Within a single six-month window, the stewards of this domain shipped maturity models at speed.
OWASP’s GenAI Security Project published its Enterprise Adoption Maturity Model on June 3, 2026. SANS released its AI Security Maturity Model in May 2026. The Cloud Security Alliance published its Agentic Trust Framework in February 2026. NIST’s AI Risk Management Framework carries an agentic profile, and NIST has named agent interoperability as a domain to be standardized, with an interoperability profile still in development.
Each is the product of serious work by people who have done the work. None is wrong. The problem is not quality. The problem is that all four return a number that uses the same word — Level 0, Stage 1, maturity tier — and a board reads those numbers as if they were the same number. They are not.
What a zero is
Every scale has a zero. The zero is the point where the thing being measured is absent. Celsius and Kelvin disagree about where to put that point, but they measure the same quantity — temperature — so a conversion between them exists and is exact. Celsius and decibels share neither a zero nor a quantity. There is no conversion. The expression “twenty degrees plus thirty decibels” is not wrong; it is meaningless. Nothing is being added.
The four stewards are closer to Celsius-and-decibels than to Celsius-and-Kelvin. Their zeros are zeros of different objects. When OWASP or SANS marks an organization at the bottom of its scale, the absent thing is a governance program. When the Cloud Security Alliance marks an agent at the bottom of its ladder, the absent thing is earned trust — this particular agent has demonstrated nothing yet and is held to read-only. When the interoperability fabric is at the bottom, the absent thing is the capacity of agents to coordinate across boundaries at all. Three different nothings. The grades that climb away from those three floors are climbing away from three unrelated origins.
The object a model grades
It helps to have a name for the thing a maturity model is actually measuring. We will call it the unit of assessment — the object the grade is attached to. This term, and the recognition that the agentic maturity models in circulation attach their grades to three different units, is our analytical contribution; it is not drawn from any single steward’s framework, though each framework, read carefully, reveals which unit it has chosen.
Read against that lens, the four resolve into three units. The enterprise’s governance program — graded by OWASP and SANS, and by the adoption models the hyperscalers publish. The individual agent — graded by CSA, which promotes an agent up a trust ladder as it earns the right to act. The interoperability fabric — the connective substrate between agents, the unit NIST has named for standardization but not yet graded, and which the academic literature describes as barely begun.
A maturity model is only coherent once you know which of these three it has in hand. “We are mature” is not a claim until the unit is named.
Why this is structural, not vocabulary
The easy dismissal is that the industry simply hasn’t standardized its terms yet, and that a future consortium will harmonize the scales into one. That is the wrong reading. The incommensurability is not a labeling accident waiting for cleanup. It follows from the units being different objects with independent failure behavior — a point the empirical record makes plainly, and which the next post takes up directly.
Two cautions keep this honest. First, the temperature analogy is a teaching device, not a claim that these scales are formal interval measures; maturity ladders are ordinal at best. If anything that strengthens the argument — ordinal scales are even less reconcilable than the analogy implies, not more. Second, naming three units does not rank them. None is the real one. An enterprise carries all three at once, and the next four posts take each in turn before the series closes on how a board reads three grades together instead of mistaking one for the whole.
The value of a maturity model is that it makes a fuzzy question auditable. That value is destroyed the moment a grade attached to one object is read as a grade of another.
Before an enterprise adopts any agentic maturity model, the first discipline is not scoring — it is naming the unit of assessment the model grades, and refusing to let a single number stand in for a posture it cannot represent. There is no shared zero. Everything else follows from that.
