How to read this book — and a disclaimer
This short handbook covers the AI for Defence course: an AI-basics on-ramp, then the Australian defence specifics — the policy stack, approved providers and sovereignty, shadow AI and real case studies, prompt hygiene and vendor evaluation, adversarial risks, the industry context, and a daily checklist. Nine chapters, read front to back in well under an hour — or jump to the part you need.
This is educational only — not legal or security advice. Australian AI policy for government changes every quarter. The book is anchored to the PSPF Policy Advisory 001-2025 and the Defence Policy Settings for Responsible Use of AI (March 2026), and was reviewed in June 2026. Always confirm tool-specific rulings with your own security advisor or ISO. AUKUS Pillar II material is out of scope.
Contents
What's Inside
2. Prompt Engineering
3. The Classification Boundary
5. Providers & Sovereignty
6. Shadow AI & Case Studies
7. Hygiene & Vendor Evaluation
8. Adversarial Risks & Industry
AI Basics
Chapter One
How AI Works & Is Trained
A large language model isn't a database or a search engine. It's a pattern-prediction system, trained on vast amounts of text to guess the most likely next words. That sounds abstract, but it has one very concrete consequence for Defence: the risk isn't the model being wrong — it's where your words go.
Models are trained on enormous text corpora, and on consumer tiers what you type can become training data for future versions unless you opt out. Your conversations are usually retained on the provider's servers, for a period and sometimes indefinitely. Enterprise and government tiers behave differently: they contractually don't train on your data, let you control retention, and add audit logging — which is exactly why approved tools matter so much in what follows.
The idea that matters
The data you type into an AI tool may be stored, may be seen by the provider, and — on consumer tiers — may be used to train future models. That single fact is the reason the rest of this book exists.
Try this
Open the privacy or data-handling page of the AI tool you use most. Find the answer to one question: does it train on my input by default, and how long does it keep my conversations?
Chapter Two
Prompt Engineering Essentials
Most disappointing AI output comes from vague prompts. The fix is a simple structure: tell the model who to be (role), give it the context only you have, state the task precisely, and specify the format you want. Then verify. This is the ‘Act–Explain–Please’ / RCTF approach, and it turns a generic answer into something genuinely useful for day-to-day work.
The one habit that separates good practice from bad is verification. A model can be fluent and wrong — so check names, dates, figures and claims before you use or forward anything. You are accountable for the output, not the model. And every prompt stays at the OFFICIAL level: keep personal, capability and contract detail out of it (the subject of the next chapter).
Key insight
Role + Context + Task + Format = reliable output — but you must still verify before you use it. Specificity beats everything.
Try this
Take a recent vague prompt and rebuild it with all four parts. Compare the two outputs — then fact-check the better one line by line.
Chapter Three
Confidentiality & the Classification Boundary
Here is the rule the whole course turns on: OFFICIAL information can be used with approved generative AI; OFFICIAL: Sensitive and above must never be entered into public AI tools. This is explicit in the DTA staff guidance and the PSPF Advisory. Because models retain — and sometimes train on — what you type, anything sensitive that goes in may be impossible to get back.
The practical habit is redaction: replace names with role descriptors, remove identifying numbers, generalise dates, and abstract any capability description before you ever paste. And when you're unsure of a classification, treat it as higher and ask.
The rule that matters most
OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET must never be entered into public generative AI. No exceptions, no ‘just this once’. The test: “Would I be content if this appeared in tomorrow's newspaper?” If not, redact it, generalise it, or use your approved enterprise tool.
Try this
Take a paragraph of real work and redact it for public-AI use: roles instead of names, no identifying numbers, generalised dates, abstracted capability. Notice how much is left — and whether it's still useful.
The Defence Specifics
Chapter Four
The Australian AI Policy Stack
As of 2026 there is a single, coherent stack of Australian policy for OFFICIAL-level generative AI. Top to bottom: the Policy for the Responsible Use of AI in Government v2.0 (DTA, December 2025) → PSPF Policy Advisory 001-2025 (Home Affairs, October 2025) → the DTA staff guidance → the Information Security Manual (ASD) → the Policy Settings for Responsible Use of AI in Defence (March 2026). Crucially, Defence sits outside the whole-of-government policy and is governed by its own Policy Settings.
