Editor’s Note: CMMI Institute recently released the CMMI AI Maturity (AIM) model, designed to drive sustainable innovation and measurable enterprise performance outcomes with AI adoption. In the following Q&A, hear from Government Technical Services Corporation (GTSC), one of the participants of the CMMI AIM pilot program on why they participated, what they’ve changed since receiving guidance, their measurable results and more. Learn more about CMMI AIM.
Why did GTSC choose to participate in the CMMI AIM pilot?
AI was already a core component of GTSC’s 2026 strategic direction, with use expanding across multiple functions. GTSC recognized that adoption was moving faster than the governance, processes and controls needed to support it. Addressing that gap early gave us an opportunity to build a stronger foundation before scaling further.
The AIM pilot gave us an early opportunity to assess AI maturity across the organization, define priorities and establish a more disciplined approach to enterprise AI governance. It also helps position GTSC for its planned Maturity Level 5 (ML5) and AIM Benchmark Appraisals in 2027.
What AI-related risks or challenges were you most concerned about prior to utilizing the CMMI AIM framework, and how has CMMI AIM helped with implementing safeguards?
Our central concern was that organic AI adoption could move faster than our ability to govern it consistently. That included data security and intellectual property risks from third-party tools, varying client restrictions, unclear enterprise ownership, inconsistent tool approvals and limited visibility into AI use and effectiveness. AIM helped us identify where those risks required clearer ownership, controls and measurement.
What are the biggest changes GTSC made after receiving guidance from CMMI AIM?
The AIM pilot changed the conversation from “should we do more with AI” to “here is exactly what we need to build, by when and who owns it.” The evaluation gave leadership clear, practice-area-specific insight into where governance and processes had not kept pace with active AI use.
In response, GTSC launched an enterprise-wide AI initiative and:
- Appointed a Chief AI Officer with defined authority and accountability;
- Integrated AI governance into security and risk frameworks;
- Began building role-based AI training across the organization;
- Embedded AI considerations into quality audits; and
- Aligned AI execution with established CMMI-based processes.
Together, these actions moved AI from a collection of individual efforts toward a managed enterprise capability.
What are your top priorities for the next year to safely scale AI?
Our priorities are straightforward: standardize what is already working, turn policy into practical guardrails, build role-based competency and measure results while keeping human oversight in the loop.
- Scale deliberately. We are addressing the highest-value gaps first and keeping AI within the CMMI and ISO process architecture we already trust. That approach also supports our planned 2027 appraisals.
- Turn policy into guardrails. A policy nobody can act on is theater. We issued our first enterprise AI security policy in 2026 and are translating it into practical controls with defined thresholds, required checks, accountable owners and automation where it makes sense.
- Standardize what works. We are taking proven practices from teams such as our Weather Group, documenting them and making lessons learned available across the organization.
- Build role-based competency. Not everyone needs to be a power user. We are defining AI competencies by job family so employees receive the depth of training their roles require – but can go deeper, as needed.
- Measure what matters. We are establishing measures for AI use, adoption and effectiveness so we can manage the capability with evidence and demonstrate its return.
- Keep the human in the loop. As AI output grows, subject matter experts remain essential reviewers. One of the greatest operational risks is the “AI handoff,” when everyone assumes someone else checked the work.
What would you tell other organizations that may be considering utilizing CMMI AIM?
Go in looking for gaps, not a good score. We asked for the hardest possible look at our AI adoption, and that is what made the experience valuable.
A few lessons stand out:
- Read findings as risk ratings, not grades. In an AI evaluation the tolerance is deliberately low, so anything in doubt gets flagged. A weakness identifies a higher-risk gap to address; it is not a failure.
- Expect variable maturity. An organization with a mature process foundation can be strong in competency, quality and governance while still having gaps in a new capability such as AI.
- Do not confuse adoption with maturity. Capable AI users can produce real results while the organization still needs greater standardization.
- Establish foundational controls before scaling adoption, including a clear AI use policy and IT guardrails. Governance is not the brake; it is the steering.
- Invest in training and internal ownership. Our Building Organizational Capability and Building Artificial Intelligence Maturity training across departments gave us a shared vocabulary for the work.
- Make the assessment cross-functional. Quality, engineering, recruiting, business development, operations and security all brought department-level insight that strengthened the evaluation.
- Do not fix everything at once. Prioritize the highest-risk gaps, strengthen the policies behind them and build from there.
Now that the pilot has been complete for about six months, has anything new been uncovered? What measurable results have you seen so far?
The biggest development is that AI governance has moved from plan to practice. It now operates within our normal quality, security and change-control processes rather than as a separate initiative.
Since the pilot, we have:
- Issued GTSC’s first enterprise AI security policy through our Change Control Board, covering authorized company-managed accounts and technical safeguards. Rollout is underway through manager briefings, companywide communications and a dedicated AI channel.
- Converted the evaluation findings into a tracked action plan with defined steps, owners and measures. The road map is now active work, not a document on a shelf.
- Extended AI governance into our security program, bringing approved AI tool use under central management and establishing supporting security policy and technical controls.
- Made AI governance a standing item in executive reporting and internal quality audits.
The clearest results are operational. AI-augmented modernization at our Weather Group delivered in about one month work that was estimated at three to four months without AI. AI-assisted capture produces compliance-checked proposal work packages in hours rather than weeks, and our recruiting dashboard has improved hiring visibility and workload tracking. GTSC deliberately paced adoption to put guardrails in place first, and the operational results above are what that approach has returned so far.
We are also establishing enterprise measures behind those results, including training completion, documented AI processes by department, AI findings in quality audits and consistency of tool approval.
What was the biggest challenge when adopting AIM, and how did you overcome it?
The biggest challenge was realizing that AI was everywhere at GTSC and nowhere at the organizational level.
Teams were using AI effectively, but often in isolation. We had real capability and results in pockets without a consistent organizational layer asking the same questions across the enterprise: Are we using AI responsibly? Are we mitigating risk? Do we have the right policies, processes and awareness in place? Are we implementing guardrails for security and protecting our data appropriately?
The AIM evaluation brought that gap into focus. The findings showed that the underlying capability was real, but practices were not yet consistently standardized at the organizational level. Read as risk ratings rather than grades, the weaknesses became a useful road map for improvement.
We treated the results as a mandate rather than a critique. Our CEO appointed a Chief AI Officer with clear authority and a structured mandate, and our newly certified practitioners helped create internal ownership of the findings. We started with foundational controls and the highest-risk gaps, then brought AI into the CMMI governance discipline we already trusted rather than creating a parallel structure.
Closing risk gaps is how a disciplined organization adopts something new. Our participation in the AIM pilot provided us a framework and the enterprise insights our organization needed.