AI Privacy Risk Scorer
Who it's for: Business owners who suspect their AI tool use might have Privacy Act exposure but aren't sure how serious it is.
What it does: A 12-question quiz that scores your specific setup, not a generic checklist, and returns a risk level (Low/Medium/High/Critical) plus exactly what to fix.
Email me this risk summary
This tool provides general information only and does not constitute legal advice. It estimates relative risk based on your answers and common Privacy Act considerations. For guidance on your business specific obligations, consult a qualified privacy practitioner or the OAIC.
How this tool works
How the score is calculated
The tool asks 12 questions and adds points for selected answers. Scores increase for uncertainty about staff AI use, use of a general-purpose AI tool, certain data entered into AI tools, unconfirmed model-training settings, no Data Processing Agreement (DPA), gaps in AI policy or staff training, healthcare or HR use, privacy-policy gaps, and known or possible AI privacy incidents.
The final bands are Low at 0 to 3 points, Medium at 4 to 8, High at 9 to 14, and Critical at 15 or more. A result is also Critical at any score when health data is combined with no DPA, health data is combined with no AI policy, or healthcare-context use is combined with a general-purpose AI tool.
Inputs, defaults and special results
The score is based on the answers you provide, not on an external benchmark or business database. The supplied tool specification identifies no prefilled answers or default dataset. This explanation was reviewed against the supplied scoring logic on 25 August 2026.
If you select “None yet” for the AI-tools question, scoring stops. The tool displays Not started with a pre-adoption checklist instead of calculating a numerical risk level. Results can be emailed, but the answers themselves are not stored. Only the summary you choose to send is retained for that email action.
Worked example
A small bookkeeping practice uses ChatGPT to help draft client emails. General-purpose AI use adds 2 points. Staff enter customer financial information, adding 4 points. The practice has no DPA, adding 3 points. It has a written AI policy, so that answer adds 0 points, but staff have not yet received AI-use training, adding another 3 points.
The calculation is 2 + 4 + 3 + 0 + 3 = 12 points. No listed automatic Critical combination applies in this scenario, so the point band determines the result. Twelve points falls within the 9 to 14 range, producing a High result.
Frequently asked questions
Why can a low point total still produce a Critical result?
The tool checks the three automatic Critical combinations separately from the point total. If any one is present, it overrides the normal score band.
What happens if my business does not use AI yet?
Selecting “None yet” bypasses scoring and returns Not started with a pre-adoption checklist. The tool does not assign a zero or Low score.
How should I interpret the result?
Treat it as a prioritisation signal based on the tool’s defined questions. Review the answers that added points and the combinations that may have triggered Critical.
Can I change an answer and recalculate?
Yes. Because the result comes from the current answers, changing an answer can change the total, the applicable band, or an automatic Critical trigger.