AI Infrastructure Readiness Assessment at 10 to 200 People

Avolis Research Group

·

·

20 min read

In 2018 Census data, cloud buyers were 5 points likelier to use AI. What an AI infrastructure readiness assessment should check at 10–200 people and what waits.

For a business with 10 to 200 people, an AI infrastructure readiness assessment checks whether the systems you already run can hand an AI tool the information it needs, safely, and take the result back without anyone retyping it. It isn't about buying servers or chips. The AI runs in someone else's data center, so what you're really assessing is the connections into it.

Most of what ranks for this term was written for a different buyer. None of the 14 top-ranking pages we reviewed in September 2026 named a company size under 200 employees, and one widely cited benchmark, Cisco's AI Readiness Index, surveys only organizations with more than 500 (Cisco, AI Readiness Index 2025, October 2025). Half of those 14 pages frame infrastructure around GPUs, data centers, and power and cooling, which are fair questions for a bank or a hospital network. They're the wrong questions for a 60-person plumbing and HVAC company, whose infrastructure is a field service app, an accounting package, a shared inbox, forty phones in forty trucks, and the spreadsheet on the office PC that quietly runs the week.

The compute side of the problem has mostly been solved for you. In its 2025 AI Index, Stanford HAI reported that the cost of running a model at the level of GPT-3.5 fell more than 280-fold between November 2022 and October 2024 (Stanford HAI, AI Index Report 2025). What's left for a smaller operation is everything around the model: where your data lives, whether it can get out, who can log in, and how you'd recover if something broke.

This page is the systems piece of our guide to AI readiness assessment services, which covers all six areas an assessment should examine. We should be upfront about one thing. Avolis runs diagnostics that include this check, which gives us a stake in how you read it. So we've written the page to be usable without us: most of what follows you can do yourself in an afternoon, and we point to the free government guide that covers the security half.

Key Takeaways

  • At 10 to 200 people, AI infrastructure readiness means your software, connections, logins, and backups, not servers or GPUs, because you rent the compute by subscription or by use.
  • Stanford HAI's 2025 AI Index found GPT-3.5-level AI got more than 280 times cheaper to run between November 2022 and October 2024.
  • In 2018 Census data, firms that bought cloud services were 5 percentage points more likely to use AI (McElheran and others).
  • Of workers who use AI at small and medium companies, 80% bring their own tools rather than ones the business provides (Microsoft and LinkedIn, 2024).
  • Most gaps aren't blockers. No IT staff, older laptops, and no central reporting database rarely stop a first build, while shared logins and untested backups should be fixed first.

Table of Contents

What Is an AI Infrastructure Readiness Assessment?

An AI infrastructure readiness assessment checks whether your technology can support a specific AI workflow: where your systems live, how they connect, who can get into them, and how you'd recover if one failed. Most of the top-ranking pages for this term assess a data center's worth of hardware, which is a different job from the one a 10-to-200-person operation needs done.

The word "infrastructure" carries most of the confusion, because it means something different at each end of the market. Here's the same list of categories as an enterprise assessment would use, translated for an operation your size:

Layer In an enterprise assessment At 10 to 200 people
Compute GPU clusters, power, and cooling Rented from an AI provider, by subscription or by use
Storage Data lakes and warehouses (central databases built for reporting) The systems you already run jobs in: field service, CRM, property management, accounting
Network High-bandwidth links between servers Office internet, plus the cell signal your crews get on a job site
Integration API gateways and a middleware team Whether each system can send and receive data, and on which plan tier
Security A security operations center Named logins, multifactor authentication, tested backups, and a list of who has admin rights
Operations A machine learning operations team One named person who owns each system and knows the vendor's support number

Readiness is also always relative to a workflow, which is the part generic checklists miss. Drafting quote follow-up emails needs little more than access to your CRM and your email, and many businesses could start that quickly. Suggesting the next day's dispatch board needs the live schedule, each technician's skills, and job locations in one place that software can read, which is a much taller order. The assessment's job is to tell you which workflows your current setup can already support and which ones need something fixed first.

It's also narrower than a full readiness assessment. Whether your records are complete and accurate is a data question, which our data readiness assessment guide covers. This page is about the pipes, not the water.

Why You Rent the Compute Instead of Buying It

Smaller operations don't need their own AI hardware, because the models run on providers' servers and you pay for what you use. Stanford HAI's 2026 AI Index counts 5,427 data centers in the United States, more than 10 times any other country, and that's the kind of facility where the AI tools your team uses actually run (Stanford HAI, AI Index Report 2026).

