No. The Essential Eight is a set of eight cyber security controls published by the Australian Signals Directorate, designed to protect internet-connected IT networks, and last updated in November 2023. None of the eight address anything specific to AI. That is not a criticism of it, because ASD is explicit about what it was scoped for, and it has published separate guidance for AI. If a buyer's security questionnaire asks whether you meet the Essential Eight and then asks how you secure your AI, those are two different answers and you need both.
This comes up constantly once an Australian business starts selling to government, financial services or a larger enterprise. The Essential Eight is the framework everyone here knows, so it gets reached for, and it does not reach.
Before the AI part, it is worth being clear about what the thing actually is, because plenty of people are asked to comply with it without ever having been told.
What the Essential Eight actually is
ASD is Australia's signals intelligence and cyber security agency. Among other things it runs the Australian Cyber Security Centre, responds to incidents at Australian organisations, and publishes advice based on what it sees.
One of those publications is a long list called Strategies to Mitigate Cyber Security Incidents. The Essential Eight is the top of that list: the eight strategies ASD assesses as most effective. In its own words on Essential Eight explained, the maturity model supporting it "is based on ASD's experience in producing cyber threat intelligence, responding to cyber security incidents, conducting penetration testing and assisting organisations".
That is the useful thing about it. It is not a committee's theory of good security. It is a short, ordered list of what actually stops the attacks ASD keeps being called out to clean up. Which is also why it is short: the point was to give organisations something achievable instead of a thousand-control standard nobody finishes.
The eight are:
1. Patch applications. Keep software current, because known holes are what get used.
2. Patch operating systems. The same, for the machine underneath.
3. Multi-factor authentication. A stolen password alone should not be enough.
4. Restrict administrative privileges. Fewer people with the keys, and not for everyday work.
5. Application control. Only approved software runs.
6. Restrict Microsoft Office macros. A very old and still very effective delivery route.
7. User application hardening. Turn off risky features in browsers and document readers.
8. Regular backups. So ransomware is a bad week and not the end.
Read that list and you can see the shape of the threat it was built for: someone gets malware onto a Windows desktop, escalates privileges, moves across the network, and encrypts or steals what they find.
Who actually has to do it
Three groups, and the difference matters.
Non-corporate Commonwealth entities must. PSPF Policy 10 was amended to mandate it, and requires those entities "to implement Essential Eight Maturity Level Two mitigations to achieve a PSPF maturity rating of 'Managing'". Four of the strategies became a core requirement from 1 July 2022. If you are a federal department or agency, this is not advice.
Suppliers to those entities usually must, by contract. This is where most private businesses meet it. The obligation arrives in a procurement document or a security questionnaire. No statute puts it there. Same for many state government, financial services and large enterprise contracts, which have adopted it as the local shorthand for "are you taking this seriously".
Everyone else should, because it is genuinely good. No statute compels a private Australian business to implement the Essential Eight. It remains the best-value list of eight things to do, for the same reason it was mandated: it is derived from real incidents.
So it is useful to two audiences at once. To a security team, it is a prioritised plan. To a sales team, it is the answer to a question buyers keep asking.
Maturity levels, and the bit that catches people
The maturity model defines four levels, Zero through Three. They are not a score out of three for effort. ASD describes them as mitigating "increasing levels of tradecraft and targeting", and advises organisations to consider what level of tradecraft they are trying to stop, instead of which attackers they imagine facing.
Two things people get wrong:
Your weakest strategy sets your level. Maturity Level Two means Level Two across all eight, not on average. Seven at Level Two and one at Level Zero is Maturity Level Zero. This is the single most common misunderstanding, and it is why self-reported levels are usually optimistic.
There is no certification. ASD says plainly that there is "no requirement for organisations to have their Essential Eight implementation certified by an independent party", though an independent assessment may be required by a government directive, a regulator, or a contract. Nobody issues you an Essential Eight certificate, so if a supplier claims one, ask what they actually mean.
ASD is also clear it is a floor and not a ceiling: it "will not mitigate all cyber threats", and points to the broader strategies list and the Information Security Manual for the rest.
Why it does not cover AI, and why that is fine
Look back at the eight. Three are about keeping software current, one is about macros in Office documents, one is about browsers and PDF readers. The closest thing to a control touching an AI agent is restricting administrative privileges, and that was written about human administrators on endpoints.
The date settles it. November 2023 is before the current generation of agentic systems existed in any deployable form.
ASD is also explicit that the framework has a scope. The Essential Eight "has been designed to protect organisations' internet-connected information technology networks", and while the principles may apply elsewhere, "it was not designed for such purposes and alternative mitigation strategies may be more appropriate". That is ASD telling you not to stretch it over things it was not built for. An AI agent with its own credentials, taking actions across systems, is one of those things.
Where Australian AI guidance actually lives
ASD did not leave the gap open. It put AI somewhere else.
Engaging with Artificial Intelligence, published 24 January 2024, is the general one. Be careful here, because that page still looks canonical and has been overtaken for anything involving agents.
