AI in Governance, Risk & Compliance: Regulators begin the call to action

Artificial Intelligence (AI) has rapidly evolved from experimental use cases such as document summarisation and basic automation to being embedded across critical processes within Australian financial services via agents and automation of key activities and tasks. On the cybersecurity front, frontier AI models have accelerated the risk of external threat vectors with actors now better equipped to target organisations. In April 2026, APRA issued an open letter to regulated entities following targeted engagement with banks, insurers, and superannuation trustees. The findings across entities were consistent and illustrated that AI adoption was progressing at pace while change management controls, information security and governance frameworks were struggling to keep up.

At a Board level, APRA observed strong interest in AI’s strategic and commercial potential, particularly in driving productivity, efficiency, and customer experience. However, Boards were not consistently able to demonstrate the technical literacy required to effectively challenge and oversee AI-related risks. APRA specifically noted an overreliance on vendor presentations and high-level summaries, without sufficient independent scrutiny of underlying risks of AI adoption and the specific impacts to customers and organisations.

In May 2026, ASIC reinforced this message through its own open letter to Australian Financial Services (AFS) licensees, calling for urgent uplift in cyber resilience. ASIC highlighted that frontier AI models are significantly accelerating the capability and accessibility of sophisticated cyber-attacks, allowing vulnerabilities to be identified and exploited at unprecedented speed and scale. ASIC’s message to industry was unambiguous: entities should not wait for further sophisticated AI developments before addressing their cyber resilience fundamentals and should act now with urgency, focus and accountability. Though an external lens to consider, it highlights that AI adoption is here now and the rapid pace of change and adoption represents significant risks to not only organisations but ultimately the end customers.

Both APRA and ASIC have shifted scrutiny towards Boards and senior executives, reinforcing that AI governance is not solely a technology responsibility, but a broader governance and risk management issue. This regulatory posture puts risk management back at the heart of AI adoption – CROs now need to consider what risk this change poses and how to manage it.

AI Adoption and Acceleration of Threat Vectors

This regulatory focus is underpinned by two related dynamics: the risk organisations and their service providers take on through adoption of AI and the acceleration of threat vectors that AI now enables.

One area of challenge facing organisations is that AI adoption risk is no longer confined to formally approved AI transformation programs or initiatives. Increasingly, AI capabilities are being embedded into everyday business tools, SaaS platforms and third-party solutions, often without the explicit label of “AI”. Each point of adoption can shift an organisations risk tolerances and resilience settings. The question for entities is whether this drift is being appropriately captured in governance and risk processes and factored into resilience assessments, rather than only becoming visible once something goes wrong.

At the same time, frontier AI is lowering the skill and cost required to identify and exploit vulnerabilities and is also creating new avenues for attack that traditional security controls were not designed to detect. A growing area of concern is the emergence of indirect prompt injection attacks, often referred to as “poison pill” or “thread needle” attacks where malicious instructions are hidden inside content that an AI agent later processes. An AI agent with legitimate access to enterprise systems can be manipulated through publicly accessible content that it is instructed to analyse, summarise or act upon. No traditional intrusion may occur, yet the outcome can still compromise data integrity, confidentiality or operational controls. As organisations increasingly deploy AI agents across business functions, the threat environment evolves and the scope of cyber security must expand with it. Understanding where AI agents are operating, what systems they can access and how they can be influenced by external content is rapidly becoming a core component of cyber resilience.

These impacts are compounded by service providers and third-party vendors, many of whom are embedding AI capabilities into their products and service. AI-related risks can be inherited through the supply chain with limited visibility over how these capabilities operate and are governed. Importantly AI-related risks rarely sit within a single risk category. Vulnerabilities can quickly cascade into broader risks such as privacy, conduct and operational resilience and reinforces AI as across-cutting risk theme as opposed to a standalone item on a risk register.

Integrating AI Into Existing Frameworks

Australia’s principles-based regulatory approach means that existing frameworks remain relevant and the focus for entities is on integrating AI into their existing governance structures and risk management frameworks. At the same time, organisations can also draw on global reference frameworks, such as the EU AI Act, ISO 42001, and the NIST AI Risk Management Framework to inform areas such as risk classification, monitoring, and assurance. This combined approach anchors governance in domestic regulatory requirements while leveraging international standards to fill capability and maturity gaps.