The price of using those data centers has also collapsed. The 280-fold fall in the cost of GPT-3.5-level performance that Stanford measured means that the model is now rarely the expensive part of an AI workflow for a business your size. In our builds, the cost that decides whether a workflow is worth doing is almost always the time it takes to connect the model to your systems and get your people using it, and almost never the usage bill. (That's our own client work, not independent research.)

In other words, the question has moved. It used to be whether you could afford the machine, and now it's whether your systems can talk to it. The largest representative study of what travels with AI use at ordinary US firms points the same way. In the 2018 Annual Business Survey, which covered about 850,000 firms, 43% bought cloud services for at least one IT function. Firms that did were 5 percentage points more likely to use AI after controlling for industry, location, size, and age. That's a wide gap at a time when only 5.8% of firms used AI at all (McElheran and others, AI Adoption in America: Who, What, and Where, NBER Working Paper 31788, October 2023; published in the Journal of Economics & Management Strategy, 2024).

Two caveats belong with that finding. It's a correlation, so it doesn't prove that moving to the cloud causes AI use, and the data predates generative AI, the kind that drafts text and answers questions in plain language. Still, the researchers conclude that digital information and cloud computing "appear in our analysis to be central to AI adoption" across a broad range of firms, and that matches what we see in our client work. A business whose systems already live online, with data that can be reached from outside the office, has most of the infrastructure it needs.

Citation-ready summary: In the Census Bureau's 2018 Annual Business Survey of about 850,000 US firms, 43% purchased cloud services for at least one IT function, and those firms were 5 percentage points more likely to use AI than comparable firms that didn't, when only 5.8% of all firms used AI (McElheran and others, NBER Working Paper 31788).

So where does that leave the server in the closet? Older desktop accounting software, a file server only reachable from inside the office, and job records on one person's laptop aren't disqualifying. They do usually decide which workflows are ready now, because an AI tool can't work with information it has no way to reach.

The Six Things to Check

For a smaller operation, an AI infrastructure readiness assessment comes down to six checks, and most of them can be done in an afternoon with whoever pays the software bills. The check with the sharpest evidence behind it is logins: in 2023, Microsoft researchers found that multifactor authentication cut the risk of an account being compromised by 99.22% across the Microsoft business accounts they studied (Meyer and others, How Effective Is Multifactor Authentication at Deterring Cyberattacks?, Microsoft, May 2023).

Check The question Ready looks like Not yet looks like
1. Where systems live Is each system online, or on a PC or server in the office? Software you log into from anywhere, including the truck Desktop software on one office PC, or files on a drive only one person can reach
2. Whether systems connect Can data get out and back in without retyping? A documented connection or scheduled export on your current plan Manual exports only, or a connection that sits on a plan you don't pay for
3. Who logs in Does each person have their own account? Named accounts, with multifactor on email and the main systems One shared office login, and former employees still active
4. What AI is already running Which AI tools are people using today, and on whose accounts? Company accounts and a short written rule on what can go in Personal free accounts with customer details pasted in
5. How you'd recover If a system locked up tomorrow, what would you lose? Backups tested, updates on, vendor contacts listed Nobody knows when the last backup ran
6. Who owns each system Who holds admin rights and the vendor relationship? One named owner per system, written down The admin password left with a former office manager

For how these checks sit alongside the other five readiness areas, and how each area is weighted, see our AI readiness assessment methodology.

1. Where Your Systems Live

Start with a plain list of every system the business runs on, and mark each one as online (you log in through a browser or an app) or local (it's installed on a machine in the office). Online systems are almost always easier to connect an AI tool to, because their vendors expect other software to reach them. Local ones aren't impossible, but they often mean an export someone runs by hand.

Then check where the work actually happens, because for a trades business that's often a basement, a rooftop, or a crawl space. A workflow that depends on a technician uploading photos from a mechanical room has to survive having no signal until they walk back to the van. That's an infrastructure question too, and it's cheaper to answer before a build than after.

2. Whether Your Systems Connect

This is the check that decides the most, and it's the one owners know least about. Most business software offers an API, which is a documented doorway that lets one program ask another for information or send it some. If your field service software has one, an AI workflow can read a new job as soon as it's booked, draft the estimate, and write it back into the same record for your estimator to check before it goes out. If it doesn't, someone is exporting a spreadsheet by hand and uploading it somewhere else. The time saved shrinks fast.

