Skip to main content

Policy Advisory – OFFICIAL Information Use with Generative Artificial Intelligence

This Policy Advisory concerns the use of OFFICIAL information with generative artificial intelligence (AI) technologies.

Entities can use OFFICIAL information, including information created for business operations and services, with generative AI technologies.

Use of generative AI technologies must be assessed under existing responsibilities in the PSPF.

Adopting the following principles ensures entities have considered and managed data security risks when incorporating generative AI into business operations. Entities must:

  • only give access to generative AI products hosted on Hosting Certification Framework providers, OpenAI or Anthropic; or have had a Foreign Ownership, Control, or Influence (FOCI) risk assessment
  • appropriately manage security classified information when using generative AI as part of staff training on responsible AI use
  • follow the existing technology authorisation process in PSPF Requirements 0086, 0087 and 0088. They must also consider relevant Australian Signals Directorate Guidance when approving access to generative AI tools for use with OFFICIAL information.

Entities giving access to generative AI products certified under the Hosting Certification Framework, OpenAI and Anthropic do not need extra FOCI assessment to the assurance given by the Department of Home Affairs. All other providers must be assessed under PSPF Direction 001-2024 before allowing access.

Certified Service Providers under the Hosting Certification Framework include:

  • Amazon Web Services (including Nova)
  • AUCloud
  • Centorrino Technologies Pty Ltd
  • Deloitte
  • Emantra
  • GoHosting Pty Ltd
  • Google Australia (including Gemini and Notebook LM)
  • IBM Australia
  • Ironstar Hosting Services Pty Ltd
  • Macquarie Telecom Pty Ltd
  • Medihost Solutions
  • Microsoft Azure Cloud (including all Microsoft products and Microsoft 365)
  • Oracle Australia (including AI services)
  • Secure Collaboration
  • Sliced Tech Pty Ltd
  • Vault Cloud

For more information see Policy Advisory - OFFICIAL Information Use with Generative Artificial Intelligence on the Policy Advisory page.