AI Risk & Privacy Checklist

A practical assessment to estimate risk level and recommended safeguards for AI-enabled software.

No uploads. No storage. Your answers stay in your browser.

Evaluate how critical the information processed by the AI system is.

Public or synthetic data with no reference to identifiable individuals.

Common information like names, business emails, or browsing preferences.

Protected information requiring maximum safeguards and strict compliance.

The volume and type of data that users upload or write into prompts.

Simple text interactions limited to a few lines.

Sending extended texts or portions of documents for analysis or synthesis.

Uploading whole files (PDFs, images) that may contain unfiltered data.

How much weight and what consequences the AI-generated results have in the real world.

Output is used only for non-critical consultation or creative support.

Output guides human choices in professional contexts or operational processes.

AI independently modifies databases, writes code, or sends communications.

The level of human control and validation before the AI output is utilized.

Every single output is verified by a person before any use.

Partial review, spot checks, or limited to specific use cases only.

AI operates independently without direct human filters or approvals.

Who the recipients or users interacting with the AI features are.

Internal use limited to a small, trusted, and trained group.

Extended use across different departments or segregated user groups.

AI is exposed to end users or customers outside the organization's direct control.

The level of traceability required to monitor interactions and ensure compliance.

Monitoring system status and general technical errors is sufficient.

Basic tracking of who uses the system, when, and with what volumes.

Immutable recording of every single interaction for legal or regulatory purposes.

How the AI interacts with other systems or performs technical tasks.

The model receives input and returns text, without interacting with other resources.

AI can invoke external tools (e.g., calculators, search) to enrich the output.

AI orchestrates complex processes by calling multiple functions in autonomous sequence.

How long input and output data remain stored in the systems.

Data is deleted immediately after the response is processed.

Storage limited to the time needed for the session or immediate debugging.

Data archived for historical analysis, model improvement, or contractual obligations.

This checklist is a starting point, not legal advice.