CPS230 Implications

For APRA-regulated entities and service providers across the value chain, CPS 230 (Operational Risk Management) provides a clear pathway for embedding AI governance. Although not explicitly AI-focused, it applies to all critical business processes and by extension, captures AI to the extent it is embedded into these processes.

  • Operational Risk Management: – Entities must identify and assess AI-specific risks prior to deployment, including model error, data bias, and disruption states that may not be immediately visible.
  • Critical Operations – AI systems supporting critical operations require enhanced governance, including defined disruption tolerances, recovery objectives, and tested fallback arrangements. Additionally, considerations on how AI impacts resiliency and service continuity
  • Material Service Providers – Most AI vendors will meet the materiality threshold under CPS 230, requiring formal agreements, ongoing monitoring, and clearly defined exit strategies.
  • Business Continuity – AI failure scenarios must be incorporated into business continuity plans and tested regularly.

Regulatory Expectations for Uplift

APRA’s open letter to industry clearly articulates regulator expectations and next steps for entities. ASIC’s subsequent communication reinforces and cross-references APRA’s position, signalling that these expectations apply broadly across regulated financial services organisations.

Taken together, the following represent the minimum expectations communicated by regulators:

  • Establish an AI governance framework – AI governance should be embedded into the enterprise-wide Risk Management Framework with policies, standards and accountability structures established, including clear ownership across the AI lifecycle. This includes maintaining a live inventory of AI tools and use cases with defined ownership across the full lifecycle.
  • Upgrade third-party and supplier risk management – Map the full AI supply chain including fourth-party dependencies and review AI vendor contracts to include appropriate controls such as audit rights, notification of model updates, incident reporting and exit provisions where necessary.
  • Concentration risk – SNOW and MSPs are increasingly reliant on a small pool of frontier AI models, warranting explicit third-party risk assessments in the same way concentration in cloud infrastructure providers is managed.
  • Update cyber resilience controls – Review and validate core security controls against AI-accelerated threat scenarios. This includes strengthening identity and access management for non-human actors, patching cadences, penetration testing and incident response plans. Cyber resilience controls must be demonstrably working and not just documented.
  • Implement integrated & continuous assurance – Entities should establish effective assurance mechanisms across cyber security, data governance, model performance risk, operational resilience, privacy, and conduct risks. Second line and internal audit functions must have sufficient capability and tooling to independently assess AI systems, with risk and security assessments conducted pre-deployment and on a continuous basis.
  • Ensure board-level oversight is substantive – Boards should receive clear, evidence-based reporting on AI and cyber risk, including control effectiveness, testing outcomes, and incidents, supported by defined escalation triggers. Oversight should enable informed challenge rather than high-level summaries of AI tools in use.
  • Uplift Board and Executive AI capabilities – Implement targeted training programs on AI risk, controls and regulatory expectations, ensuring Boards have sufficient AI literacy to effectively challenge and direct the business.

The Path Forward

Looking ahead, regulatory scrutiny is expected to increase. APRA has indicated further supervisory focus on AI-enhanced risk, while broader regulatory developments such as the Privacy Act reforms coming into effect December 2026 will introduce additional requirements relating to automated decision-making transparency.

Organisations that proactively embed AI within their governance, risk, and resilience frameworks will be better positioned to meet these expectations and demonstrate effective oversight in an increasingly complex risk environment.

Share :

Author:

Publish Date:

August 10, 2026

Related News

Almost five years on from the commencement of the Design and Distribution Obligations (DDO) in October 2021, the expectations around how Fund Issuers oversee their distributors have moved on considerably.
APRA has sharpened its expectations on investment governance and, over the past year, begun backing them with enforcement. The standards apply with equal force
ASIC's recent directive to superannuation trustees represents more than regulatory oversight - it signals a fundamental shift in expectations for an industry custodian of $4.3 trillion in Australian retirement savings.