Two details catch people out. Some vendors only include that doorway on a higher-priced plan, so check your plan's feature list rather than the product's marketing page. And the best single measure of how connected you are is how often somebody retypes the same information. Count the fields a job gets copied through on its way from first phone call to paid invoice, and you'll have a rough map of where connecting systems pays.

3. Who Logs In, and How

AI tools inherit the access of the account they're connected through. If your office runs on one shared login to the CRM, any AI assistant connected through it can see everything that login sees, and you won't be able to tell afterward who did what. Named accounts for each person, with former employees switched off, are the foundation for everything else here.

Multifactor authentication, the code or app prompt you get after your password, is the cheapest fix on this page. The Microsoft study found it cut compromise risk by 98.56% even for accounts whose passwords had already leaked. Stolen passwords matter at every size. In Verizon's 2025 report, using stolen credentials was the most common hacking technique at businesses under 1,000 employees, at 33% (Verizon, 2025 Data Breach Investigations Report: SMB Snapshot). That makes switching multifactor on for email and the main systems worth doing whether you ever add AI or not.

4. What AI Is Already Running

If anyone on your team uses AI, they're probably doing it on tools the business never chose. In 2024, Microsoft and LinkedIn's Work Trend Index found that 78% of AI users were bringing their own AI tools to work, and that it was even more common at small and medium-sized companies, at 80% (Microsoft and LinkedIn, AI at Work Is Here. Now Comes the Hard Part, May 2024). It's the estimator pasting a scope into a free chatbot to tidy the wording, or the office lead summarizing a long customer email thread.

AI Infrastructure Readiness Assessment at 10 to 200 People - Avolis AI Most workplace AI runs on personal accounts Employees routinely using GenAI on corporate devices, by account type 72% 17% 11% Personal (non-corporate) email as the account login Corporate email, but no integrated company sign-in All other accounts
Source: Verizon, 2025 Data Breach Investigations Report: Small- and Medium-Sized Business Snapshot, Figure 5. Covers the 15% of employees who accessed GenAI systems on corporate devices at least once every 15 days. The "all other accounts" share is the remainder of the 72% and 17% the report states.

The trouble isn't that people use these tools. It's that they use them on accounts the business can't see. Verizon found that 15% of employees routinely accessed generative AI on their corporate devices, and of those, 72% signed in with a non-corporate email address, while another 17% used a work address without the company's own sign-in system behind it. That means customer names, job addresses, and pricing can end up in accounts the business doesn't control and can't close when someone leaves.

Our reading of the data: the infrastructure step for this check isn't to block AI tools. It's to bring the use you already have onto company accounts, with a one-paragraph rule on what can and can't be pasted in. That's the cheapest AI infrastructure improvement most small operations can make, and it tells you, for free, which workflows your people already think AI helps with.

IBM's 2025 breach study puts a cost on getting this wrong. One in five of the 600 breached organizations IBM studied traced a breach to unsanctioned AI use, and those with high levels of it paid an average of $670,000 more per breach than those with little or none (IBM, Cost of a Data Breach Report 2025, press release, July 2025). That sample skews larger than most of our readers, so treat the dollar figure as a sign of direction rather than a quote for your business. While you're making the list, also check the software you already license, since some of it now includes AI features you're paying for and nobody has switched on.

5. How You'd Recover

Every system you connect to an AI tool is one more door, so the recovery check comes before the build, not after it. The attack that locks systems up makes up far more of small businesses' breaches: in Verizon's 2025 report, ransomware was part of 88% of breaches at businesses under 1,000 employees, against 39% at larger organizations.

AI Infrastructure Readiness Assessment at 10 to 200 People - Avolis AI Ransomware dominates small-business breaches Share of confirmed breaches that involved ransomware, 2025 report 0% 50% 100% 88% Under 1,000 employees 39% Over 1,000 employees
Source: Verizon, 2025 Data Breach Investigations Report: Small- and Medium-Sized Business Snapshot. Incidents from 1 November 2023 to 31 October 2024. Verizon's "small and medium" band runs to 1,000 employees, much wider than the 10 to 200 this page is written for.

The same report found that breaches involving a third party doubled in a year, from 15% to 30%, and every AI vendor you connect is a third party holding some of your information. None of this is a reason to avoid AI. It's a reason to know three things before you connect anything: when your last backup ran and whether anyone has tried restoring from it, whether updates install automatically, and whose number you call at each vendor when something breaks. For the security half of this check, the free NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide is a good, plain-English place to begin, and you don't need to pay anyone to work through it.

