Skip to content
arrow_back
search
ISM-2092 policy ASD Information Security Manual (ISM)

Implement Fine-Grained AI Application Permissions

Organisations set detailed access rules to control who can use artificial intelligence applications.

record_voice_over

Plain language

This control is about making sure that only the right people in an organisation have access to artificial intelligence applications. It matters because if someone who shouldn’t be using these applications gets access, they might misuse sensitive information, leading to privacy breaches or damaging decisions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Access control policies are implemented to enforce fine-grained permissions for artificial intelligence applications.
policy ASD Information Security Manual (ISM) ISM-2092
priority_high

Why it matters

Lax AI access controls could lead to data leaks, misuse of sensitive information, and unauthorised decisions, risking reputation and financial loss.

settings

Operational notes

Regularly review AI app permissions by role, tool and dataset scope, and promptly update least-privilege rules when models, plugins or responsibilities change.

Mapping detail

Mapping

Direction

Controls