Small business self-check

AI risk, in five honest minutes.

In October 2025, an Australian contractor pasted 12,000 rows of names, addresses and health data into a public AI tool — not out of malice, just to be helpful. One paste, one mistake. This checklist helps you avoid the same.

532

notifiable data breaches reported to the OAIC in H1 2025.

37%

of those breaches were caused by human error.

$66k

maximum OAIC infringement notice under the Privacy Act, used in its Jan 2026 sweep.

Step 1

Pick the answer that best describes your business today.

Seven questions, four ways to answer each. Honest beats flattering.

  1. 01

    Do you have a written list of 'never paste' data types (client details, financials, health, contracts, source code)?

  2. 02

    Could your staff explain the difference between a public AI tool and an enterprise one?

  3. 03

    Whose accounts are your AI tools sitting on?

  4. 04

    How do staff know which documents are sensitive and need special handling?

  5. 05

    How well do you understand how each AI tool you use treats your data (training, retention, geography)?

  6. 06

    When did you last review AI use against your obligations under the Privacy Act and related rules?

  7. 07

    If a client asked tomorrow how you use AI, how would you answer?

0 / 7 answered

Step 2

Your details.

So we can send back your results and a short follow-up.

Specific tool, sticky situation, recent close call — all useful.

Your answers go straight to the Integrity AI team — no third parties, no marketing list.