DOCUMENT 7
FOI 24/25-1356 - DISCLOSURE LOG
BUDGET ESTIMATES 2024–25
TITLE: USE OF AI/ML AND ADVANCED TECHNOLOGIES WITHIN NDIA
WITNESS: Sam Porter, Chief Operating Officer, Deputy Chief Executive Officer, Enabling Services
Strategic Narrative
- The NDIA is supportive of the safe, responsible, and ethical use of Artificial Intelligence (AI) in line with the advice provided by the AI in Government Taskforce.
- AI, Machine Learning, and Generative AI will provide opportunities for the NDIA to improve the Agency’s efficiency and effectiveness.
- However, there are also important questions about how to ensure that the use of AI is safe, responsible and ethical.
- We are closely following whole-of-government developments in this space, and taking a cautious approach.
- The Australian Government is thinking about mandatory rules for AI development and deployment in high-risk settings and is taking immediate actions such as working with industry to develop a voluntary AI Safety Standard and options for voluntary labelling and watermarking of AI-generated materials. This work will be vital to the safe and responsible use of AI within the NDIA.
- The Agency has developed an interim policy position on the use of AI, especially Generative AI which is changing quickly in the market. We are working with the AI in Government Taskforce on this dynamic policy issue.
- See Attachment A for the Use of Artificial Intelligence, Generative AI, and Machine Learning – Interim Policy.
- The NDIA will develop approaches to the governance, risk management and adoption of AI at an agency level, based on the outcomes of the AI in Government Taskforce and future updates to the interim guidance.
- As part of the trial of CoPilot for Microsoft 365 (M365) coordinated by the Digital Transformation Agency (DTA), we are uplifting Agency capability to provide a better understanding of how AI may impact Agency security and support the disability sector.
FOI 24/25-1356 - DISCLOSURE LOG
- In May 2023, the Agency stopped access to Open AI products (see Background) in the Agency Information and Communications Technology Environment.
- This decision was driven by concerns about preserving the security, confidentiality and privacy of information held by the Agency.
- On 20 September 2023, the Hon Ed Husic MP, Minister for Industry and Science and Senator Katy Gallagher, Minister for Finance announced the AI in Government Taskforce.
- In January 2024, the Australian Government has released its interim response to the Safe and Responsible AI in Australia consultation, which seeks to ensure that AI is safe and responsible.
- The response focuses on the use of AI in high-risk settings, where harms could be hard to undo, while allowing low-risk AI use to keep growing.
- On 17 January 2024, interim advice from the AI in Government Taskforce was released to guide the safe and responsible use of AI. The advice indicated that mandatory guiderails for AI development and deployment of generative AI in high-risk settings may occur through specific changes to legislation to protect privacy and sharing of confidential information.
- The DTA updated its advice to Government Departments and corporate entities on the use of Generative AI to support the management of risk in November 2023.
- NDIA welcomes the AI in Government Taskforce created on 20 September 2023 and will consider outcomes from the Taskforce, and any guidance on public use of generative AI platforms.
- NDIA suspended use of Open AI products in May 2023 to prevent input of personal information into AI tools and ensure alignment with Privacy Act.
- The Agency continues to monitor the rapidly evolving AI and Generative AI technology landscape and block access to tools in the interest of protecting Agency and participant data.
FOI 24/25-1356 - DISCLOSURE LOG
Background
- Machine Learning is a subset of AI that involves the use of algorithms to learn from data and make predictions or decisions without being explicitly programmed.
- Generative AI is a type of AI that involves the use of machine learning models to generate new data that is like a training set. It differs from other forms of machine learning in that it doesn’t just make predictions or decisions based on data but can also create new data.
- OpenAI products are a collection of AI tools and models created by the research organisation OpenAI, with ChatGPT and similar language-based models being the most popular products.
