Free tool

Free AI readiness assessment

Fifteen questions that score your organisation against the six essential practices in the Australian Government's Guidance for AI Adoption, with a shadow AI risk indicator and specific next steps for every gap.

Runs in your browser. Nothing you enter is sent to AusGPT.

Answer 15 questions

Answer for your organisation as it is today, not as you plan it to be. Each question maps to one of the six essential practices in the Australian Government's Guidance for AI Adoption. It takes about five minutes.

Practice 1 of 6

Decide who is accountable

Clear ownership of AI use, and a policy staff can follow.

1. Is a senior leader accountable for how your organisation uses AI?

Someone with the authority to approve, change or stop AI use across the organisation.

2. Do you have a written AI policy that staff know about?

It should say what AI can and can't be used for, who approves higher-risk uses and what information staff may put into AI tools.

3. Does each AI tool or use have a named owner, with the vendor's responsibilities clear?

For example who handles incidents, updates, data handling and exit.

Practice 2 of 6

Understand impacts and plan accordingly

Knowing who AI could affect, and giving them a way to raise problems.

4. Before using AI for something new, do you consider who could be affected and how?

Clients, staff, job applicants and people in vulnerable circumstances, and harms such as unfair decisions, wrong information or overreliance.

5. Can people raise a concern about, or challenge, an outcome that AI contributed to?

And can you put it right if the AI got it wrong?

Practice 3 of 6

Measure and manage risks

Screening AI uses, and knowing what tools staff actually use.

6. Do you screen new AI uses for risk, and do a privacy impact assessment when personal information is involved?

For example with the National AI Centre's seven AI screening questions, before committing time or money.

7. Do you know which AI tools staff actually use for work?

Including free tools on personal accounts, browser extensions and AI features switched on in software you already use. Unapproved use is often called shadow AI.

8. Have you given staff an approved AI tool that meets your privacy and security requirements?

Without an approved option, staff are more likely to use free consumer tools.

Practice 4 of 6

Share essential information

Recording your AI use and being open about it.

9. Do you keep an AI register of every AI system and use?

Including AI features embedded in other software.

10. Do you tell people when AI is used in ways that affect them?

For example a privacy policy and collection notices that explain how you use AI with personal information, and making clear when customers are dealing with a chatbot rather than a person.

Practice 5 of 6

Test and monitor

Checking products before you adopt them, and keeping data secure.

11. Before adopting an AI product, do you check how it handles your data?

Where data is processed and stored, whether it is used to train models, who at the provider can access it, how long it is kept and what happens when you leave.

12. Do your security and data governance controls cover AI tools?

For example business accounts with strong sign-in, removing access when people leave, retention settings for chats and uploaded files, and an incident response plan that covers AI providers.

13. Do you test AI tools on your own tasks before rolling them out, and keep checking quality afterwards?

Real examples of your work, not just a vendor demonstration.

Practice 6 of 6

Maintain human control

People checking outputs, and staff trained to do it well.

14. Must a person check AI output before it is relied on?

Especially for anything that affects someone's rights, money, health or opportunities.

15. Have staff who use AI been trained on its limits and your rules?

For example that AI can be confidently wrong, what must not be entered into AI tools and how to report problems.

0 of 15 answered

This free AI readiness assessment checks whether your organisation has the basics in place to use AI safely. Fifteen questions map to the six essential practices in the Australian Government's Guidance for AI Adoption and to the OAIC's guidance on commercially available AI products. You get a score for each practice, an overall score, a shadow AI risk indicator and a specific next step for every gap, with links to the official guidance. Download the report as Word or Markdown to share with your leadership team.

How the AI readiness assessment works

Each question has three answers. "In place" scores 2, "partly" scores 1 and "not in place" scores 0. A practice counts as in place only when every answer for it scores 2, and as a gap when it scores less than half. Your overall score is your total out of 30, shown as a percentage.

Overall score Band What it means
90% and above Strong foundations The foundation practices are in place. Move on to the "next steps" in the implementation guidance.
70 to 89% Established Most foundations are in place, with a few gaps to close.
40 to 69% Developing Some foundations are in place, with clear gaps. Fix the priorities before expanding AI use.
Below 40% Getting started Most basics are missing. If staff already use AI, the risks are real now.

The bands are deliberately strict. Answering "partly" to everything gives you 50%, because partly-done governance tends to fail at the moment it's needed. The report lists your top three priorities, starting with the gaps that most often lead to real problems: not knowing what tools staff use, having no approved tool, having no policy and having no human check on outputs.

The six essential practices behind the questions

The National AI Centre published the Guidance for AI Adoption in October 2025. It condensed the Voluntary AI Safety Standard's 10 guardrails into six essential practices, in two versions: Foundations, for organisations starting out, and Implementation guidance, for more mature governance and higher-risk uses. This assessment is based on the "getting started" actions in Foundations.