Careful adoption of agentic AI services, published 1 May 2026 with CISA, the NSA and the UK, Canadian and New Zealand cyber centres, is the current word. It covers privilege and scope creep, agent impersonation, indirect prompt injection through email, tool use, rogue agents in multi-agent systems, and accountability. It asks for least privilege, human control points, versioning and rollback, and containment that limits the blast radius of unexpected behaviour.
That document, and not the Essential Eight, is what an Australian business should answer against when the question is about AI.
The Essential Eight is being evolved, and here is what ASD actually said
On 15 June 2026 ASD opened a consultation on the evolution of the Essential Eight. In its own words:
> "The proposed evolution introduces a new Essentials series, expanding the current framework to give organisations greater flexibility in how they implement cyber security, while still providing a clear path to achieving strong cyber resilience."
Grounded in the Information Security Manual. The evolution of the current guidance becomes the first chapter, Essentials for enterprise IT, "with additional chapters to follow". Consultation ran until 12 July 2026, so it has closed.
Worth being precise, because the secondary coverage ran further than the source. ASD's own page says evolution, consultation and additional chapters. It does not set a retirement date and it does not name AI as one of the chapters. Trade press at the time, including iTnews on 15 June 2026, described an intention to deprecate within about twelve months and retire within about two years. Treat the framework shape as confirmed and the timeline as reported.
Nothing there changes what you do this quarter. The Essential Eight is current, it is what your buyers will keep asking about, and it still does not cover AI.
What to tell a buyer who asks
Give two answers, and say plainly that they are two. It reads as competence.
On the Essential Eight, give your maturity level across all eight, honestly, including where you are not there yet, and remember the weakest one sets the number. Maturity Level Two is the common expectation for a mid-sized business handling sensitive customer data, because it is what the Commonwealth mandated for itself.
On AI, answer against the agentic guidance instead: what privileges each agent holds, which steps have human approval, what you log, how you would reverse an action, and what happens when the agent reads something malicious. That is a better answer than a framework name, and it is what a technical buyer is testing for.
We wrote about the broader version of this in the AI security questionnaire your buyer's CTO is about to send.
Which other frameworks apply
For most Australian mid-market businesses, more than one, and they stack together:
- The Privacy Act and the APPs if you hold personal information, plus the automated decision-making disclosure commencing 10 December 2026.
- The agentic AI guidance above for anything that acts rather than just generates.
- The National AI Centre's Guidance for AI Adoption and its six essential practices, published 21 October 2025, which superseded the Voluntary AI Safety Standard in October 2025. The older standard is still published, so check the date before quoting it at anyone.
- APRA CPS 234 and CPS 230 if you are a regulated entity or a material service provider to one.
We mapped this out in which Australian AI framework applies to you.
What we do on client builds
When a client is answering a security questionnaire that mixes the two, we split it before anything else. Essential Eight questions get Essential Eight answers, with a real maturity level and no rounding up to the next one.
AI questions get answered against the agentic guidance, control by control. Then we make those answers true, which is usually where the work is: narrowing the permissions an agent actually holds, adding approval on anything irreversible, and making sure there is a log of what the agent read as well as what it did.
In short
The Essential Eight is ASD's list of the eight controls that stop the most real-world attacks on internet-connected IT networks. It is mandatory for non-corporate Commonwealth entities at Maturity Level Two, arrives by contract for their suppliers, and is worth doing regardless.
It does not cover AI, was last updated in November 2023, and ASD says plainly it was scoped for something else. Australia's AI guidance sits in a separate document updated 1 May 2026, and that is the one to answer against.
Frequently asked questions
What is the Essential Eight? Eight cyber security mitigation strategies published by the Australian Signals Directorate, drawn from the top of its Strategies to Mitigate Cyber Security Incidents list. They are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.
Who has to comply with the Essential Eight? Non-corporate Commonwealth entities must reach Maturity Level Two under PSPF Policy 10. Their suppliers, and many state government, financial services and enterprise buyers, impose it by contract. No statute requires a private Australian business to implement it otherwise.
What are the Essential Eight maturity levels? Four levels, Maturity Level Zero through Three, based on mitigating increasing levels of attacker tradecraft and targeting. Your level is set by your weakest strategy, so Level Two means Level Two across all eight.
Does the Essential Eight apply to AI systems? Not specifically. None of the eight address AI risks such as prompt injection, agent privilege or autonomous action, and ASD states the framework was designed for internet-connected IT networks. Its Careful adoption of agentic AI services guidance, published 1 May 2026, covers AI instead.
Sources
- Essential Eight explained, ASD, last updated 27 November 2023, for the eight strategies, their origin and the stated scope.
- Essential Eight maturity model, ASD, for the four maturity levels, the tradecraft basis and the absence of certification.
- PSPF Policy 10 amendment, for the Maturity Level Two mandate on non-corporate Commonwealth entities and the 1 July 2022 core requirement.
- Consultation on evolution of Essential Eight, ASD, 15 June 2026, for the Essentials series and consultation window.
- Careful adoption of agentic AI services, ASD's ACSC, 1 May 2026, for the current AI security guidance.
Answering a security questionnaire that mixes the two, and want the AI half to be true before you send it? Talk to us.