Skip to content
arrow_back
search
ISM-2074 policy ASD Information Security Manual (ISM)

Establish AI Usage Policy for Systems Access

Organisations must create and maintain a policy for using AI in general-purpose settings.

record_voice_over

Plain language

This control is about creating and maintaining a policy for how your organisation uses artificial intelligence (AI) in everyday business settings. It's important because without clear guidelines, AI could be used in ways that compromise privacy or security, leading to data breaches or misuse of information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A general-purpose artificial intelligence usage policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-2074
priority_high

Why it matters

Without a clear AI policy, organisations risk data misuse and non-compliance, potentially causing reputational damage and financial loss.

settings

Operational notes

Define approved AI tools and prohibited inputs (e.g. credentials, classified data). Review policy quarterly and train staff on safe use for systems access.

Mapping detail

Mapping

Direction

Controls