- OpenAI and similar products can have an impact on the environment by generating an output (results, recommendations, or options) based on a given set of objectives. It uses a combination of machine AI, generative AI, and/or data and inputs from humans to perceive real and/or virtual environments and simplify these perceptions into models through analysis in an automated way. The output of these models can be documents or images.
- Access to Open AI products was largely restricted in May 2023 and the NDIA has continued to track the launch of new products into the market.
Improved AI monitoring in the future
- The NDIA Cyber Security operations team continues to provide regular scanning of the broader technology and AI landscape.
- In September 2023, NDIA Cyber Operations broadly blocked all Generative AI services.
- This block excludes services like Read Speaker, Adobe Sensei, and Microsoft’s Bing native AI chat function which can be used to support Agency assistive technology requirements.
- Access to Generative AI services were blocked due to the following risks:
- Quality of data outputs
- NDIS data being part of the AI training set which might include Agency protected data
- NDIA would not have control over NDIS data once it was used in external AI services
- The use of Generative AI products has led to a big rise in malware created by criminal and state-based actors who want to attack systems and services.
FOI 24/25-1356 - DISCLOSURE LOG
AI Opportunities for the NDIA
- By using Machine Learning AI, Generative AI, and process automation, the NDIA can enhance its performance and productivity in administrative tasks. This can lead to better results for participants and lower costs to improve scheme sustainability.
- The NDIA will work with the DTA, the AI in Government Taskforce, and other government entities to establish a cohesive strategy and effective governance model for the management and use of AI in NDIA to ensure:
- the accuracy of data and outcomes developed through AI
- the security of the systems and data engaging with AI
- the development of clear governance structures for the use of AI
- effective educative supports allow NDIA users and ICT staff to work within whole of government and legislative guiderails when using AI to keep critical data secure.
- Examples of sanctioned use of generative AI within the Agency ICT environment include:
- Adobe Sensei: This product allows NDIA business areas to utilise generative AI to assist in editing images quickly within Adobe products, saving critical time in the creation of marketing or educative materials.
- ReadSpeaker.com: This web based generative AI application is used to allow text to speech services within the NDIA external websites. The AI functionality allows text to mimic natural language and context driven speech patterns and is an advance on robotic text translators.
CoPilot for Microsoft 365
- In November 2023, the NDIA was invited to be one of 30 agencies to take part in a managed trial of CoPilot for M365 coordinated by DTA.
- The trial of Copilot for M365 will provide a safe and integrated AI environment that can be fully controlled by the Agency. The trial began in February 2024 with 300 initial licences and includes members of the NDIA Employee Disability Network.
- CoPilot is a decision support system, which supports Microsoft products and services. It automates basic activities such as minute taking and calculations, when directed. It does not make decisions or independently generate output.
Security of CoPilot for Microsoft 365
- CoPilot is part of the M365 tenancy, which the NDIA uses for its Operating Environment. The Operating Environment has a set of features incorporated into its design which protect Agency information and systems.
- The NDIA’s Operating Environment has been subject to a separate and rigorous cyber security assessment.
FOI 24/25-1356 - DISCLOSURE LOG
- CoPilot is a private large language model, which is separate from other Microsoft customers. Agency information is not available to the public and is not used to train CoPilot.
- The Agency has performed a separate risk assessment on CoPilot and reviewed DTA’s IRAP Assessment.
- CoPilot uses existing access levels and configurations across the Microsoft suite. It leverages the Agency’s existing controls to prevent unauthorised access to information.
- CoPilot users go through training on how CoPilot works and their responsibilities in using it at work. This includes their responsibility for the use of all CoPilot output.
Scheme Actuary algorithms
- The Agency’s Scheme Actuary and Data Analytics area does not use Generative AI within any of the algorithms that currently support the scheme.
NDIA Policy Update
- In April 2024, the CIO approved the NDIA’s Use of Artificial Intelligence, Generative AI, and Machine Learning – Interim Policy. The policy was considered by ICT, cyber security and legal experts in the NDIA. See Attachment A for the policy.
