7.1
AI for Defence · Module 7 · Defence Industry Context
Your AI Obligations as a DISP Member
What you should be able to show a Defence customer about your AI use.
Industry~12 min
The big idea
Contractors handling OFFICIAL Defence information should expect to: (a) maintain an AI usage policy (aligned to ISM-2074), (b) restrict public AI tools to OFFICIAL only, (c) keep a register of AI tools used against capability work, and (d) report AI-related incidents — such as inadvertent uploads — through their security incident processes. A DISP audit will increasingly ask for exactly these.
Key insight: Being able to articulate your AI obligations to a Defence customer — policy, boundary, register, incident process — is fast becoming part of demonstrating DISP compliance.
What you'll see
The four things a DISP member should be able to show on AI.
The four expectations
What to have in place. Tap to expand.
Key points to remember
Maintain an AI usage policy aligned to ISM-2074.
Restrict public AI to OFFICIAL; keep sensitive work off it.
Keep a register of AI tools used against capability work.
Report AI incidents through your security incident process.