Those Defence settings establish three obligations — lawfulness, values-based principles, and proportionate, risk-based controls — and the Accountable Officer, who retains accountability across the AI lifecycle even when authority is delegated. Governance runs through the Defence AI Centre (DAIC), established July 2024. And Defence is a real operational user: Microsoft 365 Copilot was rolled out on its PROTECTED network from September 2025. For industry, the December 2025 ISM added ISM-2074 — maintain a general-purpose AI usage policy — which is now part of what a DISP member (at Essential Eight Maturity Level 2) is expected to hold.
Key insight
For Defence APS staff and DISP-member contractors at OFFICIAL, the two binding anchors are the PSPF Policy Advisory 001-2025 and the Defence Policy Settings (March 2026). Know those two and where they sit.
Try this
Write down, from memory, the order of the policy stack and which layer binds you. Then check it against the live documents — this area changes every quarter.
Chapter Five
Approved Providers & Sovereignty
Under PSPF Advisory 001-2025, the approved set is 18 providers: 16 Hosting Certification Framework (HCF) Certified Service Providers, plus OpenAI and Anthropic directly. These are pre-approved. Every other provider must first undergo a Foreign Ownership, Control or Influence (FOCI) risk assessment under PSPF Direction 001-2024. It's the provider's certification — not the model's reputation — that decides whether a tool is pre-approved.
The same brand can be safe or unsafe depending on the tier. Consumer ChatGPT, Claude and Gemini may train on your input and retain it; enterprise tiers contractually don't train, let you control retention, and add audit logging. Several providers now offer in-country processing in Australia — but data residency is not the same as sovereignty: US-headquartered providers remain exposed to the US CLOUD Act, and a 2025 court order requires OpenAI to retain output logs (except for Zero-Data-Retention API customers).
All of this resolves into a three-question check you can run before any prompt: is the data OFFICIAL: Sensitive or above (if so, no public AI)? Is the provider one of the 18 or FOCI-assessed? Has the system been authorised under PSPF Requirements 0086–0088 by your Authorising Officer?
Key insight
Classification → approved provider → system authorisation. Run every prompt through those three gates and you'll resolve the vast majority of ‘can I use this?’ questions yourself. The live provider list is at hostingcertification.gov.au.
Try this
Take six everyday tasks and decide, for each, which tool is appropriate: a consumer chatbot, an enterprise tier, your agency's authorised AI, or none. Use the three gates to justify each call.
Chapter Six
Shadow AI & the Case Studies
Shadow AI — unsanctioned AI use via personal accounts, devices or plug-ins — is the dominant operational risk for this audience, because it's already happening. Australian surveys show roughly a quarter of public servants using unauthorised AI tools, most use self-initiated, the overwhelming majority untrained, and more than one in three professionals regularly uploading sensitive data to public tools.
The lead case study is Australian, recent and contractor-driven. In March 2025, a former temporary contractor at the NSW Reconstruction Authority uploaded a spreadsheet — 10 columns by more than 12,000 rows of personal and health data — into ChatGPT. The Authority later confirmed 2,031 people were affected; it was disclosed publicly in October 2025, more than six months later. The earlier Samsung case (2023) saw three source-code and transcript leaks within 20 days of allowing ChatGPT internally. The fix in both cases is the same: a sanctioned tool, a policy, training, and graduated detection — network logs show who, endpoint DLP and SaaS-discovery tools show (and can block) what.
The risk profile to remember
One contractor, one spreadsheet, one paste — 2,031 people's data exposed, undetected for six months. This is exactly the risk profile of a Defence-industry contractor, and exactly what good practice prevents.
Try this
Run a five-question self-audit of your own team: which AI tools, on which devices, through which accounts, for which tasks, with what training? The gaps you find are your shadow-AI exposure.
