Develop and Maintain AI Usage Policy
Organisations must create and update policies for using AI systems.
Plain language
This control requires organisations to have guidelines on using Artificial Intelligence (AI). It matters because AI can impact privacy and decision-making, and unregulated use could lead to data breaches or unethical outcomes.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2025
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for personnel securityOfficial control statement
A general-purpose AI usage policy is developed, implemented and maintained.
Why it matters
Without a clear AI usage policy, organisations may face legal issues and ethical breaches, leading to damage to reputation and trust.
Operational notes
Regularly update AI usage policy to adapt to new legal requirements and technological advancements, ensuring continued compliance and ethical use.
Implementation tips
- Managers should prepare a draft AI usage policy. Identify the AI tools in use and outline permissible types of data and functions for each tool to ensure responsible use.
- The compliance team should review legal and ethical guidelines. Ensure that AI use doesn't violate privacy laws or ethical norms by aligning the policy with Australian laws and standards.
- Human Resources should train staff on AI policy. Conduct workshops to explain what the AI usage policy covers, illustrating with real-world scenarios on acceptable and unacceptable use.
- IT teams should monitor AI systems regularly. Set up checks to track AI decision-making processes, ensuring they operate within policy guidelines and highlight unusual behaviour.
- Management must periodically review and update the AI policy. Schedule annual reviews to address new developments in AI technology and legislative changes that affect AI use.
Audit / evidence tips
- Askthe AI usage policy documentLook atits structure and content to ensure it covers data types, allowed AI tools, and user responsibilitiesGoodshows a comprehensive policy aligning with laws and ethical standards
- Goodincludes up-to-date records with details of each AI tool's purpose and scope
- Asktraining records on AI policyLook atattendance records and training materials to ensure staff understand and follow the policyGoodshows widespread staff participation and clear instructional content
- Look atintervals and findings to ensure regular analysis of AI outputs against policy standardsGoodincludes recent review entries and identified adjustments where necessary
- Askrecords of policy reviews. Check dates and notes to ensure policy updates reflect current AI and legal standardsGoodshows regular updates and rationales for changes
Cross-framework mappings
How ISM-2074 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.1 | ISM-2074 requires an organisation to develop, implement and maintain a general-purpose artificial intelligence usage policy | |
handshakeSupports(1)expand_less | ||
| Annex A 5.15 | ISM-2074 requires a general-purpose AI usage policy that sets expectations and constraints for using AI tools | |
extensionDepends on(2)expand_less | ||
| Annex A 5.4 | ISM-2074 requires an organisation to have a documented and maintained policy governing general-purpose AI usage | |
| Annex A 5.36 | ISM-2074 requires an organisation to develop, implement and maintain a general-purpose AI usage policy | |
linkRelated(1)expand_less | ||
| Annex A 5.10 | Annex A 5.10 requires organisations to set and implement acceptable use rules for information and assets | |
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 2.4 | Annex A 2.4 calls for periodic and as-needed reviews of the AI policy to ensure its effectiveness | |
| Annex A 9.2 | Annex A 9.2 requires process documentation for responsible AI use | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Personnel security
See all Guidelines for personnel security controls, or browse the full ASD ISM library.