6. Who Owns Each System

The last check is about people, and it's the one that most often explains the other five. For every system on your list, write down who holds the admin rights, who the vendor's contact is, what it costs each month, and who in the business would notice if it stopped working. In our diagnostics, it's common to find an admin password that left with a former office manager, or a system set up years ago by a relative who has since moved on, and nobody can change the settings an AI connection would need.

You don't need an IT department to pass this check. You need one named person for each system, often the office lead or the operations manager, who can approve a connection and answer the vendor's questions. That's usually the same person who'll own the AI workflow once it's built, so it's worth naming them now.

How the Assessment Runs at This Size

At 10 to 200 people, an AI infrastructure assessment is a systems inventory plus one workflow traced end to end. The inventory takes an afternoon. Tracing the workflow and testing the connections usually add a few days, and they tend to run inside a broader diagnostic rather than as a project of their own. The inventory lists every vendor that holds your data, since Verizon's 2025 report found third parties involved in 30% of breaches, double the year before.

To make it concrete, picture a 60-person residential HVAC and plumbing company. It's a composite we've put together for illustration, not a client. It runs on a field service app, an accounting package, a shared customer inbox, a phone system, and the dispatcher's spreadsheet of which technician is certified for which equipment.

1. Inventory the systems. One spreadsheet, one row per system: what it does, who pays for it and how much, who has admin rights, how data gets out, and what it already connects to. For the HVAC company, that's an afternoon with the office manager and the last few months of card statements, which is where the forgotten subscriptions turn up.

2. Trace one workflow across them. Follow a single service call from the phone ringing to the invoice being paid, and note every place the information changes hands. In our composite, the customer service rep types the caller's details into the field service app, the dispatcher checks the certification spreadsheet by hand, the technician photographs the equipment tag and texts it to the office, and the office retypes the model number into the invoice. That's four handoffs, and each one is a place an AI workflow could help or break.

3. Test the doors. Don't take anyone's word for what connects. Try the export, look up whether your plan includes the connection, check which accounts have multifactor switched on, and ask when the last backup was restored rather than when it ran.

4. Sort every gap. Each problem you find gets one of three labels: a blocker for a named workflow, something to fix alongside the build, or not a blocker at all. That sorting is what turns a list of worries into a plan, and it's the subject of the next section.

From our own builds: in one residential design-build engagement, the infrastructure finding wasn't a missing server or a weak network. It was ten platforms, bought one convenient purchase at a time, none of them connected. Quoting sat in a legacy construction CRM, files were split across two ecosystems, and email ran through two providers. Consolidating that stack came before any AI, and the firm's headcount has roughly doubled since, though the consolidation isn't the only reason (Avolis, Residential design-build case study). This is our own client work, not independent research.

Which Gaps Block AI and Which Don't

Most infrastructure gaps at a small operation don't block a first AI workflow, and the few that do are rarely the ones owners worry about. The gap that matters most is access: in IBM's 2025 breach study, 13% of organizations reported breaches of AI models or applications, and 97% of those lacked proper AI access controls.

Gap Verdict Why
No servers or GPUs Not a blocker You rent the compute from an AI provider
No in-house IT staff Not a blocker Each system needs one owner, not a department
Older laptops and phones Not a blocker Most AI tools run in a browser or an app
No data warehouse Not a blocker Start from the system where the work already lives
Messy or incomplete records Depends on the workflow See our data readiness guide
Key records in desktop software with no export Blocker for that workflow Nothing can reach the information
Connection only on a higher-priced plan Fix alongside the build Price the upgrade into the business case
Personal AI accounts with customer data Fix alongside the build Move the use onto company accounts and write the rule
Shared logins on systems with customer data Fix first An AI tool inherits whatever that login can see
No multifactor on email Fix first It takes an afternoon and stops most attacks that rely on stolen passwords
Backups nobody has tested Fix first A new connection is a new way in

Notice what's in the "fix first" rows. None of them costs much or takes long, and none of them is really about AI, since they're overdue whether you build anything or not. The expensive items owners tend to worry about, such as new hardware, a data warehouse, or a hire, are mostly in the "not a blocker" rows.

The expensive mistake is fixing the wrong layer. We regularly meet businesses that were told to upgrade their infrastructure before they could use AI, and spent the budget on a new server or a data project that no workflow needed. It's the same error as buying an AI tool before diagnosing where the hours go, just one layer down. Pick the workflow first, then fix only the infrastructure that workflow touches. That ordering problem shows up again and again in our look at why AI projects fail.

One caveat on the table. If the workflow touches health records, card payments, or client financial files, the rules that already govern that data add their own checks on where it's stored and who can reach it. Settle those with whoever handles your compliance before you connect an AI tool, not after. If you'd rather run the whole assessment yourself, not just the infrastructure half, our guide to assessing your organization's AI readiness walks through it.

