I’ve actually just realized that you don’t need a filter! You were using the term filter, but you actually wanted to split the string and check to ensure that the value (iam.disableServiceAccountKeyCreation) exists.
Anyway, for reference google_org_policy is a filter because the value assignment starts with the keyword filter. More information here: Sentinel Language - Collection Operations | Sentinel by HashiCorp