Small-Business AI Risk & Opportunity Scan
Tell us your industry, team size, current tools and how sensitive your data is. Our AI maps the safe, high-value AI use-cases for your exact situation, flags the red-flags to avoid, and drafts you an internal AI Usage Policy aware of the Australian Privacy Act and the APPs — plus data-handling do's and don'ts and a 30-day safe-adoption plan. General guidance to get you moving safely, not legal or privacy advice.
The decision in front of a small business owner is not whether to use AI. Someone on the team probably already is, quietly, on a personal account. The real decision is whether that happens under ground rules or without them. The Small-Business AI Risk & Opportunity Scan is A$49 one-off, takes about 8 minutes, and answers that for your situation rather than in the abstract: which AI uses are worth your time, which ones will bite you, and a drafted internal policy your staff can actually follow. It arrives as an on-page report with a Markdown download you can print to PDF or drop into Word, and two free AI revisions come with it.
A bookkeeper and a landscaper should not get the same answer
A bookkeeping practice handling TFNs and bank details carries a different exposure than a landscaping crew handling addresses and quotes, and the advice should not be identical. The scan ranks recommended safe AI use-cases against your industry, your team size and how sensitive your data is, so the shortlist reflects the risk you actually carry rather than whatever is popular this quarter. The same three inputs drive the list in reverse: red-flag use-cases to avoid, each with the reasoning attached rather than left implied. A bare prohibition gets ignored the first time it is inconvenient. An explained one has a better chance of surviving a busy week.
It is worth knowing how the scan reaches those conclusions. Nothing connects to your systems. No one logs into accounts, inspects your software or monitors what staff are typing into which tool. The report is written from what you tell it, which means the honesty of your data-sensitivity answer sets the ceiling on how useful the output is. If you suspect unsanctioned tools are already circulating, name them in your current stack, because the scan cannot see what you do not declare.
The policy is a draft to circulate, not a certificate to file
The report includes a drafted internal AI Usage Policy written with the Privacy Act 1988 and the Australian Privacy Principles in mind. Circulate it, adapt it to how your team actually works, and have a qualified privacy or legal professional review it before you lean on it. This is general guidance to get you moving safely, not legal or privacy advice, and it is no substitute for a proper privacy assessment if you sit in a regulated field or handle health or financial data at any scale.
Alongside it sit the practical data-handling do's and don'ts: what is safe to paste into an AI tool, and what should never leave your systems. That part is written for the people using the tools, not for the filing cabinet. Then comes a 30-day safe-adoption plan with week-by-week actions, so the report closes with something to do on Monday rather than a set of principles to admire. Read as an orientation document and a first draft, A$49 buys real clarity. Read as a compliance sign-off, it will let you down.
What you get
- Recommended SAFE AI use-cases ranked for your industry, team size and data sensitivity
- Red-flags and risky use-cases to avoid (with why each one bites)
- A drafted internal AI Usage Policy aware of the Privacy Act 1988 and the APPs
- Data-handling do's and don'ts (what's safe to paste into AI, what never to)
- A 30-day safe-adoption plan with week-by-week actions
- 2 free AI revisions included
Turnaround: ~8 minutes. Delivery: On-page report + Markdown download (print to PDF / paste to Word).
Frequently asked questions
Our team is three people. Is a written AI policy overkill at that size?
Small teams are where informal habits set fastest, because nobody feels the need to say anything out loud. The scan is sized for that: one drafted policy rather than a governance library, plus a 30-day plan written as a sequence of first steps. Setting ground rules before staff improvise their own is usually less work than unwinding a habit six months in.
We already have a privacy policy. Does this cover the same ground?
It sits beside it rather than on top of it. The scan addresses AI use specifically: which use-cases are safe for your data, which to avoid, an internal AI Usage Policy, rules about what can be pasted into a tool, and a 30-day adoption plan. It does not review, amend or check itself against your existing privacy policy, and it has not seen your contracts or your industry's specific obligations.
Can I hand the drafted policy straight to staff?
You can hand it round as a draft and adapt it to how your team works. What you should not do is treat it as final. It is written by AI from your form answers with the Privacy Act 1988 and the APPs in mind, so it needs a qualified professional's eyes before you rely on it, and it has not been checked against state-level requirements or anything specific to your sector.
What happens if the report misreads my business?
That is what the two free AI revisions are for. They are re-runs that correct wrong assumptions about your industry, a data-sensitivity rating that does not match reality, or a use-case shortlist that missed something you specified. They are not open-ended consulting, and they will not add deliverables beyond the six listed for this product.