- The NDIA shared the policy with the DTA as part of our participation in the trial of Copilot for M365. Feedback and comments from the DTA and the AI in Government Taskforce will be considered as the NDIA actively monitors the AI environment.
Attachments
- Attachment A - Use of AI Gen AI and ML Interim Policy
FOI 24/25-1356 - DISCLOSURE LOG
DOCUMENT 7.1
OFFICIAL
Use of Artificial Intelligence, Generative AI, and Machine Learning — Interim Policy
Version 1.0 — April 2024
OCIO
ndis.gov.au
ndis
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 1
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Policy Summary
The National Disability Insurance Agency (NDIA or the ‘Agency’) requires all staff (including contractors and partner staff) to implement and adhere to the Agency Policies and Procedures. This document establishes the policy for Use of Artificial Intelligence, Generative AI, and Machine Learning in the Agency.
Document Control
| Document Name | Use of Artificial Intelligence, Generative AI, and Machine Learning — Interim Policy |
|---|---|
| HPE Document No or SharePoint Link | Use of AI Interim Policy Draft 0.1.docx |
| Date | April 2024 |
| Status | Final |
| Version | 1.0 |
| Owner | Branch Manager, Enterprise Architecture and Governance Branch |
Approval Status Log
| Version | 1.0 |
|---|---|
| Reviewed by | BM Enterprise Architecture and Governance |
| Publication date | April 2024 |
| Approved by | Ajay Satyan, Chief Information Officer |
| Approval date | April 2024 |
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 2
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Table of Contents
- Use of Artificial Intelligence, Generative AI, and Machine Learning — Interim Policy……………. 1
- Policy Summary …………………………………………………………………………………………………………….. 2
-
- Introduction ………………………………………………………………………………………………………………. 4
-
- Purpose ……………………………………………………………………………………………………………………. 4
-
- Applicability ……………………………………………………………………………………………………………….. 4
- 3.1. Policy exclusions ………………………………………………………………………………………………….. 4
- 3.2. Policy exemptions ………………………………………………………………………………………………… 5
-
- Policy Principles …………………………………………………………………………………………………………… 5
-
- Roles and responsibilities ……………………………………………………………………………………………… 6
- 5.1. Chief Information Officer (CIO) ……………………………………………………………………………….. 6
- 5.2. AI Working Group ……………………………………………………………………………………………….. 6
- 5.3. Project Team ……………………………………………………………………………………………………….. 6
- 5.4. Copilot trial members ……………………………………………………………………………………………. 7
-
- Non-compliance …………………………………………………………………………………………………………… 7
-
- Authority and review …………………………………………………………………………………………………….. 7
- Appendix A — Glossary of terms and abbreviations …………………………………………………………….. 8
- Appendix B — References, legislation, and standards ………………………………………………………….. 9
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 3
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
1. Introduction
The National Disability Insurance Agency (Agency) is participating in a trial of Copilot for Microsoft 365 (the trial) along with other Federal Government Agencies. The trial is sponsored by the Prime Minister and is supported by the Digital Transformation Agency (DTA). The use of Copilot as part of a trial aligns with interim Government guidance on the use of generative AI tools.
Copilot by Microsoft brings the power of generative AI to professional settings while offering protection from unauthorised data sharing and unregulated internet access.
The aim of the trial is to help to shape the future use of Artificial Intelligence (AI) by Government staff. Copilot is built on top of advanced AI tools to provide intelligent assistance to users to potentially enhance productivity and collaboration.
Copilot is not a mechanism for making independent decisions.
During the trial, emphasis will be placed on protecting Agency data and personal privacy.
Finally, the trial will explore the benefits and any potential impacts of integrating Copilot within the Agency and the wider APS.
2. Purpose
This policy outlines expectations in the use of AI functionality provided by Copilot within the trial.
The policy establishes a framework for the ethical, legal, secure, and effective use of Artificial Intelligence (AI), Generative AI, and Machine Learning (ML) within the Agency. The policy ensures the safety and security of our staff, critical data, and the National Disability Insurance Scheme (the Scheme) information.
