C CARI

Based on GAISO project research

How ready is your security function to govern AI risk?

CARI — the CISO AI Readiness Index — turns a vague sense of "we should probably do something about AI" into a number you can track, defend and act on. Six literacy areas, technology effectiveness and organizational leverage, combined into one live index.

Free on the App Store · iPhone & iPad · iOS 17+

The CARI Assess screen showing the live readiness score, current strategic zone and the six AI-literacy sliders.

What CARI measures

Most AI-governance assessments produce a maturity label and a slide. CARI produces a signed index that moves when something real changes — and tells you which intervention comes next.

Dimension 1

AI literacy

Rated across six areas, from what AI actually is to the regulation that binds you. Each area carries a five-band rubric, so a score is a judgement you can evidence rather than a guess.

Dimension 2

Technology effectiveness

Signed from −100% to +100%. Positive means your AI tooling accelerates prevention; negative means it adds false positives, friction and integration burden. Capable people with obstructive tools is a real failure state, and the index reflects it.

Dimension 3

Organizational leverage

How effectively literacy converts into reduced process time. Low leverage means the capability exists but the operating model stops it paying off — a different problem with a different fix.

See how the app puts these to work →

The model

CARI is deliberately simple arithmetic over honestly-scored inputs. The value is in the rubric that forces the conversation and in the change between assessments — not in false precision.

CARI = (LCISO · Teff) / (1 − α · LCISO)
LCISO — AI literacy · 0 to 1
The mean of six area scores. It approaches 1 asymptotically and never reaches it: a security function is never finished learning.
Teff — technology effectiveness · −1 to +1
Whether AI tooling accelerates prevention or adds overhead. Negative values produce a negative index regardless of literacy.
α — organizational leverage · 0 to 1
How well literacy converts into reduced process time. It amplifies the index and drives the process-hour estimate P(L) = P₀ · (1 − α · L).

The four quadrants

Plot AI literacy against technology effectiveness and every security function lands in one of four positions. The quadrant — not the raw score — is what determines which intervention comes next. Thresholds sit at literacy 0.5 and technology effectiveness 0.

Q1

Proactive defender

L ≥ 0.5 · T ≥ 0 — literacy high, technology helps

High literacy and technology that accelerates prevention. This is the target zone for CISO effectiveness.

What to do nextConsolidate rather than correct: formalise governance evidence, extend automation deliberately, and re-measure on a defined cadence so the position is demonstrably held rather than assumed.

Q2

Competent but slowed down

L ≥ 0.5 · T < 0 — literacy high, technology hinders

High literacy, but technology creates additional burden. The tool portfolio and operating model need correction, not the people.

What to do nextThe most tractable position in the model. Audit for overhead — false-positive volume, integration burden, analyst friction — and be willing to retire tools rather than tune them indefinitely.

Q3

Automated but vulnerable

L < 0.5 · T ≥ 0 — literacy low, technology helps

Useful technology with low human understanding. Deceptively comfortable: the tooling is carrying a function that cannot yet validate it.

What to do nextThe exposure is automation bias. Prioritise literacy and add human-in-the-loop checkpoints before extending autonomous action any further.

Q4

Critical risk zone

L < 0.5 · T < 0 — literacy low, technology hinders

Low literacy and technology that slows the CISO function down. Both dimensions are working against you and this requires intervention.

What to do nextSequence matters: stabilise first by pausing or constraining the highest-risk AI tooling, then start the literacy programme. Optimising tools the team cannot yet evaluate entrenches the wrong choices.

Vertical ↑ AI literacy, 0 → 1 Horizontal → Technology effectiveness, −1 → +1 Representative position

Mapped to the frameworks that bind you

CARI is built around the obligations a security leader is actually measured against. The EU AI Act makes AI literacy an explicit duty under Article 4; NIS2 puts cybersecurity risk measures on the management body personally. The app carries the provisions, not just the acronyms.

Regulation (EU) 2024/1689

EU AI Act

Art. 4 AI literacy, Art. 6 high-risk classification, Art. 9 risk management, Art. 10 data governance, Art. 13 transparency, Art. 14 human oversight, Art. 15 accuracy and cybersecurity.

Directive (EU) 2022/2555

NIS2

Art. 20 governance and management accountability including the training duty, Art. 21 risk-management measures and the obligation to assess their effectiveness.

Management system

ISO/IEC 42001:2023

The first certifiable AI management-system standard. Clause 9 performance evaluation is where a repeatable, dated readiness measurement belongs.

Voluntary framework

NIST AI RMF 1.0 · ENISA ECSF

GOVERN, MAP, MEASURE and MANAGE as a structuring vocabulary, and the European competence profile that defines what a CISO function should be able to do.

EU AI Act Art. 4EU AI Act Art. 14NIS2 Art. 20 NIS2 Art. 21ISO/IEC 42001 §9NIST AI RMF: MEASUREECSF: S-CISO

CARI is an assessment and strategy instrument. It is not legal advice, and it does not establish conformity with any framework it maps to.

Research foundation

CARI is not a marketing framework. The model, its six literacy areas and the quadrant logic are derived from the scientific research results of the GAISO project.

GAISO

GAISO project

Research on Cyber Resilience Through Application of Generative Artificial Intelligence in Chief Information Security Officer Operations

The GAISO project investigates how generative AI changes the work of the CISO function — where it strengthens cyber resilience, where it introduces new risk, and what competences a security leadership function needs in order to govern it. CARI operationalises those findings as a measurable, repeatable index that a security function can apply to itself.

gaiso.lt →

Nothing leaves your device

CARI has no accounts, no analytics, no advertising, no third-party SDKs and makes no network requests. Every calculation runs on-device, and saved assessments are stored in the app's own local storage — readable only by the app, never transmitted, never visible to the developer.

Delete the app and every saved assessment goes with it.

Read the full privacy policy →