Skip to content
arrow_back
search
ISM-2084 policy ASD Information Security Manual (ISM)

Document AI Model Characteristics and Risks

Use specific documentation to detail AI models, their architecture, usage, and potential security risks.

record_voice_over

Plain language

This control is about making sure that any artificial intelligence (AI) systems used in your organisation are well-documented. This includes knowing how they work, what they're used for, and what security risks they might pose. If this isn't done, your business could unknowingly face privacy breaches or make decisions based on flawed AI, leading to financial loss or reputational damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Artificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics, system architectures, use cases and security risks.
policy ASD Information Security Manual (ISM) ISM-2084
priority_high

Why it matters

Without model/system cards documenting AI characteristics, use cases and architecture, security risks can be missed, enabling misuse, data leakage and unsafe decisions.

settings

Operational notes

Maintain model/system cards for each AI system and update after model, data or architecture changes; record intended use, limits, threats and security risks.

Mapping detail

Mapping

Direction

Controls