7.1 AI for Defence · Module 7 · Defence Industry Context

Your AI Obligations as a DISP Member

What you should be able to show a Defence customer about your AI use.

Industry~12 min

The big idea

Contractors handling OFFICIAL Defence information should expect to: (a) maintain an AI usage policy (aligned to ISM-2074), (b) restrict public AI tools to OFFICIAL only, (c) keep a register of AI tools used against capability work, and (d) report AI-related incidents — such as inadvertent uploads — through their security incident processes. A DISP audit will increasingly ask for exactly these.

Key insight: Being able to articulate your AI obligations to a Defence customer — policy, boundary, register, incident process — is fast becoming part of demonstrating DISP compliance.

What you'll see

The four things a DISP member should be able to show on AI.

The four expectations

What to have in place. Tap to expand.

Key points to remember

Maintain an AI usage policy aligned to ISM-2074.
Restrict public AI to OFFICIAL; keep sensitive work off it.
Keep a register of AI tools used against capability work.
Report AI incidents through your security incident process.