What the DeepSeek Direction actually bans
PSPF Direction 001-2025 is two pages, signed under the Secretary of the Department of
Home Affairs, and dated 4 February 2025. Its operative sentence requires Australian
Government entities to prevent the access, use or installation of DeepSeek products,
applications and web services and where found remove all existing instances
from all
Australian Government systems and devices. The reasoning is stated rather than implied: the
Secretary determined the use of them poses an unacceptable level of security risk
,
and entities must manage the risks arising from DeepSeek’s extensive collection of
data and exposure of that data to extrajudicial directions from a foreign government that
conflict with Australian law
.
That is a supply-chain and jurisdiction argument, not a claim about model quality, and
the scope of the ban follows the argument closely. Footnote 2 defines products,
applications and web services as everything supplied directly or indirectly by DeepSeek
or any of its predecessor, successor, parent, subsidiary, or affiliate companies
. The
target is the company and the pipe to it.
The carve-out, which is three conditions and is easy to miss
The same footnote then says the ban does not include open sourced Large Language
Models (LLM) where the entire codebase is available for inspection, the model is deployed
locally on a government system, and appropriate mitigations are in place as outlined in
Policy Explanation Note 001-25
.
Read that as three cumulative conditions rather than a general exemption for open weights. The codebase has to be inspectable, the deployment has to be local to a government system, and the mitigations in a separate note have to be in place. Miss any one and you are back inside the ban.
It is a coherent position, and it is the same position the reasoning implies: if the risk is data leaving for a jurisdiction that can compel its disclosure, a model running on your own infrastructure with no call home does not create that risk. It is also the part most likely to be reported as Australia banned DeepSeek without qualification. The Commonwealth banned the company’s services. It did not ban the arithmetic.
There is a limit worth naming. The exemption route for the banned services themselves is
narrow: an Accountable Authority may seek one for a legitimate business reason
limited to national security and regulatory functions
, it must be time
limited
, and the Direction names only one category, where use is necessary for
national security or regulatory functions including compliance and law enforcement.
Then the mechanism changed
DeepSeek was not the first named ban and was never going to be the last. The public library carries Direction 001-2023 on the TikTok application, Direction 002-2025 on Kaspersky Lab products and web services in February 2025, and Direction 001-2024 on managing foreign ownership, control or influence risks in technology. Each named ban is its own public document, which is a slow instrument if the problem is a steady stream of applications rather than one company.
In October 2025 the approach changed. Direction 004-2025 on Commonwealth
Technology Management was signed by Stephanie Foster PSM, Secretary of the
Department of Home Affairs, and it points at a standing list instead of naming anything.
The Secretary determined further guidance was needed to respond to the growing use of
products, applications and web services within Australian Government entities that pose an
unacceptable level of security risk to Australian Government networks and data arising from
threats of foreign interference, espionage and sabotage
.
It carries two dated obligations, and both have now passed.
| From | Every entity must |
|---|---|
| 31 October 2025 | Identify and remove all existing instances of products, applications and web services on the Deny List; prevent installation of new ones; report completion to Home Affairs |
| 2 February 2026 | Implement a policy to consider sharing risk assessments through the Centralised Risk Sharing Capability; implement a process at technology system authorisation that considers the Applications Policy; report completion |
The exemption test is looser here than in the DeepSeek Direction, which is worth noting
because the Deny List is the broader instrument. It is still a time-limited
legitimate business reason
, but the Direction names three qualifying categories
rather than one: regulatory functions including national security, compliance and law
enforcement; research or communications assisting a work objective, with
countering mis- or dis-information
given as the example; and where an entity
must use the application to reach key audiences to undertake marketing or public
relations activity
.
What is not published, stated precisely
The Direction binds. The list it binds you to is somewhere else.
We enumerated the PSPF publications library in full on 29 August 2026: 40 items across
four pages, grouped as Directions, Fact sheets, General, Guides, Policy Advisory, Posters
and Reporting. Neither the Commonwealth Technology Standard nor Policy Explanatory
Note 005-2025 is among them, and neither is Policy Explanation Note 001-25, the
note the DeepSeek carve-out depends on. A search of the department’s own domain did
not surface them either. The framework does have a members-only channel: the PSPF Release
2026 list of requirements says government personnel can get the spreadsheet version
on the Protective Security Policy GovTEAMS community
.
