Skip to content
arrow_back
search
ISM-2072 policy ASD Information Security Manual (ISM)

Ensure AI Models are Stored Securely

AI models must be kept in a format that prevents them from running unwanted code.

record_voice_over

Plain language

This control is about keeping your AI models from accidentally or maliciously running harmful code. If AI models aren't stored safely, someone might trick the system into doing something it's not supposed to do, which could compromise sensitive information or harm your organisation's reputation. It's a bit like making sure a recipe book can't accidentally catch fire just because it's near a hot stove.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Artificial intelligence models are stored in a non-executable file format that does not allow arbitrary code execution.
policy ASD Information Security Manual (ISM) ISM-2072
priority_high

Why it matters

Improper storage of AI models can lead to execution of malicious code, risking data breaches and causing severe reputational damage.

settings

Operational notes

Store model artefacts only in non-executable formats (e.g., weights/checkpoints). Block pickled/serialised objects that can run code and scan uploads for unsafe formats.

Mapping detail

Mapping

Direction

Controls