Call NowFree Quote
AI

AI Readiness Checklist for Perth SMBs: What to Check Before You Roll Out AI Tools

Most Perth businesses aren't deciding whether to adopt AI anymore, staff are already using ChatGPT, Copilot, or Gemini for something, whether IT knows about it or not. The real question is whether the basics are in place to let that happen safely. Before you roll out an AI tool business-wide, or write a policy telling staff what's allowed, run through the checklist below first.

Know someone who needs this checklist?

Forward it to whoever handles IT, admin, or operations on your team.

✉️ Forward to Your Team

Why "AI Ready" Isn't About the AI Tool

It's tempting to think AI readiness is about picking the right product, ChatGPT vs Copilot, which plan, which features. In practice, the tool is rarely the risk. The risk is what the tool can see and do once it's connected to your business - your files, your inboxes, your customer data. Copilot in particular doesn't create new information, it surfaces whatever your existing Microsoft 365 permissions already allow it to see, just faster and more thoroughly than a human ever would. Getting ready for AI is mostly about getting those foundations right first.

The Six-Point AI Readiness Checklist

These are the six things worth checking before AI tools go anywhere near real business data:

  • 1. Identity and access. MFA enforced on every account, no shared logins, and conditional access in place so a compromised password isn't enough on its own to reach company data, let alone an AI tool connected to it.
  • 2. Data permissions. A review of who can actually access what across SharePoint, OneDrive, and Teams - not who was meant to have access, but who technically still does after years of ad-hoc sharing.
  • 3. A written AI usage policy. A short, plain-English document covering which tools are approved, what data can and can't be pasted into them, and who to ask if a staff member wants to use something new. See our guide to writing an AI usage policy for staff for a practical starting point.
  • 4. Staff awareness. Basic training on what not to paste into a public AI tool (client data, financial details, anything under an NDA), and awareness that AI-written phishing is now genuinely harder to spot than the clumsy scam emails staff were trained to recognise a few years ago.
  • 5. Vendor data handling. Understanding whether the AI tool you're using trains on your inputs by default, where your data is processed, and whether a business or enterprise tier actually changes that, most consumer-grade AI accounts do not offer the same data protections as a business plan.
  • 6. Ownership and review cadence. Someone specific responsible for AI governance, and a plan to revisit the policy and permissions periodically, not a one-off exercise that's never looked at again.

The Risk Most Businesses Don't See Coming

Of the six, data permissions is the one that catches businesses out most often, and it's worth explaining why. Before AI search, an oversharing problem in SharePoint or OneDrive was mostly theoretical. Nobody was going to manually click through thousands of files to find the one HR spreadsheet with the wrong permissions attached. AI tools change that instantly. Copilot-style search can surface a sensitive file the moment someone asks a relevant question, regardless of whether they were ever meant to see it, because it's only respecting the permissions that already exist. If those permissions have never been properly audited, an AI rollout is often the first thing that actually exposes the gap.

What Happens If You Skip This

Skipping the checklist doesn't usually mean a dramatic breach on day one. More often it means a slow accumulation of risk: client data pasted into a personal AI account, a Copilot response that surfaces something it shouldn't have, or a staff member falling for an AI-written phishing email that reads more convincingly than anything they were trained to spot. None of these show up in a typical IT report until something goes wrong, which is exactly why checking the basics upfront matters more than picking the right AI product.

Where to Start

If none of this has happened yet, that's normal, most Perth businesses are in the same position. The fastest way to get a sense of where you stand is our free 2-minute AI readiness self-assessment - eight plain-English questions covering policy, data handling, identity, and staff awareness, with an instant result and no email required.

Frequently Asked Questions

Do we need an official AI policy before staff can use AI tools?

Ideally yes, but don't let the absence of one stop you from acting. Staff are almost certainly using AI tools already, policy or not. A short, plain-English policy is one of the six checks below, and it's one of the fastest to put in place - see our guide to writing an AI usage policy for a template you can adapt.

What's the single biggest AI readiness risk most Perth businesses overlook?

Stale file permissions. Years of ad-hoc sharing in SharePoint or OneDrive usually means far more files are technically accessible to far more people than anyone intended. Traditional browsing never surfaced that mess. AI search tools do, instantly, which is why a permissions review matters more than any AI-specific security product.

Does 'AI ready' mean we need to buy new security tools?

Usually not. For most businesses, AI readiness is about fixing basics that should already be in place - MFA, a proper permissions review, and a written policy - rather than purchasing AI-specific software. If those basics are solid, you're most of the way there.

How do we find out where we actually stand?

Start with our free, 2-minute AI readiness self-assessment - it's anonymous and gives an instant estimate. If you want a verified answer rather than an estimate, that requires an actual review of your file permissions, identity setup, and current policies.

We help Perth businesses fix the identity, permissions, and policy gaps that make AI adoption risky.

Cybersecurity Services →

Not sure how AI-ready your business actually is?

Take the free 2-minute self-assessment or call 0433 087 091 for a free, no-obligation conversation.

Book a Free Consultation

For related reading, see AI Usage Policy for Staff, How AI Is Changing Cybersecurity for Perth Businesses, and ChatGPT vs Microsoft Copilot.

Share this article