Opti Assist Free
Free, governed AI for regulated Australian organisations.
92 readiness assessments, 18 specialist advisors and a scored compliance gap analysis. Free for one user, no credit card, no time limit.
- No IT approval needed to start
- Australian-hosted infrastructure
- No data sent to third-party AI providers
- No training on user inputs
What's included
Everything below is free, for one user, with no time limit
Not a trial and not a cut-down demo. The assessments, the advisors and the credits renew every month for as long as you use it.
Readiness and compliance assessments
Scored self-assessments across AI governance, data readiness, AI security and privacy, framework discovery and sector-specific standards. Each one takes about fifteen minutes and produces a structured result, not a number.
AI specialist advisors
Advisors trained on the standards and regulations that apply to your sector, from NDIS practice standards and defence obligations to ISO 42001 and the Essential Eight. Matched to your industry at sign-up.
OO Credits every month
Enough for a full readiness assessment plus everyday governance queries, gap analysis and report generation. The allocation renews monthly and there is no trial timer.
ORCA pearl and workflow library
Run any of the pre-built skill packs and workflows in the ORCA library. Building your own is a paid feature, but running what is already there is not.
Personalising your account at sign-up recommends the assessments and advisors most relevant to your sector. It does not restrict them. Everything above is available to every free account.
No credit card. No IT approval. About two minutes to set up.
How free compares
What you actually get for nothing
Compared with the two categories most organisations reach for first: a consumer AI assistant, and a compliance platform.
| Capability | Free consumer AI assistant | Compliance platform | Opti Assist Free |
|---|---|---|---|
| Readiness and compliance assessments | None | No free tier | 92 and counting |
| Specialist advisors for your sector | None | No free tier | 18, matched at sign-up |
| Framework coverage | General knowledge only | No free tier | ISO 27001, ISO 42001, Essential Eight and more |
| Where your data is processed | Usually offshore | Varies, often offshore | Australian infrastructure |
| Whether your inputs train the model | Often, on consumer tiers | Not applicable | Never |
| Record of what your team asked | None you can produce | No free tier | Retained in your own tenancy |
| What it costs | Free, with usage caps | Paid plans only | Free for one user, no time limit |
Categories rather than named products, because the free tiers of individual tools change from month to month and a comparison that is out of date is worse than none. If you want a like-for-like against a specific platform, our comparison pages go into detail.
Free for one user, with no time limit and nothing to cancel.
$15,000 and three weeks.
Now free, and about fifteen minutes.
“A DISP readiness report at this level of detail used to cost around fifteen thousand dollars and take three weeks. We're giving it away for free, on sovereign infrastructure, and it takes about fifteen minutes. Every Australian organisation deserves to know where they stand on compliance. Cost and complexity shouldn't be the barrier, and neither should having to send the answers to an overseas tech company.”
Getting in
Try it first. Involve IT when you're ready.
Most people assume they need their IT team before they can even look. On the free plan you don't, so you can judge it properly before you put it in front of anyone else.
Microsoft 365 work or school account
The full experience, including the integrations. Some organisations restrict which applications staff can approve, so if you hit a request for administrator approval, the page below has a note you can forward to your IT team.
Personal Microsoft account
Available on the Free and Opti Assist Solo plans. There is no administrator approval step, so you can be running your first assessment within a couple of minutes.
Google account
Available now in beta. Sign-in works and the assessments and advisors all run. Integration support is more limited than the Microsoft path while the beta continues.
Coverage
The standards your industry runs on, already mapped
Run a scored readiness assessment against any of these. Each report is structured the way an auditor expects to read it, with gaps rated by severity and remediation steps prioritised.
ISO 27001
Information Security Management
Essential Eight
ACSC cyber controls maturity
DISP
Defence Industry Security Program readiness
NDIS Practice Standards
Quality and Safeguards expectations
ISO 42001
AI Management System
PSPF
Protective Security Policy Framework
DSPF
Defence Security Principles Framework
ISO 9001
Quality Management System
Pick the standard that applies to you and see where you stand.
Why now
The visibility gap is already inside your organisation.
Employees are using AI. Most of it is happening outside any system the organisation can see, on personal accounts, on platforms that train on user inputs, under offshore jurisdiction. Banning it has stopped working. Governing it is the only path left.
85.7%
of knowledge workers now use AI at work (Cyberhaven, 2026)
72.8%
of those using personal accounts their employer can't see (Cyberhaven, 2026)
36%+
of Australian professionals have exposed sensitive company data to AI platforms (Josys, 2025)
11%
of what employees paste into AI tools is confidential (Cyberhaven, 2026)
In March 2026 a single contractor exploited a known vulnerability in McKinsey's internal AI assistant and extracted 46.5 million confidential conversations referencing 728,000 client files in two hours. In 2023, Samsung engineers pasted proprietary semiconductor source code into the consumer version of ChatGPT within twenty days of lifting an internal ban. That data entered the model's training pipeline and cannot be removed.
Governing AI starts with knowing where you stand today.
The regulatory floor is rising
Australian regulators have already moved.
The Office of the Australian Information Commissioner's October 2024 guidance made organisations directly accountable for any personal information employees enter into commercial AI tools, including ChatGPT, Copilot and Gemini.
Privacy Act reforms lifted maximum penalties for serious breaches to the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.
In August 2026 the Australian Signals Directorate and the Australian Institute of Company Directors published guidance for boards on frontier AI cyber threats, giving directors a set of threshold questions to put to management.
The Australian Signals Directorate's March 2026 update to the Information Security Manual introduced its first formal AI-specific controls. Australia's Voluntary AI Safety Standard set out ten guardrails covering transparency, accountability, human oversight and data governance.
The lesson was never “ban AI.” The lesson was “ungoverned AI is the risk.”
Find out where you actually stand
A scored readiness assessment against the standard you pick, with gaps rated by severity and remediation steps prioritised. About fifteen minutes, free for one user.
Built for
Regulated Australian organisations without the headcount of a Fortune 500 security team
The organisations most exposed to the current visibility gap. Built to enterprise rigour, priced and packaged so a thirty-person team can actually say yes.
Professional services
Firms operating under client confidentiality obligations and rising AI-use scrutiny from auditors.
Healthcare providers
Clinical and operational teams where patient data cannot move to offshore consumer AI tools.
NDIS operators
Providers carrying Practice Standards and Quality and Safeguards obligations with limited compliance headcount.
Financial services
Regulated entities where data residency, auditability and CPS 234 alignment are non-negotiable.
Government suppliers
Organisations that need to evidence PSPF, ISM and supply-chain assurance before contract.
Defence industry
Suppliers and primes who need DISP-ready governance with sovereign data handling.
Research institutions
Universities and labs balancing open collaboration with ethics, IP and DISP-related expectations.
Sign in with a work account, a personal Microsoft account, or Google in beta.
Not ready to sign in yet?
Leave an email and we'll send you the framework list and what a readiness report actually covers, so you can decide in your own time.
Know where you stand. In about fifteen minutes.
Free for one user, no credit card, no time limit. Sign in with a Microsoft 365 work account, a personal Microsoft account, or Google in beta. Your data stays on Australian infrastructure.