What could go wrong with the AI you already use?
Pick one way your business uses AI today. Fourteen questions later you get a risk band, the dimension that needs attention first, and a straight answer on whether to carry on, fix something first, or stop.
No email needed to see your result.
Fourteen questions, on one use case.
Assess as many as you like. The pattern across them is the useful part.
Assess one use case
Two things stand out
Where to start
Worth knowing before December
This one influences a decision about a person, which is what Australian Privacy Principle 1.7 covers from 10 December 2026. Whether it reaches you is the part most businesses get wrong. The Information Commissioner lists a contractor providing services under a Commonwealth contract, or a subcontract, among the businesses the Privacy Act covers regardless of turnover. If you do government work, or you sit under a head contractor who does, turnover is not the test.
Across everything you have assessed
| Use case | Data | Access | Decision impact | Governance | Regulatory exposure | Verdict |
|---|
Want my read on this one?
Everything above is yours already. Leave your first name and email and I will send you a copy, then write back today with what I would fix first and what I would leave alone. Everything under them is optional, and the more you tell me the more specific the reply.
We keep the risk bands anonymously to understand where Australian businesses are exposed, without your answers or your address attached. Detail is in the privacy policy
The more you assess, the more useful the pattern.
The short answer
Assessing AI risk means taking one thing you already do with AI and asking four questions about it: what data it touches, what it can reach, what its output affects, and who owns it. A fifth question matters in Australia from December 2026: whether it influences a decision about a person. Most businesses have never done this for any of their use cases, which is not negligence. It is that nobody handed them a way to.
This does it for one use case, free, in about five minutes. No email needed to see the result. It reports exposure, not compliance, and it is not legal advice.
Governance, risk, compliance, security: four different things
These get used as though they mean the same thing, and a business that asks for one and is handed another has bought a quarter of what it needed.
The rules of the game. How AI should be used here, who decides, and whether we should be doing this at all.
What happens if something goes wrong. How likely, how bad, and what we would do about it. This page is here.
Whether you are following the rules that actually apply to you: the law, your contracts, your clients' conditions.
Whether the systems are protected. Necessary, and on its own it answers none of the three above.
This page does the second one. Whether a business your size needs formal governance at all is worked through in do Australian businesses still need AI governance, and if what you actually need is the rules written down, there is a plain-English AI use policy you can copy.
What the assessment measures
Four of them come from a risk framework taught in the Innovating with AI programme, by a certified chief information security officer. The fifth is ours, because Australia has a date on it.
What the use case touches, how sensitive it is, and where it could end up. The most common cause and the cheapest to fix.
What systems it can reach, whether it only reads or can also act, and who is able to use it.
What the output influences, what a wrong answer costs, and whether anyone would notice.
Who owns it, what rules exist, and whether anyone is still watching it. Usually the least comfortable question in the room.
Whether it touches a decision about a person, and whether a contract or a client condition already restricts what you may do.
Why one of these questions is about a date
Australian Privacy Principle 1.7 starts on 10 December 2026, and the part businesses get wrong is the width of it. It reaches a program doing something substantially and directly related to making a decision, which includes one recommending or guiding a decision a person then makes. Having a human review the output is not an exemption.It is not limited to AI either: a rule-based system is captured the same way.
Whether it reaches your business is a separate question, and the answer is less obvious than the turnover threshold suggests. That, and what governance is actually worth doing at your size, is worked through properly here.
Which check do you actually want?
There are two on this site and they answer different questions. This one is about exposure from something you already do. The other is about whether the business can get value from AI at all: direction, workflows, people, trust and whether buyers find you when they ask an AI.
If you have not started with AI yet, take that one first. If AI is already in use and nobody has looked at it properly, you are in the right place.
Questions we get asked
How long does the AI risk assessment take?
Fourteen questions about one use case, roughly five minutes. Your result appears on screen as soon as you finish, and you do not need to leave an email to see it.
What is the difference between AI governance, risk, compliance and security?
They get used interchangeably and they are four different things. Governance is the rules of the game: how AI should be used here, and whether we should do this at all. Risk is what happens if something goes wrong. Compliance is whether you are following the rules that apply to you. Security is whether the systems are protected. A business that asks for AI governance and is handed a security solution has bought one quarter of what it needed.
Why does it assess one use case instead of the whole business?
Because risk is not a property of a business, it is a property of a particular thing that business does. Summarising internal meetings and screening job applicants carry completely different exposure even inside the same company with the same policy. Assess the use cases you actually rely on, one at a time. If you want the business-level picture instead, that is the AI Readiness Score.
Does a human reviewing the output make it safe?
It helps, and it is not the exemption people assume it is. Australian Privacy Principle 1.7 reaches a system that is substantially and directly related to making a decision, and that includes one guiding or recommending a decision a person then makes, so having someone check the output does not put the system outside it. Whether the obligation applies to your business is a separate question that turns on whether you are an APP entity and whether personal information is involved. If AI touches decisions about people in your business, that is worth establishing before 10 December 2026.
Is a risk assessment the same as AI risk management?
No. An assessment is a snapshot of one use case on one day. AI risk management is the ongoing part: someone owning each use, rules people have actually read, and a review that happens on a schedule rather than after something goes wrong. Those are three of the questions here, which is why governance scores badly for most businesses on their first run. The assessment tells you where you stand. Managing it is what you do next.
Is this legal advice?
No, and it is not a compliance assessment either. It reports exposure so you can have a better conversation with whoever advises you. Where the result points at a legal or contractual question, the right next step is your own legal or compliance advice, not a webpage.
What happens to my answers?
Your result is yours. If you leave an email, I use your answers to write you something specific about your situation. Answers are also used anonymously to understand where Australian businesses are exposed, and that anonymised picture may be published. The privacy page has the detail.
What if the result says not yet?
It means one or two specific things need to be true before that use case is safe to widen, not that AI is wrong for you. The result names them. Most are small: moving people onto business accounts, deciding who owns the thing, putting a human approval step in front of anything that leaves the business.
This assessment reports exposure. It is not legal advice, not a compliance assessment, and not a warranty that a use case is safe. It does not determine whether you meet any obligation. Where a result points at a legal or contractual question, take your own legal or compliance advice. Regulatory references are current as at 28 August 2026.
Assessed it, and now you want it fixed?
Book a discovery call and bring the result. We will tell you which parts are a half-day of work and which need someone else entirely.
