Rate Limiting for AI Inference Queries
Limit the rate at which AI models can be queried to prevent overuse.
Plain language
This control is about setting limits on how often people can use AI tools to make sure they aren't overused and possibly hacked. If too many queries are allowed, it could lead to system overload or unwanted access, which can disrupt business operations and expose sensitive data.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2025
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
Rate limiting is applied to inference queries for AI models.
Why it matters
Not applying rate limits on AI queries can lead to system overload or security breaches, risking business disruption and data exposure.
Operational notes
Regularly review and adjust rate limits to match system capabilities and user needs, ensuring both operational efficiency and security.
Implementation tips
- IT team should set limits on AI service access. They can do this by configuring software to accept only a set number of queries every hour. This reduces the risk of system overload and possible misuse.
- System managers should monitor usage patterns. They need to regularly check reports for any unusual spikes in AI queries. This helps identify and address potential misuse early.
- Business owners should communicate these limits to the team. They can hold a meeting or send out an email explaining how and why rate limiting is important for protecting the business.
- Security personnel should audit the system for bypass attempts. Regularly review logs for signs of attempts to exceed query limits to catch and respond to malicious activities quickly.
- The IT department should continuously update rate limits based on capacity and usage trends. Evaluate system performance and adjust limits to balance usability with security effectively.
Audit / evidence tips
- Askthe rate limiting configuration document: Request details about the settings controlling AI query limits. Look to ensure limits align with capacity and security needsGoodincludes documented thresholds tailored to system capability
- Askreports on AI query usage: Request logs showing recent AI queries and any exceeded limitsLook atconsistency with set policies and spike identificationGoodshows acceptable usage patterns with logged exceptions
- Asksystem alert documentation: Request information on alerts configured for when limits are exceededLook atactive alerts that notify the right personnel promptlyGoodincludes timely alerts connected to a response plan
- Askstaff meeting notes or emails about rates: Request records of communications regarding rate limits shared with relevant staffLook atclear instructions and rationaleGoodshows comprehensive communication to involved teams
- Askincident response records: Request any reports or logs from incidents related to exceeding AI query limitsLook atappropriate handling and quick resolution of such incidentsGooddescribes prompt investigation and mitigation
Cross-framework mappings
How ISM-2090 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 8.6 | Annex A 8.6 requires monitoring and adjustment of resource use to prevent performance degradation or failures due to capacity shortfalls | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.