The policy aims to harness the benefits of generative AI services to enhance business outcomes and administrative efficiencies for Agency staff.
This policy is written within the context of the Agency ICT Policy Framework.
3. Applicability
This policy applies to all Agency staff, including labour hire workers, participating in the DTA trial of Copilot and the use of AI-products and related activities within the agency during the Microsoft Copilot trial period.
3.1. Policy exclusions
There are NO exclusions to this policy.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 4
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
3.2. Policy exemptions
Unless specified in this policy, there are NO exemptions, unless approved by the CIO and recommended by the Agency AI Working Group.
4. Policy Principles
AI tools offer transformative possibilities for public sector services, particularly in enhancing the efficiency and effectiveness of administrative and operational functions. To ensure confidence in the Agency’s processes and alignment with the operational and strategic goals, users of Copilot must ensure that the following policy principles are met:
- Accountability: Users must be able to explain, justify and take ownership of any advice or decisions made when using AI. Users are responsible for the outcomes of AI generated artefacts. Exercising due diligence when using AI tools is required to ensure the highest standards of quality and ethical responsibilities are met.
- Transparency: Decisions made by Agency staff utilising AI within Microsoft productivity software must be understandable and explainable and provide a clear auditable trail of how the decision was made. AI must not be used for automated independent decision making which may impact participants or the strategic direction of the Agency.
- Accessibility and Inclusion: Any AI tool used by the Agency must adhere to and actively support accessibility standards such as the Web Content Accessibility Guidelines (WCAG).
- Privacy: All Agency staff have a responsibility to protect classified, personal, or otherwise sensitive information held by the Agency. Acceptable use of AI tools compliments existing use of data and information expectations and must protect the privacy of Participants, Partners, and other stakeholders. The use of AI must adhere to the requirements of the Privacy Act 1998 (Cth). The recommendations in the privacy assurance advice in respect of Copilot must be implemented.
- Use of Scheme data: Any recording, use or disclosure of protected Agency information by the AI tools must comply with the secrecy provisions in the National Disability Insurance Scheme Act 2013 (Cth) (NDIS Act). Unless otherwise expressly [authorised by the CIO and] authorised under the NDIS Act, AI tools must not access participant records in PACE, store protected Agency information outside of Australia, disclose protected Agency information to any third parties, or use any protected Agency information for any purposes other than provision of services to the NDIA.
- Compliance: Use of AI tools must comply with existing Agency and ICT specific policies including but not limited to the Acceptable Use Policy, the Digital Collaboration policy, and ICT Security Policy. The use of AI tools must also take into consideration and comply with the APS Code of Conduct and other relevant legislation.
- Training: All users of AI tools must have familiarised themselves with Agency supplied information and training on the responsibilities and ethical use of AI tools within the Agency.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 5
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
- Governance: The establishment of a dedicated AI Governance function via the Agency AI Working Group will oversee this trial. The governance body will include representatives with expertise in accessibility, technology, ethics, and legal compliance.
- Human Intervention and Review Processes: Procedural guidelines will ensure that human oversight and input is integral to any continued use of AI tools after the trial.
This policy, supported by procedural documents and information, reflects our commitment to ethical AI usage across the Australian Government.
5. Roles and responsibilities
5.1. Chief Information Officer (CIO)
The CIO is responsible for ensuring that, as far as reasonably possible, effective controls are in place during the trial period to ensure that Copilot is being used as per the requirements of this policy. The CIO is responsible for resourcing the Copilot trial.
5.2. AI Working Group
The AI Working Group are the responsible governance body for the trial. They are responsible for monitoring the use of AI, ensuring that users have access to training and resources that provides clear guidance on the use of AI during the trial. The body will review the outcomes of the Microsoft Copilot trial when it concludes on the 30^th^ of June 2024. The body is also responsible for informing the DTA and other agencies of any insights that will assist the government in implementing and guiding the use of AI tools throughout the APS.
