Australian defence contractors adopting AI tools must ensure deployment meets the Defence Industry Security Program (DISP), ASD Essential Eight, and Information Security Manual (ISM) requirements — Mycelium 365 specialises in deploying Microsoft 365 Copilot and Azure AI within DISP-compliant Microsoft 365 environments for Australian defence contractors, primes, and subcontractors working on controlled or sensitive government projects.
What AI tools can Australian defence contractors use safely?
The set of AI tools acceptable inside a defence contractor's environment is deliberately narrow. In practice, three patterns work:
- Microsoft 365 Copilot deployed inside a Microsoft 365 tenant configured to handle OFFICIAL and OFFICIAL: Sensitive information, with sensitivity labels, DLP, and conditional access enforced tenant-wide.
- Azure OpenAI Service deployed in Azure Australia East or Australia Southeast, wrapping the firm's own indexed content and returning responses inside the same trust boundary.
- Microsoft Azure Government / sovereign cloud for workloads at higher classification levels where commercial Azure regions are not accredited.
Consumer AI tools — the free web versions of ChatGPT, Claude, Gemini, Perplexity — must not be used with Controlled Unclassified Information (CUI), project data, ITAR-affected material, or anything that could aggregate to sensitive. These tools egress prompts to third-party model providers, may retain data for training, and provide no audit trail acceptable under DISP or the ISM.
The decision tree for defence contractors is: is the data classified or sensitive? If yes, only enterprise AI inside the firm's own accredited Microsoft 365 or Azure tenant is acceptable.
DISP compliance and AI — what defence contractors need to know
DISP membership carries specific obligations under the Governance, Personnel, Physical, and Information and Cyber Security categories. AI tools intersect directly with the information and cyber security category and, indirectly, with governance.
AI introduces four new risks that DISP-registered contractors must address:
- Data egress — where does the prompt go, and where does the response come from?
- Model training — is the firm's data used to train a third-party foundation model?
- Audit trail — can the firm evidence who prompted what, when, and against which project data?
- Aggregation — can AI responses aggregate multiple pieces of OFFICIAL information into an outcome that is more sensitive than any single input?
Microsoft 365 Copilot addresses the first two by keeping data inside the tenant boundary and excluding tenant data from Microsoft foundation model training. The last two require configuration: Microsoft Purview sensitivity labels, DLP policies, Entra ID conditional access, and audit log retention aligned to DISP evidentiary requirements. See our defence contractors industry page for the full compliance operating model.
Essential Eight requirements for defence contractors using AI
DISP requires contractors to align with the ASD Essential Eight, typically at Maturity Level 2 or above depending on the projects supported. AI tools do not sit outside the Essential Eight — they map into existing controls:
- Application control — Copilot plugins, Microsoft 365 add-ins, browser extensions, and any AI-powered SaaS tool are applications and must be governed under ML2/ML3 application control.
- Patch applications — AI connectors, Copilot Studio flows, and Azure OpenAI SDKs need the same patch cadence as any other software.
- Multi-factor authentication — every Copilot licence assumes Entra ID with phishing-resistant MFA; sensitive projects should enforce FIDO2 or Windows Hello for Business.
- Restrict administrative privileges — Copilot Studio, Power Platform environments, and Azure OpenAI resources are privileged surfaces and need PIM-gated access.
- User application hardening — includes disabling consumer AI tools at the browser and endpoint level via Intune.
Our Huntress-powered SOC monitors AI tool usage for anomalous prompting patterns, off-hours access, and data exfiltration attempts across the tenant.
Microsoft 365 data residency for defence contractors
Microsoft's Australian data residency for Microsoft 365 covers customer data at rest in the Australia East and Australia Southeast regions. Microsoft 365 Copilot inherits this — prompts and responses are processed within the tenant boundary and Copilot does not use tenant data to train the underlying foundation models.
For most OFFICIAL and OFFICIAL: Sensitive work, Microsoft's Australian commercial cloud is the right foundation, provided the tenant is correctly configured (sensitivity labels, DLP, conditional access, audit retention).
For workloads at higher classification, contractors should evaluate Azure sovereign cloud offerings and the specific accreditation status of each service. Not every Microsoft service is accredited at every classification level, and the accreditation position changes — contractors should confirm current status against the ASD Cloud Assessment and Authorisation Framework and Defence's project-specific requirements before deploying.
The word "sovereign" is doing a lot of work here — for a defence contractor, it means data residency, operational sovereignty (who can access the underlying infrastructure), and legal sovereignty (which country's laws apply). Microsoft addresses each of these differently across its cloud offerings, and the right choice depends on the project.
How to build an AI governance framework for a defence contractor
An AI governance framework for a defence contractor is a written document, endorsed by the CISO or equivalent, that answers:
- Which AI tools are approved? Named tools only — Microsoft 365 Copilot, Azure OpenAI Service, specific approved plugins.
- Which data can be used with which tool? Mapped to sensitivity labels — OFFICIAL is fine in Copilot, project-specific CUI may require additional controls, anything above OFFICIAL: Sensitive is out of scope for standard Copilot.
- Which projects are AI-eligible? Some prime contracts explicitly restrict AI use; the framework must respect contract-level constraints.
- How is AI usage logged and audited? Microsoft Purview audit logs, retention aligned to DISP, and periodic review by the security function.
- Staff training — every user of an approved AI tool completes AI-in-a-security-context training before their licence is provisioned.
- Review cadence — the framework is reviewed at least every six months as the technology and threat landscape evolve.
Mycelium 365 builds and operates this framework for Australian defence contractors as part of our managed Microsoft 365 service and technology roadmap advisory.
