Free tool
Free AI readiness assessment
Fifteen questions that score your organisation against the six essential practices in the Australian Government's Guidance for AI Adoption, with a shadow AI risk indicator and specific next steps for every gap.
Runs in your browser. Nothing you enter is sent to AusGPT.
Your results
%
By practice
Shadow AI risk indicator:
Your full report, with specific next steps and links to the official guidance, is below. Download it to share with your leadership team.
Your readiness report
Generated with the free AusGPT tool at https://ausgpt.com.au/tools/ai-readiness-assessment. Review and adapt before use.
This free AI readiness assessment checks whether your organisation has the basics in place to use AI safely. Fifteen questions map to the six essential practices in the Australian Government's Guidance for AI Adoption and to the OAIC's guidance on commercially available AI products. You get a score for each practice, an overall score, a shadow AI risk indicator and a specific next step for every gap, with links to the official guidance. Download the report as Word or Markdown to share with your leadership team.
How the AI readiness assessment works
Each question has three answers. "In place" scores 2, "partly" scores 1 and "not in place" scores 0. A practice counts as in place only when every answer for it scores 2, and as a gap when it scores less than half. Your overall score is your total out of 30, shown as a percentage.
| Overall score | Band | What it means |
|---|---|---|
| 90% and above | Strong foundations | The foundation practices are in place. Move on to the "next steps" in the implementation guidance. |
| 70 to 89% | Established | Most foundations are in place, with a few gaps to close. |
| 40 to 69% | Developing | Some foundations are in place, with clear gaps. Fix the priorities before expanding AI use. |
| Below 40% | Getting started | Most basics are missing. If staff already use AI, the risks are real now. |
The bands are deliberately strict. Answering "partly" to everything gives you 50%, because partly-done governance tends to fail at the moment it's needed. The report lists your top three priorities, starting with the gaps that most often lead to real problems: not knowing what tools staff use, having no approved tool, having no policy and having no human check on outputs.
The six essential practices behind the questions
The National AI Centre published the Guidance for AI Adoption in October 2025. It condensed the Voluntary AI Safety Standard's 10 guardrails into six essential practices, in two versions: Foundations, for organisations starting out, and Implementation guidance, for more mature governance and higher-risk uses. This assessment is based on the "getting started" actions in Foundations.
| Practice | What Foundations asks you to start with | Questions |
|---|---|---|
| 1. Decide who is accountable | A senior leader as overall AI governance owner, and an AI policy | 1 to 3 |
| 2. Understand impacts and plan accordingly | A stakeholder impact assessment, and channels for people to report problems or challenge AI decisions | 4 and 5 |
| 3. Measure and manage risks | A risk screening process that flags uses needing more attention | 6 to 8 |
| 4. Share essential information | An AI register, and disclosing your use of AI | 9 and 10 |
| 5. Test and monitor | Proof of testing from suppliers, testing before deployment, monitoring after, and extending data governance and cybersecurity to AI | 11 to 13 |
| 6. Maintain human control | Meaningful human oversight and clear points where people can pause or override AI | 14 and 15 |
Several questions also draw on the OAIC's guidance on privacy and commercially available AI products, which covers due diligence before you choose a product, updating privacy policies and notices, checking the accuracy of AI output, human oversight and staff training.
Shadow AI: the risk most organisations underestimate
Shadow AI is AI that staff use for work without the organisation's approval or knowledge: a free chatbot on a personal account, a browser extension, or an AI feature quietly switched on in software you already pay for. It usually starts with good intentions. The problem is that client details, health information or commercially sensitive documents end up in tools nobody has assessed, under terms nobody has read.
As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The National AI Centre notes that keeping a single AI register helps reduce "shadow" AI use.
The shadow AI indicator in your results combines four answers: whether you have a policy (question 2), whether you know what tools staff use (question 7), whether staff have an approved tool (question 8) and whether they've been trained (question 15). Banning AI without offering an approved option rarely works. Most organisations get further by finding out what's in use, providing a tool that meets their privacy and security requirements, and telling staff clearly what they can and can't put into it.
What this assessment doesn't cover
This is a self-assessment against voluntary guidance, so it is only as accurate as your answers. It doesn't check compliance with the Privacy Act, and it doesn't cover sector-specific rules, such as those that apply in health, financial services, legal practice or education.
Two obligations are worth checking separately:
- Automated decisions. From 10 December 2026, organisations covered by the Privacy Act that use personal information in computer programs that make, or do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect people's rights or interests must describe this in their privacy policy (APP 1.7 to 1.9). The OAIC published a fact sheet and flowchart on 30 September 2026.
- Commonwealth agencies. The Digital Transformation Agency's Policy for the responsible use of AI in government (version 2.0, effective 15 December 2025) sets mandatory requirements for non-corporate Commonwealth entities, including accountable officials, transparency statements, internal AI use case registers, staff training and AI use case impact assessments.
After the assessment
Start with your top priorities. If you don't yet know which AI tools are in use, build a list with our AI register template. If a use involves personal information, work through the AI privacy impact assessment. The National AI Centre's AI policy template and "Questions to ask AI suppliers" are good places to start on policy and vendor due diligence, and our security page shows the kind of detail you should expect a provider to give you about where your data is stored and processed.
Run the assessment again in six months, or whenever your AI use changes significantly, to track progress.
Sources
- National AI Centre: Guidance for AI adoption: foundations
- National AI Centre: Guidance for AI adoption: implementation guidance
- National AI Centre: AI systems register
- National AI Centre: Create an AI policy
- National AI Centre: Planning tools and templates (including Questions to ask AI suppliers)
- OAIC: Guidance on privacy and the use of commercially available AI products
- OAIC: New resources on transparency for use of AI and automated decision-making (30 September 2026)
- Digital Transformation Agency: Policy for the responsible use of AI in government, version 2.0
Frequently asked questions
- What is an AI readiness assessment?
- A structured check of whether your organisation has the basics in place to use AI safely: someone accountable, a policy, visibility of the tools in use, risk screening, data protection, human oversight and staff training. This one scores you against the six essential practices in the National AI Centre's Guidance for AI Adoption.
- What are the six essential AI practices?
- The Guidance for AI Adoption (October 2025), sometimes called AI6, sets out six practices: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. It replaced the 10 guardrails of the Voluntary AI Safety Standard.
- What is shadow AI?
- Shadow AI is staff using AI tools for work that the organisation hasn't approved or doesn't know about, such as free chatbots on personal accounts or AI features switched on inside existing software. The risk is that personal or confidential information goes into tools nobody has assessed. The National AI Centre notes that a single AI register helps reduce shadow AI use.
- Does a high score mean we comply with the law?
- No. This is a self-assessment against voluntary government guidance and OAIC good practice. It doesn't test compliance with the Privacy Act or any sector rules, and it isn't legal advice. Use it to find gaps and decide what to fix first.
- Is my data sent anywhere?
- No. The assessment runs entirely in your browser. Your answers are saved only in this browser so you can come back to them, and you can clear them with Start again.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.