Practice What Foundations asks you to start with Questions
1. Decide who is accountable A senior leader as overall AI governance owner, and an AI policy 1 to 3
2. Understand impacts and plan accordingly A stakeholder impact assessment, and channels for people to report problems or challenge AI decisions 4 and 5
3. Measure and manage risks A risk screening process that flags uses needing more attention 6 to 8
4. Share essential information An AI register, and disclosing your use of AI 9 and 10
5. Test and monitor Proof of testing from suppliers, testing before deployment, monitoring after, and extending data governance and cybersecurity to AI 11 to 13
6. Maintain human control Meaningful human oversight and clear points where people can pause or override AI 14 and 15

Several questions also draw on the OAIC's guidance on privacy and commercially available AI products, which covers due diligence before you choose a product, updating privacy policies and notices, checking the accuracy of AI output, human oversight and staff training.

Shadow AI: the risk most organisations underestimate

Shadow AI is AI that staff use for work without the organisation's approval or knowledge: a free chatbot on a personal account, a browser extension, or an AI feature quietly switched on in software you already pay for. It usually starts with good intentions. The problem is that client details, health information or commercially sensitive documents end up in tools nobody has assessed, under terms nobody has read.

As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The National AI Centre notes that keeping a single AI register helps reduce "shadow" AI use.

The shadow AI indicator in your results combines four answers: whether you have a policy (question 2), whether you know what tools staff use (question 7), whether staff have an approved tool (question 8) and whether they've been trained (question 15). Banning AI without offering an approved option rarely works. Most organisations get further by finding out what's in use, providing a tool that meets their privacy and security requirements, and telling staff clearly what they can and can't put into it.

What this assessment doesn't cover

This is a self-assessment against voluntary guidance, so it is only as accurate as your answers. It doesn't check compliance with the Privacy Act, and it doesn't cover sector-specific rules, such as those that apply in health, financial services, legal practice or education.

Two obligations are worth checking separately:

  • Automated decisions. From 10 December 2026, organisations covered by the Privacy Act that use personal information in computer programs that make, or do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect people's rights or interests must describe this in their privacy policy (APP 1.7 to 1.9). The OAIC published a fact sheet and flowchart on 30 September 2026.
  • Commonwealth agencies. The Digital Transformation Agency's Policy for the responsible use of AI in government (version 2.0, effective 15 December 2025) sets mandatory requirements for non-corporate Commonwealth entities, including accountable officials, transparency statements, internal AI use case registers, staff training and AI use case impact assessments.

After the assessment

Start with your top priorities. If you don't yet know which AI tools are in use, build a list with our AI register template. If a use involves personal information, work through the AI privacy impact assessment. The National AI Centre's AI policy template and "Questions to ask AI suppliers" are good places to start on policy and vendor due diligence, and our security page shows the kind of detail you should expect a provider to give you about where your data is stored and processed.

Run the assessment again in six months, or whenever your AI use changes significantly, to track progress.

Frequently asked questions

What is an AI readiness assessment?
A structured check of whether your organisation has the basics in place to use AI safely: someone accountable, a policy, visibility of the tools in use, risk screening, data protection, human oversight and staff training. This one scores you against the six essential practices in the National AI Centre's Guidance for AI Adoption.
What are the six essential AI practices?
The Guidance for AI Adoption (October 2025), sometimes called AI6, sets out six practices: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. It replaced the 10 guardrails of the Voluntary AI Safety Standard.
What is shadow AI?
Shadow AI is staff using AI tools for work that the organisation hasn't approved or doesn't know about, such as free chatbots on personal accounts or AI features switched on inside existing software. The risk is that personal or confidential information goes into tools nobody has assessed. The National AI Centre notes that a single AI register helps reduce shadow AI use.
Does a high score mean we comply with the law?
No. This is a self-assessment against voluntary government guidance and OAIC good practice. It doesn't test compliance with the Privacy Act or any sector rules, and it isn't legal advice. Use it to find gaps and decide what to fix first.
Is my data sent anywhere?
No. The assessment runs entirely in your browser. Your answers are saved only in this browser so you can come back to them, and you can clear them with Start again.
AI governance AI register template Record every AI system and use case in your organisation, screen each one with the Australian Government's seven screening questions, and export the register to a spreadsheet or Word document. Privacy AI privacy impact assessment A guided privacy impact assessment for a proposed generative AI use. Describe the project, map the information flows, answer questions on the Australian Privacy Principles and get a structured draft PIA report with risks and recommendations. AI governance AI policy generator Create an AI acceptable use policy for your staff in a few minutes. It follows the National AI Centre's AI policy template and six essential practices, with privacy rules based on OAIC guidance and extra clauses for your sector. Privacy ADM privacy policy generator From 10 December 2026, organisations covered by the Privacy Act must explain in their privacy policy how computer programs use personal information to make decisions that significantly affect people. Screen your decisions and draft the wording here. AI privacy Is ChatGPT safe for business? ChatGPT can be used safely at work, but the plan matters and so do your rules. Here's what OpenAI's own documentation says about training and data location, what the OAIC recommends, and the rules to give staff. AI governance Guidance for AI Adoption (AI6) The National AI Centre's Guidance for AI Adoption is the government's main playbook for using AI responsibly. It updated the Voluntary AI Safety Standard in October 2025. Here are the six practices, the free templates and a 90-day plan for a small or mid-sized organisation.

Secure AI for your team, processed in Australia

Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.