APRA and ASIC warn frontier AI awareness must turn to action

The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) are urging financial market entities to move from gaining awareness of risks linked to frontier AI to taking decisive action.

Both APRA and ASIC have warned publicly in recent months that frontier AI is increasing the speed, scale and sophistication of cyber threats to the financial system while also accelerating technology and operational risks.

Building on those messages, the regulators hosted nine roundtables in June and July involving more than 600 attendees from across the financial system.

The roundtables were aimed at supporting industry to navigate a dynamic and rapidly evolving risk environment.

They were supported by the Australian Signals Directorate and included participation from the Reserve Bank of Australia, Treasury and the Australian Competition and Consumer Commission, signalling a whole-of-government response to this urgent threat.

Key themes to emerge included:

  • the importance of getting the cyber fundamentals right, including identifying and managing critical assets and systems, timely patching, strong identity and access controls, attack surface reduction, backup integrity, tested response and recovery arrangements, and third-party risk management;
  • the need to consider key decisions such as risk appetite, escalation authority, recovery priorities and communication strategies at board level before a crisis hits, given that frontier AI compresses incident response timeframes;
  • a growing interest in defensive AI, including for threat intelligence, vulnerability detection, code review and incident response, however it was also acknowledged that capability remains limited;
  • common dependency and concentration risk associated with third-party service providers can turn isolated individual incidents into much broader sector-wide disruption; and
  • the importance of actively contributing to industry-led collaboration, including sector-wide threat intelligence sharing, dependency mapping, supplier assurance and sector incident coordination.

ASIC Commissioner Simone Constant said: “The urgency of this challenge cannot be overstated. Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find.

“Now is the time to ensure you have a strong, tested plan to respond when the worst happens. Australia’s financial system is only as resilient as its weakest link. Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans and understand where they are vulnerable, so they can respond effectively under pressure.”

APRA Deputy Chair Therese McCarthy Hockey said: “This was the first time APRA and ASIC have created forums for rapid information-sharing across such a broad cross-section of the financial sector. It highlights both regulators’ commitment to better regulatory practices that support and enable industry – especially in the face of complex and evolving risks.

“A particularly encouraging theme that stood out was the willingness of more advanced entities to share practical insights, lessons and approaches with peers and less mature entities. This is precisely the type of ‘Team Australia’ mindset that is needed to shore up resilience across our highly interconnected financial system.”

An information paper with more insights from the roundtables, as well as a preparedness checklist for boards and executives, are available at: Insights from the APRA-ASIC Industry Roundtables

Background

On 30 April 2026, APRA called for a step-change in how banks, insurers and superannuation trustees manage AI-related risks.

On 8 May 2026, ASIC called on all licensees and market participants to urgently strengthen their cyber resilience measures, as frontier AI intensifies the global cyber risk environment.

/Public Release. View in full here.