The feedback collated from the AI Working Group will be incorporated when developing the permanent Use of AI Policy, should the Copilot trial be embedded further into the agency.
The AI Working Group is not responsible for individual quality control of artefacts produced as part of the trial.
5.3. Project Team
The project team for the trial are responsible for monitoring the use of Copilot and ensuring that, throughout the trial users are informed of their responsibilities and the need to comply with this policy. The project team are accountable for undertaking a review of the trial and providing feedback to DTA. The project team are responsible for working with the Information Law and Privacy team in Legal Services Group to facilitate the privacy assurance advice for the Copilot trial.
The project team will be responsible for reporting the outcomes of the trial to the Agency Senior Leadership Team (SLT) and the Board in the form of a decision paper on the future use of AI within the Agency in alignment with the approach of the Australian Government. The project team will engage with DTA during the trial period, to socialise and review the policy, to ensure consistency with DTA’s expectations of the Copilot trial.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 6
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
5.4. Copilot trial members
The members of the Copilot trial are responsible for ensuring that they understand and comply with the requirements of this policy and that they provide unbiased and factual feedback in a timely manner regarding their experience using Copilot.
6. Non-compliance
Any intentional, repeated, or negligent breach of this policy or any other ICT policy by Agency personnel may be considered a breach of the APS Code of Conduct which could give rise to a range of possible sanctions including termination.
Breaches will be managed in line with Agency Human Resource policies.
7. Authority and review
This policy was approved by the CIO on April 2024 and will be reviewed at the completion of the trial pending recommendations from DTA.
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 7
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Appendix A — Glossary of terms and abbreviations
The Glossary contains definitions for all key terms used in this document and contain specific meaning in the context of this policy.
| Term or Abbreviation | Definition |
|---|---|
| Artificial Intelligence (AI) | Systems performing tasks requiring human intelligence. For the Agency, this could include AI-assisted communication tools for clients with speech or hearing impairments. |
| Machine Learning (ML) | A subset of AI where systems learn from data and improve results over a period. In the Agency context, this could involve using ML to analyse data indicating software use to inform decisions around the purchase of additional licences. |
| Generative AI | AI tools that generate new content based on data. For the Agency, this can include summarising documents, providing meeting notes from a recorded transcript, or creating a PowerPoint presentation from a reading. |
| Copilot for Microsoft 365 Trial | A government initiative using AI in public sector operations. The Agency may leverage this for automated reporting and administration tasks, reducing the workload on staff and enhancing service delivery. |
| Copilot for Microsoft 365 | Copilot is an AI-powered productivity tool that coordinates large language models (LLMs), available and appropriate Agency data, and the Microsoft 365 apps such as Word, Excel, PowerPoint, Outlook, and Teams. This integration provides real-time quasi-intelligent assistance, enabling users to enhance their creativity, productivity, and skills. |
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 8
FOI 24/25-1356 - DISCLOSURE LOG
OFFICIAL
Appendix B — References, legislation, and standards
Legal Frameworks and Acts
The Privacy Act
Disability Discrimination Act 1992
National Disability Insurance Scheme Act 2013
National Disability Insurance Scheme (Protection and Disclosure of Information) Rules 2013
Ethical Guidelines and Standards
Australia’s Artificial Intelligence Ethics Framework
European Unions Ethics guidelines for Trustworthy AI
Australian Government AI Resources
Digital Transformation Agency’s AI resources and guidelines
Australia’s Tech Future policy document
Engaging with Artificial Intelligence
International AI Guidelines
OECD Principles on AI
IEEE Standards on AI and Autonomous Systems
Best Practice Guidelines for AI in Public Sector
World Economic Forum’s Guidelines on AI Governance
United Nations Guidelines on AI and Public Service Delivery
Use of Artificial Intelligence, Generative AI, and Machine Learning Interim Policy 9