Where Avolis Fits

The six checks on this page are part of our two-week diagnostic, run alongside measuring the workflows themselves, rather than a separate service. Across our builds, the infrastructure finding is almost always about connections and logins rather than hardware. We build into the systems you keep, and we recommend consolidating only when disconnected tools are the blocker, as they were in the design-build engagement above.

If you only want the infrastructure half, you can do most of it yourself with the table above and the NIST quick-start guide, or with a local IT provider for the security items. Whether to hire anyone for a readiness assessment, and what the options cost, is covered in our comparison of AI readiness assessment consulting firms. For the broader partner decision, start with which AI consulting company to choose.

Frequently Asked Questions

What is an AI infrastructure readiness assessment?

It's a check of whether your systems can support a specific AI workflow: where they live, how they connect, who can log in, and how you'd recover from a failure. At 10 to 200 people it's mostly software and access, since the compute is rented. Stanford found GPT-3.5-level AI got more than 280 times cheaper to run from late 2022 to late 2024.

Do small businesses need servers or GPUs to use AI?

No. The models run on AI providers' servers, and you pay by subscription or by use. Stanford's 2026 AI Index counts 5,427 data centers in the United States alone, and facilities like those are where this kind of work runs. A smaller business needs online systems that can share data, named logins with multifactor authentication, and tested backups, not hardware of its own.

What's the difference between infrastructure readiness and data readiness?

Infrastructure readiness asks whether information can move safely between your systems and an AI tool. Data readiness asks whether that information is complete and accurate. A business can pass one and fail the other, since its systems can connect cleanly and still hold incomplete job records.

How long does an AI infrastructure readiness assessment take?

At 10 to 200 people, the inventory and most checks take an afternoon, and tracing one workflow and testing the connections adds a few days, often inside a broader diagnostic. Avolis's own diagnostic runs about two weeks and covers workflows too. The security half can start from NIST's free quick-start guide, and multifactor alone cuts compromise risk by 99.22%.

What's the biggest infrastructure risk when adding AI?

Uncontrolled access. In IBM's 2025 study, 97% of organizations with breached AI models or applications lacked proper AI access controls. For a small business, that usually means shared logins and staff using AI tools the company didn't provide, which 80% of AI users at small and medium companies do (Microsoft and LinkedIn, 2024).

Continue Learning

For a smaller operation, AI infrastructure readiness isn't a hardware project. It's knowing where your systems live, whether they connect, who can get in, and how you'd recover, and then fixing only what the first workflow touches.

Before anyone quotes you for an infrastructure upgrade, ask which workflow it's for.

The wider assessment:

Other kinds of readiness:

Choosing who does it:


Sources

All sources retrieved 2026-09-24.

On the cloud finding. The 43% and 5-percentage-point figures come from the 2018 Annual Business Survey, before generative AI tools were widely available, and the 5-point gap is a conditional correlation from the authors' regression, not proof that cloud adoption causes AI use. We cite it because it's the largest representative study of which technologies travel with AI at ordinary US firms.

On the security figures. Verizon's "small and medium-sized business" band covers organizations under 1,000 employees, and IBM's sample is 600 breached organizations of all sizes worldwide, so neither describes a 10-to-200-person business exactly. We use them for direction, not as estimates of your own risk. The "all other accounts" share in the account-type chart is the remainder after the 72% and 17% Verizon reports.

On the page review. "The 14 top-ranking pages we reviewed" means the pages ranking for "ai infrastructure readiness assessment" and close variants on 2026-09-24: consulting and IT services pages, hardware and cloud vendor articles, checklist guides, and three vendor self-assessment tools. Seven framed infrastructure mainly as GPUs, data centers, or power and cooling, and none stated an employee range below 200. It's a snapshot of one day's search results, not a market survey.

On first-party claims. Statements such as "in our builds" and "in our diagnostics" describe Avolis's own engagements. They are not independent research and are not offered as benchmarks. The HVAC and plumbing company is an illustrative composite, not a client.


About Avolis Research Group

Avolis Research Group is Avolis's in-house research practice, focused on how operations-heavy small and mid-sized businesses actually adopt AI. It synthesizes primary economic research, government survey data, and results from real implementations into practical, vendor-neutral guidance.

More about Avolis and how we work · Get in touch

Ready to make AI work for you?

Book an AI readiness evaluation. If there’s nothing worth automating, we’ll tell you.