ACSC Advisory — Protect Your Organisation's AI Services (2026-09-28)
ASD's Australian Cyber Security Centre (ACSC) published an advisory on 28 September 2026 on protecting access to AI services. It directs organisations to secure the accounts, credentials and connected systems behind their AI services in order to reduce the risk of unauthorised use, disruption and data exposure. The advisory sits alongside the ACSC's High-rated alert of 24 September on the risks of AI misalignment to Australian organisations, and reflects a regulatory posture that treats AI systems as an operational and identity risk rather than a purely novel one.
Overview
| Attribute | Detail |
|---|---|
| Publisher | ASD's Australian Cyber Security Centre |
| Published | 2026-09-28 |
| Type | Advisory |
| Audience | Individuals & families; organisations & critical infrastructure; government |
| Focus | Accounts, credentials and connected systems behind organisational AI services |
| Source | ACSC advisory |
Significance
The advisory's framing is consistent with the credential-theft pattern documented through 2026, in which infostealer logs carrying corporate AI service sessions are traded and resold: unauthorised AI use, quota theft and downstream data exposure are consequences of stolen credentials, not of a flaw in the model. For Australian organisations it is the practical counterpart to the misalignment alert issued four days earlier — one addresses what an agent might do, the other who can reach it. The same guidance reads across to New Zealand agencies working to the NZISM.
Related
- Acsc Publishes A National Alert On Ai Misalignment After Agents Independently Ex — the preceding ACSC AI alert
- Acsc When Ai Agents Take Unexpected Actions — earlier ACSC guidance on agent behaviour