Based on GAISO project research
CARI — the CISO AI Readiness Index — turns a vague sense of "we should probably do something about AI" into a number you can track, defend and act on. Six literacy areas, technology effectiveness and organizational leverage, combined into one live index.
Free on the App Store · iPhone & iPad · iOS 17+

Most AI-governance assessments produce a maturity label and a slide. CARI produces a signed index that moves when something real changes — and tells you which intervention comes next.
Rated across six areas, from what AI actually is to the regulation that binds you. Each area carries a five-band rubric, so a score is a judgement you can evidence rather than a guess.
Signed from −100% to +100%. Positive means your AI tooling accelerates prevention; negative means it adds false positives, friction and integration burden. Capable people with obstructive tools is a real failure state, and the index reflects it.
How effectively literacy converts into reduced process time. Low leverage means the capability exists but the operating model stops it paying off — a different problem with a different fix.
CARI is deliberately simple arithmetic over honestly-scored inputs. The value is in the rubric that forces the conversation and in the change between assessments — not in false precision.
Plot AI literacy against technology effectiveness and every security function lands in one of four positions. The quadrant — not the raw score — is what determines which intervention comes next. Thresholds sit at literacy 0.5 and technology effectiveness 0.
L ≥ 0.5 · T ≥ 0 — literacy high, technology helps
High literacy and technology that accelerates prevention. This is the target zone for CISO effectiveness.
What to do nextConsolidate rather than correct: formalise governance evidence, extend automation deliberately, and re-measure on a defined cadence so the position is demonstrably held rather than assumed.
L ≥ 0.5 · T < 0 — literacy high, technology hinders
High literacy, but technology creates additional burden. The tool portfolio and operating model need correction, not the people.
What to do nextThe most tractable position in the model. Audit for overhead — false-positive volume, integration burden, analyst friction — and be willing to retire tools rather than tune them indefinitely.
L < 0.5 · T ≥ 0 — literacy low, technology helps
Useful technology with low human understanding. Deceptively comfortable: the tooling is carrying a function that cannot yet validate it.
What to do nextThe exposure is automation bias. Prioritise literacy and add human-in-the-loop checkpoints before extending autonomous action any further.
L < 0.5 · T < 0 — literacy low, technology hinders
Low literacy and technology that slows the CISO function down. Both dimensions are working against you and this requires intervention.
What to do nextSequence matters: stabilise first by pausing or constraining the highest-risk AI tooling, then start the literacy programme. Optimising tools the team cannot yet evaluate entrenches the wrong choices.
CARI is built around the obligations a security leader is actually measured against. The EU AI Act makes AI literacy an explicit duty under Article 4; NIS2 puts cybersecurity risk measures on the management body personally. The app carries the provisions, not just the acronyms.
Art. 4 AI literacy, Art. 6 high-risk classification, Art. 9 risk management, Art. 10 data governance, Art. 13 transparency, Art. 14 human oversight, Art. 15 accuracy and cybersecurity.
Art. 20 governance and management accountability including the training duty, Art. 21 risk-management measures and the obligation to assess their effectiveness.
The first certifiable AI management-system standard. Clause 9 performance evaluation is where a repeatable, dated readiness measurement belongs.
GOVERN, MAP, MEASURE and MANAGE as a structuring vocabulary, and the European competence profile that defines what a CISO function should be able to do.
CARI is an assessment and strategy instrument. It is not legal advice, and it does not establish conformity with any framework it maps to.
CARI is not a marketing framework. The model, its six literacy areas and the quadrant logic are derived from the scientific research results of the GAISO project.
Research on Cyber Resilience Through Application of Generative Artificial Intelligence in Chief Information Security Officer Operations
The GAISO project investigates how generative AI changes the work of the CISO function — where it strengthens cyber resilience, where it introduces new risk, and what competences a security leadership function needs in order to govern it. CARI operationalises those findings as a measurable, repeatable index that a security function can apply to itself.
CARI has no accounts, no analytics, no advertising, no third-party SDKs and makes no network requests. Every calculation runs on-device, and saved assessments are stored in the app's own local storage — readable only by the app, never transmitted, never visible to the developer.
Delete the app and every saved assessment goes with it.