From the journal

APRA and ASIC Issue Coordinated Frontier AI Risk Directives to Australian Finance Sector, 2026

Australia's Australian Prudential Regulation Authority and Australian Securities and Investments Commission issued coordinated public letters and conducted nine Frontier AI Roundtables in 2026, directing regulated financial services entities to strengthen AI risk management and cyber resilience programs in response to threats posed by frontier AI models.

3 min read

APRA and ASIC issued coordinated public guidance to Australian financial services entities in 2026, each addressing distinct but complementary dimensions of frontier AI risk. APRA published a letter to industry on artificial intelligence risk management and announced a targeted supervisory review across all its regulated industries examining how AI is deployed and governed. ASIC issued Media Release 26-092MR as an open letter to all AFS licensees and market participants, calling for urgent cyber resilience uplift as frontier AI intensifies the cyber threat environment. Together, the two regulators convened nine Frontier AI Roundtables to enable knowledge transfer between regulated entities, both regulators, and the Australian Signals Directorate.

APRA's letter invokes Prudential Standard CPS 220 (Risk Management), under which boards and senior management must set explicit AI risk appetite, manage AI-related financial and operational exposures, and ensure clear accountability structures. APRA's targeted review found that expanded deployment of advanced AI is introducing new financial and operational vulnerabilities, and that information security practices are not keeping pace with deployment. ASIC's open letter exercises its conduct oversight mandate under the Corporations Act 2001 (Cth) and the Australian Securities and Investments Commission Act 2001 (Cth), directing licensees to assess how frontier AI capabilities could be used by threat actors against their systems, data, and clients.

Banks, insurers, superannuation trustees, and investment managers regulated by APRA must integrate frontier AI risk into their CPS 220 risk management programs, document AI governance arrangements at board level, and report material AI-related exposures in supervisory submissions. AFS licensees and ASX market participants regulated by ASIC must conduct frontier AI threat assessments and update their cyber incident response plans. Entities that procure AI services from third-party vendors must extend their oversight obligations to those vendors' AI capabilities and update vendor contracts to reflect AI-specific risk controls.

No binding prudential standard specific to AI has been issued, leaving entities to interpret frontier AI risk obligations through existing CPS 220 and ASIC conduct standards, which may produce inconsistent compliance interpretations across the sector. APRA's 2026-27 Corporate Plan signals that quantum computing risks will become the next supervisory focus. The nine roundtables have not produced public outputs, limiting third parties' ability to benchmark their compliance positions against peer practices.

Licentium advises financial institutions on AI governance, prudential risk management, and regulatory engagement with APRA and ASIC. We may advise on the impact of the 2026 AI guidance on your risk management program or connect you with cyber resilience specialists through our partner network. Work we undertake includes AI risk appetite design, CPS 220 gap analysis against frontier AI expectations, vendor contract review for AI service providers, cyber resilience assessment, and correspondence with APRA and ASIC on AI supervisory matters.

Source: APRA, APRA calls for a step-change in AI-related risk management and governance, 2026