The six AI cyber controls every Australian org needs
Baseline AI risk controls
- AI register — every model in use, vendor, data flow, business owner, risk rating.
- Acceptable-use policy with explicit shadow-AI controls and data handling rules.
- Data-loss prevention rules covering pasted text and uploaded documents to AI tools.
- Human-in-the-loop requirements for AI-influenced material decisions.
- Vendor governance: ISO/IEC 42001 alignment, training-data position, incident clauses.
- Board-level oversight under the existing risk-management framework, not a parallel one.
Shadow AI is the immediate problem
Staff are pasting customer data, source code and board papers into consumer AI tools today. Block-everything rarely works; instead, provide a sanctioned alternative, configure DLP rules to detect material data flowing to AI endpoints, and brief the board on what is being controlled and what is residual.
How ISO/IEC 42001 fits
ISO/IEC 42001 sits next to ISO/IEC 27001 the way an ISMS sits next to a quality system. Use 27001 for information security capability, 42001 for AI management capability and CPS 234 / SOCI for regulated overlays. The frameworks are stackable, not competing.
FOR LEADERS GOVERNING AI RISK
Structure your AI risk decisions into defensible options.
FORTE/CYBERx generates three ranked, framework-anchored options against ISO 27001, ISO 42001, CPS 234 and the federal AI Ethics Principles.
Start a free missionWhat boards will ask in the next 12 months
- Do we have an AI register, and is it current?
- Where is our data going when staff use AI tools?
- Which decisions are AI-influenced, and what is the human oversight?
- Are our AI vendors ISO/IEC 42001-aligned?
- What is our AI incident response plan?
FAQ
What are the main AI cyber risks for Australian organisations?
The top AI cyber risks are: data leakage into third-party models, shadow AI use bypassing controls, model manipulation (prompt injection, training-data poisoning), over-reliance on AI for material decisions and unclear accountability when an AI-influenced decision goes wrong. Each maps to controls in ISO/IEC 42001 and ISO/IEC 27001:2022.
How do Australian regulators view AI risk?
APRA, ASIC and the OAIC have all signalled that AI does not change the underlying accountability of directors and officers. The federal AI in Government Policy and the voluntary AI Safety Standard expect risk-based controls, transparency and human oversight. Regulated entities should treat AI systems that influence material decisions as in-scope for existing risk-management standards.
Does ISO/IEC 42001 apply to my organisation?
ISO/IEC 42001 is the AI management system standard. It is not legally mandated but is rapidly becoming the expected evidence base — particularly for organisations deploying AI in regulated sectors, government supply chains or customer-facing decisions. Aligning to it now reduces audit and tender friction later.
How should AI use be governed inside the business?
Run AI through the same governance pattern as any other technology risk: register every AI system, classify by risk, assign an accountable owner, define acceptable use, monitor for drift and report to the board. A standalone "AI policy" without a register and ownership is decorative.