3.3 AI for Defence · Module 3 · Data Sovereignty & Approved Providers

The ‘Can I Use This Tool?’ Decision Flowchart

Three questions that resolve almost every ‘is this allowed?’ moment.

FlowchartExercise~12 min

The big idea

This is the single most useful habit from the course — a three-question check to run before any AI prompt: (1) Is the data OFFICIAL: Sensitive or above? If yes → no public AI. (2) Is the provider one of the 18 in the PSPF Advisory, or has it passed a FOCI assessment? (3) Has the system been authorised under PSPF Requirements 0086–0088 by your Authorising Officer? Laminate it; keep it at your desk.

Key insight: Classification → approved provider → system authorisation. Run every prompt through those three gates and you'll resolve the vast majority of ‘can I use this?’ questions yourself.

What you'll see

The three-question decision flowchart, plus the tool-selection exercise.

The three gates (and a practice exercise)

Work each gate in order. Tap to expand.

Key points to remember

Three gates: classification → approved provider → system authorisation.
If the data is OFFICIAL: Sensitive or above, the answer is always ‘no public AI’.
Keep the flowchart at your desk and run it every time.
When any gate is unclear, ask your security advisor before proceeding.