Skip to content
arrow_back
ISM-2085policyASD Information Security Manual (ISM)

Prevent Exposure of AI Model Confidence Scores

Do not show AI model confidence scores in outputs to avoid revealing exact confidence levels.

record_voice_over

Plain language

This control advises against displaying how confident an AI model is about a decision or prediction. Sharing such confidence scores could allow others to figure out how your AI makes decisions, potentially leading to misuse or manipulation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The exposure of exact AI model confidence scores in API outputs or user interfaces is prevented.
policyASD Information Security Manual (ISM)ISM-2085
priority_high

Why it matters

Revealing AI confidence scores could lead to exploitation, distorting the decision-making process or reducing system reliability.

settings

Operational notes

Regularly check AI outputs to ensure confidence scores remain hidden, adapting practices as AI models evolve.

build

Implementation tips

  • AI developers should avoid including confidence scores in user-facing outputs. Instead, summarise results without specific numbers to prevent revealing internal working details.
  • Product managers should ensure user interfaces are designed to display decisions without confidence scores. They can work with designers to present outcomes understandably without details that expose confidence.
  • IT teams must configure APIs to exclude confidence scores from responses. This can be done by altering the API settings or data output format to suppress these numbers.
  • Project leads should regularly review AI outputs for unintentional exposure of confidence levels. Set periodic audits or tests to confirm that outputs are free of these details.
  • Compliance officers should train staff to understand the importance of keeping confidence scores private. Host workshops and create materials that outline risks of exposing this information.
fact_check

Audit / evidence tips

  • Askuser interface design documents: Verify that they specify no confidence scores shownLook atscreen mock-ups to ensure such details are not includedGoodis documentation showing outcomes without numeric confidence values
  • Goodis a clear indication that no confidence scores are provided
  • Look atadjustments made to suppress confidence scoresGoodis clear evidence of configuration changes
  • Asktraining materials on AI outputs: Ensure there's content educating staff on not sharing confidence scores. Training slides or manuals should highlight this control's requirementsGoodinvolves well-documented training sessions focused on privacy
  • Look atdetailed records showing review dates and findingsGoodis consistent documentation of no breaches over time
link

Cross-framework mappings

How ISM-2085 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.28ISM-2085 requires organisations to prevent exposing exact AI model confidence scores in APIs and user interfaces

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls