What happened
ASD's September 2026 quarterly release of the Information Security Manual (ISM) — the mandated cyber security control catalogue for Australian government agencies and a widely-referenced benchmark for industry — incorporated new AI-specific controls and guidance across at least seven chapters: Guidelines for Security Assurance (AI models for detecting cyber security events/incidents), Guidelines for System Management (retention requirements for records created using AI, referencing National Archives of Australia guidance), Guidelines for Enterprise Mobility (systems disallowed from granting access to unapproved AI agents), Guidelines for Procurement and Outsourcing (AI application supply-chain considerations), Guidelines for Media, Guidelines for Networking, and Guidelines for Cyber Security Roles (non-human/AI identity role guidance). Individual chapter pages carry a 'September 2026' publication label with 'Updated: Sep-26' control revision tags.
Why it matters
The ISM is a normative, mandated control catalogue (not merely advisory) for Australian Commonwealth entities and a de facto reference for regulated industry; embedding AI-agent access controls, AI-record retention, and AI-assisted monitoring directly into ISM control language moves AI security from guidance into an enforceable compliance baseline for a national government.
Action needed
Australian government agencies and ISM-aligned organizations should map current AI deployments (agents, copilots, AI-assisted SOC tooling) against the updated ISM controls — particularly unapproved-AI-agent access blocking, AI-generated record retention, and AI-assisted security monitoring — and update Essential Eight / assurance documentation accordingly.