Guidelines  ·  2026-09-09

Australian Signals Directorate updates Information Security Manual (ISM) with AI-specific controls across multiple chapters

GuidelinesHigh impactAustralia
ASD's September 2026 quarterly release of the Information Security Manual (ISM) — the mandated cyber security control catalogue for Australian government agencies and a widely-referenced benchmark for industry — incorporated new AI-specific controls and guidance across at least seven chapters: Guidelines for Security Assurance (AI models for detecting cyber security events/incidents), Guidelines for System Management (retention requirements for records created using AI, referencing National Archives of Australia guidance), Guidelines for Enterprise Mobility (systems disallowed from granting access to unapproved AI agents), Guidelines for Procurement and Outsourcing (AI application supply-chain considerations), Guidelines for Media, Guidelines for Networking, and Guidelines for Cyber Security Roles (non-human/AI identity role guidance). Individual chapter pages carry a 'September 2026' publication label with 'Updated: Sep-26' control revision tags.
The ISM is a normative, mandated control catalogue (not merely advisory) for Australian Commonwealth entities and a de facto reference for regulated industry; embedding AI-agent access controls, AI-record retention, and AI-assisted monitoring directly into ISM control language moves AI security from guidance into an enforceable compliance baseline for a national government.
Australian government agencies and ISM-aligned organizations should map current AI deployments (agents, copilots, AI-assisted SOC tooling) against the updated ISM controls — particularly unapproved-AI-agent access blocking, AI-generated record retention, and AI-assisted security monitoring — and update Essential Eight / assurance documentation accordingly.
Cyber.gov.au — Guidelines for security assuranceCyber.gov.au — Guidelines for system managementCyber.gov.au — Guidelines for enterprise mobilityCyber.gov.au — Guidelines for cyber security roles
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →