7.2 AI for Defence · Module 7 · Defence Industry Context

Primes & SMEs: What's Expected

From the big primes' approach down to a workable SME baseline.

IndustryExercise~15 min

The big idea

Major Australian primes (BAE Systems Australia, Lockheed Martin Australia, Thales Australia, Saab Australia, Boeing Defence Australia) publicly commit to ‘responsible AI’ that mirrors Defence's three obligations, mostly using approved enterprise tooling and prohibiting consumer AI on corporate devices. Treat those as illustrative only — your binding policy is your own corporate security officer's. For a small DISP-member SME, the baseline is achievable: license one approved tool, train staff on the OFFICIAL boundary, document a one-page policy aligned to ISM-2074, and align cyber posture to Essential Eight ML2.

Key insight: An SME doesn't need to build an enterprise AI stack. License one approved tool good enough that staff stop reaching for personal ones, train them on the boundary, and write the one-page policy.

What you'll see

The primes' approach and the SME baseline.

From primes to SMEs

What good looks like at each scale. Tap to expand.

Key points to remember

Primes use approved tooling and ban consumer AI on corporate devices.
Treat prime policies as illustrative; your own security officer's is binding.
SME baseline: one approved tool + training + a one-page policy + Essential Eight ML2.
A good sanctioned tool is the best defence against shadow AI.