RC
Rupert Chesman
or Space to navigate
1 / 17
A practical course for working safely at OFFICIAL

AI for Defence

Using AI safely, productively and in compliance — for Defence APS staff & DISP-member contractors

Educational only — not legal or security advice. Reviewed June 2026. Confirm tool-specific rulings with your security advisor.

by Rupert Chesman

Why this matters now

The Reality

~25%
of Australian public servants already use unauthorised AI tools
Mandarin / Liquid Interactive, Sept 2025
1 in 3
Australian professionals regularly upload sensitive data to public AI tools
Josys, 2025
18
providers approved under PSPF Advisory 001-2025 — your team needs to know which
ISM-2074
now expects a documented general-purpose AI usage policy
ASD, ISM Dec 2025
The rule that matters most

The Classification Boundary

✓ OFFICIAL — generally OK

OFFICIAL information can be used with approved generative AI, subject to your entity's policy.

✕ OFFICIAL: Sensitive and above

Never entered into public AI tools. No exceptions, no ‘just this once’.

The test: “Would I be content if this appeared in tomorrow's newspaper?”

Structure

Course Overview

A

AI Basics

The on-ramp: how AI works and is trained, prompt engineering, and the confidentiality boundary the whole course turns on.

Module 1

B

AI for Defence: The Specifics

The policy stack, approved providers & sovereignty, shadow AI & case studies, prompt hygiene & vendor evaluation, adversarial risks, the industry context, and your checklist.

Modules 2–8

8 modules · 22 interactive lessons · exercises, case studies & a laminated checklist

Section A
01

AI Basics for Defence

  • How AI works & how it's trained
  • Prompt engineering essentials
  • Confidentiality & the classification boundary

Key takeaway: Understand what AI is and where your data goes — before any rules.

Section B
02

The Australian AI Policy Stack

  • The Australian AI policy hierarchy
  • Defence's own rules: obligations, DAIC & the Accountable Officer
  • DISP, the Essential Eight & ISM-2074

Key takeaway: Your two anchors: the PSPF Advisory 001-2025 and the Defence Policy Settings (March 2026).

Section B
03

Data Sovereignty & Approved Providers

  • The approved-provider regime (the 18 providers)
  • Where the models actually process data
  • The ‘Can I use this tool?’ decision flowchart

Key takeaway: It's the provider's certification — not the model's brand — that decides what's allowed.

Section B
04

Shadow AI & Case Studies

  • What shadow AI is — and how common
  • Case study: the NSW Reconstruction Authority leak
  • The Samsung leak & detecting shadow AI

Key takeaway: The biggest risk is a well-meaning staffer quietly pasting work into a consumer tool.

Section B
05

Prompt Hygiene & Vendor Evaluation

  • Prompt hygiene & redaction
  • Safe vs prohibited tasks at OFFICIAL
  • Evaluating an AI vendor

Key takeaway: Roles not names, no identifying numbers, abstract capability — before you ever paste.

Section B
06

Adversarial Risks

  • Prompt injection (OWASP LLM01:2025)
  • Model inversion & IP exposure

Key takeaway: A model can be hijacked by content it merely reads — keep a human in the loop.

Section B
07

Defence Industry Context

  • Your AI obligations as a DISP member
  • Primes & SMEs: what's expected
  • AUKUS Pillar II — the hard caveat

Key takeaway: For industry, doing AI safely is now a DISP expectation, not a nice-to-have.

Section B
08

Your Checklist & Putting It Together

  • Your daily AI-at-OFFICIAL checklist
  • Incident response, staying current & where next

Key takeaway: Five checks, every time — and treat your knowledge as perishable.

Case study spotlight

NSW Reconstruction Authority

March 2025: a former temporary contractor uploaded a spreadsheet — 10 columns by 12,000+ rows of personal and health data — into ChatGPT.

2,031
people confirmed affected
12,000+
rows of data pasted in
~6 mo
before public disclosure
1 paste
one contractor, one spreadsheet

The closest analogue to the Defence-industry contractor risk — and exactly what this course prevents.

The most useful habit

‘Can I Use This Tool?’ Three Gates

1

Classification

OFFICIAL: Sensitive or above? Stop — no public AI.

2

Approved provider

One of the 18, or a completed FOCI assessment?

3

System authorisation

Authorised under PSPF 0086–0088 by your Authorising Officer?

Run every prompt through these three gates. When any is unclear — ask your security advisor.

Your laminated desk habit

The Daily Checklist

  • Classification check — OFFICIAL or below for public AI
  • Approved-tool check — one of the 18, or your enterprise AI
  • Prompt-hygiene check — no personal, contract or capability detail
  • Output check — verify before use; you own the output
  • Incident response — report to your ISO/SO; don't delete logs
A note on currency

This Area Changes Every Quarter

This course is educational, not legal or security advice. It's anchored to the PSPF Policy Advisory 001-2025 and the Defence Policy Settings for Responsible Use of AI (March 2026), and was reviewed in June 2026. Re-check the live documents whenever the policy stack, the ISM, or the approved-provider list changes — and always confirm tool-specific rulings with your own security advisor or ISO.

Next Steps

Bring This Course to Your Team

A 4-hour intensive for Defence APS teams and DISP-member contractors — in person or virtual.

Enquire About Training