We are not asserting the list is secret in any formal sense, and we have not asked Home Affairs for it, which is the obvious next step and one we have not taken. What can be said from the documents is narrower and still worth saying: the obligation is public and the thing it obliges you to do is not.
There are good reasons a threat-informed deny list is not a public webpage. Publishing
it tells the vendors on it exactly where they stand and tells everyone else where the
Commonwealth’s attention is, and the underlying Technology Vendor Review Framework
was announced in December 2024 on exactly that reasoning: the government said:
To ensure the integrity of the framework’s processes and protect information
related to national security, the framework will not be made public
. That is a
different instrument from the Standard, and we are quoting it as the stated rationale for
the family rather than as a statement about the Deny List itself.
The trade-off is still real. When the Commonwealth banned TikTok and DeepSeek it did so in documents anybody could read, which meant a vendor, a journalist or a member of the public could see what had been decided and on what reasoning. The standing list does not work that way, and it is now the operative mechanism.
What this means if you are affected
If you work in a non-corporate Commonwealth entity, the Deny List obligation fell due on 31 October 2025 and the Applications Policy obligation on 2 February 2026, both with a reporting step to the Commonwealth Security Policy Branch. If you are running a local open weights deployment of a banned vendor’s model, the carve-out is three conditions and the third one lives in a note you may need to request.
If you sell AI to government, the position is less comfortable than it looks. Your buyer is bound to a list you cannot read, maintained by a department you are not the customer of, and the criteria are foreign ownership, control and influence rather than anything about your product’s behaviour. The public Directions are the best available guide to how that reasoning runs, which is a reason to read them rather than the headlines about them.
We have asked nobody for the Standard yet. If we do, we will publish what comes back.
Sources
- PSPF Direction 001-2025 on DeepSeek Products, Applications and Web Services, protectivesecurity.gov.au, published 4 February 2025 (PDF downloaded and read in full 29 August 2026): the operative requirement to prevent access, use or installation and remove existing instances; the unacceptable-level-of-security-risk determination and the extrajudicial-directions reasoning; footnote 2 defining products, applications and web services to include predecessor, successor, parent, subsidiary and affiliate companies; the open sourced LLM exclusion and its three conditions; and the exemption limited to national security and regulatory functions, which must be time limited.
- PSPF Direction 004-2025 on Commonwealth Technology Management, protectivesecurity.gov.au, signed October 2025 by Stephanie Foster PSM, Secretary of the Department of Home Affairs (PDF downloaded and read in full 29 August 2026): the foreign interference, espionage and sabotage rationale; the 31 October 2025 Deny List obligations and the 2 February 2026 Centralised Risk Sharing Capability and Applications Policy obligations, each with a reporting step; the three categories of legitimate business reason; and the references to Policy Explanatory Note 005-2025.
- Protective Security Directions under the PSPF, protectivesecurity.gov.au (read 29 August 2026): that the Accountable Authority of each entity must adhere to any Direction issued, and the current list of Directions including 001-2023 on TikTok and 002-2025 on Kaspersky.
- PSPF publications library, protectivesecurity.gov.au (all four pages enumerated 29 August 2026): the full set of 40 published items and their type groupings, which is the basis for the statement that the Commonwealth Technology Standard, Policy Explanatory Note 005-2025 and Policy Explanation Note 001-25 do not appear there.
- PSPF Annual Release, protectivesecurity.gov.au (read 29 August 2026): that PSPF Release 2026 was issued on 1 July 2026, and the quoted note that government personnel can access the Excel spreadsheet of the release's requirements on the Protective Security Policy GovTEAMS community.
- Minister for Home Affairs, New framework to address technology security risks, media release 20 December 2024 (read 29 August 2026): the Technology Vendor Review Framework and the quoted statement that, to ensure the integrity of the framework's processes and protect information related to national security, the framework will not be made public. Quoted here as the stated rationale for this family of instruments, and not as a statement about the Commonwealth Technology Standard.
How we checked this. Both Directions were downloaded as PDFs from the links on their own publications-library pages and read in full; the quotations are from those documents. The absence claim is bounded deliberately: we enumerated all 40 items in the PSPF publications library rather than searching it, because the site's search parameter does not filter results, and we then checked the department's own domain. We have not asked Home Affairs for the Standard, so this is an observation about what is published, not about what would be released on request.
Work in an entity that has done the Deny List removal, or read these Directions differently? Tell us and we will check it against the documents and log the outcome here.