Skip to content
arrow_back
ISM-2074policyASD Information Security Manual (ISM)

Develop and Maintain AI Usage Policy

Organisations must create and update policies for using AI systems.

record_voice_over

Plain language

This control requires organisations to have guidelines on using Artificial Intelligence (AI). It matters because AI can impact privacy and decision-making, and unregulated use could lead to data breaches or unethical outcomes.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

A general-purpose AI usage policy is developed, implemented and maintained.
policyASD Information Security Manual (ISM)ISM-2074
priority_high

Why it matters

Without a clear AI usage policy, organisations may face legal issues and ethical breaches, leading to damage to reputation and trust.

settings

Operational notes

Regularly update AI usage policy to adapt to new legal requirements and technological advancements, ensuring continued compliance and ethical use.

build

Implementation tips

  • Managers should prepare a draft AI usage policy. Identify the AI tools in use and outline permissible types of data and functions for each tool to ensure responsible use.
  • The compliance team should review legal and ethical guidelines. Ensure that AI use doesn't violate privacy laws or ethical norms by aligning the policy with Australian laws and standards.
  • Human Resources should train staff on AI policy. Conduct workshops to explain what the AI usage policy covers, illustrating with real-world scenarios on acceptable and unacceptable use.
  • IT teams should monitor AI systems regularly. Set up checks to track AI decision-making processes, ensuring they operate within policy guidelines and highlight unusual behaviour.
  • Management must periodically review and update the AI policy. Schedule annual reviews to address new developments in AI technology and legislative changes that affect AI use.
fact_check

Audit / evidence tips

  • Askthe AI usage policy documentLook atits structure and content to ensure it covers data types, allowed AI tools, and user responsibilitiesGoodshows a comprehensive policy aligning with laws and ethical standards
  • Goodincludes up-to-date records with details of each AI tool's purpose and scope
  • Asktraining records on AI policyLook atattendance records and training materials to ensure staff understand and follow the policyGoodshows widespread staff participation and clear instructional content
  • Look atintervals and findings to ensure regular analysis of AI outputs against policy standardsGoodincludes recent review entries and identified adjustments where necessary
  • Askrecords of policy reviews. Check dates and notes to ensure policy updates reflect current AI and legal standardsGoodshows regular updates and rationales for changes
link

Cross-framework mappings

How ISM-2074 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.1ISM-2074 requires an organisation to develop, implement and maintain a general-purpose artificial intelligence usage policy
handshakeSupports(1)expand_less
Annex A 5.15ISM-2074 requires a general-purpose AI usage policy that sets expectations and constraints for using AI tools
extensionDepends on(2)expand_less
Annex A 5.4ISM-2074 requires an organisation to have a documented and maintained policy governing general-purpose AI usage
Annex A 5.36ISM-2074 requires an organisation to develop, implement and maintain a general-purpose AI usage policy
linkRelated(1)expand_less
Annex A 5.10Annex A 5.10 requires organisations to set and implement acceptable use rules for information and assets

ISO 42001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 2.4Annex A 2.4 calls for periodic and as-needed reviews of the AI policy to ensure its effectiveness
Annex A 9.2Annex A 9.2 requires process documentation for responsible AI use

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for personnel security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls