The advisory is permissive, which is the first surprise
Most of what the Commonwealth has published about AI security this year removes things:
DeepSeek banned, Kaspersky banned, a standing deny list of applications to be stripped off
government devices. Policy Advisory 001-2025 runs the other way. Its opening line is that
generative AI presents exciting opportunities to improve how government entities manage
and use OFFICIAL information in their daily operations
, and it exists to support
the safe and confident adoption
of it.
The operative sentence is the one a public servant actually needs:
OFFICIAL information, including information created for business operations and
services, can be used
with generative AI technologies, with a footnote marker sitting
between used
and with
in the original. That is a whole-of-government
answer to a question that has been answered department by department until now.
Two scope points matter. OFFICIAL is the lowest tier of the Australian Government's
information classifications, so this is not permission for anything security classified,
and requirement 2 below is specifically about staff knowing that difference. And the
advisory's first footnote defines use
broadly, covering software on internal
systems or mobile devices, outsourced service providers, and web-based products,
including websites such as ChatGPT.com, accessed through web browsers or cloud service
providers
. The pasting-into-a-browser case is explicitly in scope rather than left to
inference.
The three requirements
The advisory sets out what entities must do, and the first is the one with news in it.
| # | Requirement |
|---|---|
| 1 | Only provide access to generative AI products hosted on Hosting Certification Framework providers, OpenAI or Anthropic, or that have undergone a Foreign Ownership, Control, or Influence (FOCI) risk assessment |
| 2 | Ensure staff training includes guidance on handling security classified information when using generative AI |
| 3 | Follow the existing PSPF technology authorisation process and consider relevant Australian Signals Directorate guidance when approving access for use with OFFICIAL information |
Requirement 3 is not a gesture at good practice. It points at three numbered PSPF
requirements, 0086, 0087 and 0088, which between them say an Authorising Officer must
authorise each technology system before it processes government information, that the
decision follows the Information Security Manual's risk-based approach, and that a system
is authorised only to the highest classification of the data it will handle. The advisory
also points to the ASD's Engaging with artificial intelligence
guidance and its Zero
Trust Modern Defensible Architecture Principles.
The named-companies part, and what it actually says
Footnote 2 is where the policy does something unusual. Entities providing access to
generative AI products certified under the Hosting Certification Framework, OpenAI and
Anthropic, do not require additional FOCI assessment to the assurance provided by the
Department of Home Affairs. All other providers must be assessed in accordance with PSPF
Direction 001-2024 before allowing access.
Read that carefully, because it is narrower than a government endorsement and wider than a technicality. It is not a statement that these two companies are better, safer or preferred. It is a statement that Home Affairs has already done the foreign-ownership work for them, so an individual entity does not have to repeat it. The assurance sits with the department, not with the vendor.
The practical effect is still a real commercial asymmetry. If you sell a generative AI product to an Australian government entity and you are not hosted on a certified provider, OpenAI or Anthropic, your buyer must commission a foreign ownership, control or influence assessment under a separate Direction before staff can touch your product. That is time, internal effort and a risk owner willing to sign, which is a meaningful barrier for a smaller or newer vendor, including an Australian one.
An allow list you can read, and a deny list you cannot
Put this beside what we published on 29 August and the shape of the regime is clearer than either document is on its own.
The Commonwealth now runs both ends. At one end is the Commonwealth Technology Standard Deny List, made binding by PSPF Direction 004-2025 from 31 October 2025, which entities must strip off their systems and which does not appear anywhere in the PSPF publications library. At the other is this advisory, which names two companies in public and tells entities they may proceed without further assessment.
That asymmetry is defensible on its own terms. Publishing who is banned tells a hostile vendor exactly where it stands and tells everyone where the Commonwealth's attention is; publishing who is cleared tells a procurement officer they may stop worrying. The information hazard runs one way. It is still worth naming plainly, because the same framework is being unusually open at one end and closed at the other, and a reader who saw only one document would draw the wrong conclusion about how transparent the regime is.
Our view
The advisory is good policy communication and the fleet does not say that often. It is two pages, it answers the question it exists to answer in one sentence, it names its audience on the page (Accountable Authorities, Chief Security Officers, Chief Information Security Officers, Procurement Officers), it prints a contact address, and it is dated and versioned. Compare that with the instrument it sits beside, where the obligation is public and the list is not.
The part we would push on is the naming. Pre-clearing two named foreign companies inside whole-of-government policy is an efficient way to unblock adoption, and it also hands those two a procurement advantage that no Australian provider can obtain by being good. The stated route for everyone else is a FOCI assessment under Direction 001-2024, and nothing in the advisory says how long that takes, who pays for it, or whether an assessment done by one entity can be relied on by another. Those are the questions we would want answered before calling this settled, and we have not asked them yet.
If you are a public servant: OFFICIAL information is in scope, security classified information is not, and the training requirement in the advisory is specifically about knowing where that line is. If you are a vendor outside the three named routes, the assessment is the thing standing between you and the desk.
Sources
- PSPF Policy Advisory 001-2025, OFFICIAL Information Use with Generative Artificial Intelligence, protectivesecurity.gov.au, FINAL Version 1.0 dated 07/10/2025 (PDF downloaded and read in full 29 August 2026): the opportunities and safe-and-confident-adoption framing; the operative sentence that OFFICIAL information including information created for business operations and services can be used with generative AI technologies; footnote 1 defining use to include web-based products such as ChatGPT.com; the three requirements including the Hosting Certification Framework, OpenAI and Anthropic route and the FOCI alternative; footnote 2 on no additional FOCI assessment being required and all other providers being assessed under PSPF Direction 001-2024; footnote 4 citing PSPF Requirements 0086, 0087 and 0088; footnote 5 citing the ASD's Engaging with artificial intelligence guidance, the Information Security Manual and the Zero Trust Modern Defensible Architecture Principles; and the stated intended audience and contact address.
- Protective Security Directions under the PSPF, protectivesecurity.gov.au (read 29 August 2026): that Direction 001-2024 concerns managing foreign ownership, control or influence risks in technology, and that Direction 004-2025 requires adherence to the Commonwealth Technology Standard.
- AI Geek, The Commonwealth’s DeepSeek ban carves out open models. The list of what else is banned is not published, 29 August 2026: our own earlier reporting, from the Direction PDFs, on the Deny List and the 31 October 2025 obligation.
How we checked this. The advisory was downloaded as a PDF from the link on its own publications-library page and read in full; every quotation is from that document. We have not contacted the Department of Home Affairs, so the open questions about the FOCI process are stated as open rather than answered.
A disclosure specific to this story. This site is written substantially by AI, as set out on how this site works. The AI system doing the reading and drafting here is made by Anthropic, one of the two companies this Commonwealth policy names. Jezweb is a paying customer of that company and has no other relationship with it, is not a party to the policy, and had no involvement in it. We considered whether to leave this story to someone else and decided that declining to report a named provision of published government policy would be the greater distortion. The provision is quoted verbatim above and linked, so you can check it against the source without taking our word for any of it.
Run procurement in an entity that has done a FOCI assessment on an AI vendor, or read this advisory differently? Tell us and we will check it against the documents and log the outcome here.