Insights

APRA and ASIC: frontier AI risk has moved from awareness to action

APRA and ASIC issued a joint statement this week on frontier AI risk, and the language was blunt. Frontier AI is “increasing the speed, scale and sophistication of cyber threats to the financial system”, and boards need to move “from gaining awareness of risks linked to frontier AI to taking decisive action.”

ASIC Commissioner Simone Constant put the urgency plainly: “Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find.” That is the shift worth sitting with. The defenders’ timelines have not changed. The attackers’ have.

What the regulators are actually asking for

The statement draws on roundtables APRA and ASIC ran in June and July, and lands on five themes.

Cyber fundamentals, done properly: knowing your critical assets, patching on time, identity controls, a smaller attack surface, backups that actually restore, and third-party risk managed rather than assumed. Board-level decisions made before a crisis, not during one: risk appetite, who has authority to escalate, recovery priorities, how you communicate when it happens. Defensive AI, deployed for threat intelligence, vulnerability detection and incident response, not just left to the attackers. Third-party dependency management, with concentration risk across providers actually mapped. And industry collaboration: sharing threat intelligence and dependency maps across the sector rather than each firm learning the same lesson alone.

APRA has also released an information paper and a board preparedness checklist alongside the statement, worth reading directly rather than through anyone’s summary.

No new standard, but no new excuse either

This statement does not create a new prudential standard or a new deadline. What it does is confirm that existing obligations, the operational resilience requirements we covered in our piece on CPS 230, now have to be read with frontier AI specifically in view. A critical operation that depends on a vendor nobody has stress-tested against an AI-accelerated attack was already a gap. It is just a harder gap to argue you didn’t see coming.

For boards, the practical question this statement puts on the table is whether risk appetite and escalation authority for an AI-accelerated incident are decided now, calmly, or discovered live, during one. That is squarely a governance question, and it is why we treat AI governance as a board and management discipline, not a bolt-on to the AI team. Attack surface, identity, third-party concentration and backup integrity are exactly what that discipline is built around.

Let's talk about what you're trying to change.

A 30 minute call. No deck, no discovery workshop. Just the problem and whether we can help.

Book a call