Greater Shepparton City Council has brought artificial intelligence tools within the scope of its new cyber security policy, requiring them to receive approval and satisfy security standards before they can be used.
The Victorian council’s policy focuses on the security implications of AI rather than setting comprehensive rules for how staff should use the technology. The council has nevertheless confirmed that internal measures are in place to support safe use, providing operational guidance beyond the formal policy’s cyber security provisions.
The approach is intended to reduce risks that can arise when employees enter information into generative AI services or use AI-enabled systems in their work. Depending on how a tool handles prompts and other submitted material, its use can raise questions about confidential information, personal data, access controls and the storage or processing of council records. Requiring approval gives the council an opportunity to assess those issues before a service is introduced.
Mayor Shane Sali described AI as a fast-changing area and acknowledged that Greater Shepparton may eventually need a standalone policy. For now, the technology is being managed as part of the council’s broader cyber security framework, supplemented by internal controls on safe use.
The distinction between security rules and usage guidelines is significant. A cyber security policy can establish requirements for assessing software, protecting data and controlling access, while a dedicated AI policy can address a wider set of governance concerns. Those can include checking the accuracy of generated material, identifying potential bias, maintaining human oversight, documenting the use of automated systems and determining when AI is unsuitable for council business.
Generative AI systems present particular governance challenges because they can produce convincing but incorrect responses. Their outputs may also reflect limitations or biases in training data. In a local government setting, those characteristics make human review important, especially where AI-assisted material could influence public communications, administrative decisions or services delivered to residents.
Greater Shepparton’s decision follows moves by other Australian local governments to establish controls for AI. In Victoria, Murrindindi Shire Council and Latrobe City Council have adopted dedicated policies dealing with the introduction of AI tools, data protection and the management of potential bias.
Local councils hold a broad range of information, including residents’ personal details and material related to planning, infrastructure, community programs and other public services. The adoption of externally operated AI products can therefore overlap with existing obligations involving privacy, information security, records management and accountability. Formal approval processes can help ensure that staff do not treat widely available consumer AI services as interchangeable with systems assessed for official use.
The council’s current model leaves open the possibility of expanding its governance arrangements as the technology and associated risks develop. Any future dedicated policy could move beyond deciding which tools meet security requirements and define more detailed expectations for acceptable use, disclosure, oversight and responsibility for AI-assisted work.
Sources: AI safety policy