already barred a party from uploading discovery material into public AI tools. One regional bank had to disclose in an SEC 8-K filing that an employee used an unauthorized AI tool to access non-public customer information. The exposure is legal, and it is landing now.
The technical exposure is moving just as fast. Attackers are targeting large language model API keys directly, using stolen keys to run up spend and reach the data behind them, a pattern we documented in LLM Keys Are Being Targeted. Autonomous agents raise the stakes again. Every agent connected through Model Context Protocol (MCP) can read files, query databases, and act on your behalf, often under identities no one inventoried. We wrote about that sprawl in Governing the MCP Sprawl. Controls built for human users do not automatically cover software that behaves like one.
From uncertainty to a map
The AI Altitude Assessment is a live diagnostic, not a static questionnaire. Its 40 questions span eight domains across the full AI lifecycle: AI governance and strategy, legal and data privacy, advisory and technical testing, shadow AI discovery, AI cost and key security, identity and access, agentic and MCP security, and end-user training. For each question, you pick the level that best describes your current practice, on a six-point scale from Not Addressed to Optimized, and your score updates as you go, so your gaps surface while you are still working through it. The assessment rolls those answers into an overall Altitude Score and places your program in one of five maturity bands, from Foundational to Leading.
The result is not a grade. It is a plan. Each domain scores on its own, so the report names your specific gaps instead of burying them in a single blended average. You get a domain-by-domain breakdown that flags your strongest area and your top priority, a prioritized set of recommendations for what to fix next, and three takeaways from every run: an interactive results page, a whitepaper-grade PDF, and an eight-slide executive readout you can take straight into a leadership meeting.
See where you stand
Governance is not a brake on AI adoption. It is what lets you move faster with confidence, because you finally know where you stand. The assessment runs in a single sitting and gives you a defensible read on your exposure before your next board meeting, your next audit, or your next deployment.
Take the AI Altitude Assessment at jetstream.security/ai-maturity-assessment.