Chapter Seven
Prompt Hygiene & Vendor Evaluation
Prompt hygiene is the daily discipline that backs up the classification boundary. A public AI tool should never receive: anything OFFICIAL: Sensitive or above; personal information; third-party copyright; supplier commercial-in-confidence or pricing; Defence personnel or clearance data; source code for controlled systems; or recordings and transcripts of internal meetings. Green-light tasks — drafting unclassified comms, summarising public documents, translating public news — are fine, ideally via an approved tool. The DTA's three staff principles capture it: protect government information, critically assess outputs, and be able to explain and own your decisions.
Choosing a tool for OFFICIAL work is itself a security decision. Evaluate a vendor on its IRAP level, HCF certification, data residency, no-training default, retention and DPA terms, sub-processors and FOCI position, SOC 2 / ISO 42001 evidence, and any Zero-Data-Retention option. Five plain questions cut to the heart of any terms of service: is my data used to train (by default or opt-in)? How long is it kept, and can I shorten it? Who can access it? Where is it stored and processed? What happens if a foreign court orders production?
Key insight
Treat tool selection as a security decision, not a feature comparison — and redact every prompt to roles, no numbers, abstracted capability, before it ever leaves your hands.
Try this
Pick one AI vendor and answer the five terms-of-service questions from its public documentation. If you can't answer one, that's a finding worth recording.
Chapter Eight
Adversarial Risks & the Industry Context
Two AI-specific attacks matter here. Prompt injection is OWASP's top LLM risk (LLM01:2025): malicious instructions typed directly, or hidden in documents, web pages, calendar invites or images that the model later reads. A model can be hijacked by content it merely reads — so keep a human in the loop for any sensitive action. Model inversion is the risk that data fed into a model that trains on input can be extracted later; it's why the no-training contractual default matters, and why the three contractor leak patterns — code, document, capability — all run through public tools that retain and may train on what you paste.
For industry, doing AI safely is now a DISP expectation: an AI usage policy aligned to ISM-2074, public AI restricted to OFFICIAL, a register of tools used against capability work, and incident reporting through your security process. The major primes mostly use approved enterprise tooling and ban consumer AI on corporate devices (treat that as illustrative — your own security officer's policy binds). The SME baseline is achievable: license one approved tool, train staff on the boundary, document a one-page policy, and reach Essential Eight ML2. One hard caveat: AUKUS Pillar II material is outside the OFFICIAL framework entirely and must never touch public generative AI.
Key insight
The best defence against shadow AI is a sanctioned tool good enough that staff stop reaching for personal ones — paired with training and a one-page policy. And AUKUS-controlled material is always handled under its own arrangements, never here.
Try this
Draft a one-page AI usage policy for your own organisation: approved tools, the OFFICIAL floor, prohibited inputs, incident reporting, and a review date. Align it to ISM-2074 and the PSPF Advisory.
Putting It Together
Chapter Nine
Your Daily Checklist & Where Next
Everything in this book distils to a five-step habit you can laminate and keep at your desk. Before, during and after every AI use: a classification check (OFFICIAL or below for public AI); an approved-tool check (one of the 18, or your enterprise AI); a prompt-hygiene check (no personal, contract or capability detail, no code or transcripts); an output check (verify before use — you own the output); and knowing your incident response (if data went somewhere it shouldn't, report to your ISO/SO immediately and don't delete logs).
Two habits outlast any specific policy: report incidents fast and preserve the evidence, and treat your knowledge as perishable. Re-check the live documents whenever the PSPF Advisory or Defence Policy Settings change, the ISM updates, the approved-provider list shifts, or a major Australian AI incident occurs. Then put it to work: draft or refresh your one-page policy, brief your team on the classification boundary, and book a quarterly refresh while the policy stack keeps moving.
Key insight
Five checks, every time: classification → approved tool → prompt hygiene → verify the output → know how to report an incident. The human is always accountable for the output.
Try this — one last time
Print the five-point checklist, pin it where you work, and run it on your next real AI task. Then book the quarterly refresh — because this area changes every quarter.
You've reached the end
For the interactive version — all 22 lessons with diagrams and exercises — head to the AI for Defence dashboard. Remember: this is educational only, not legal or security advice; it was reviewed in June 2026; and it's a living book — check back for the latest edition or grab a fresh PDF. Always confirm tool-specific rulings with your security advisor.