From the journal

APRA and ASIC Issue Joint Industry Letters on AI Risk and Cyber Resilience, April and May 2026

The Australian Prudential Regulation Authority published an open letter to all regulated entities on 30 April 2026 setting expectations for governance of AI and AI agents. The Australian Securities and Investments Commission followed with an 8 May 2026 letter to licensees calling for urgent action on cyber resilience against AI-enabled threats. Both regulators warn that existing prudential and operational risk standards already cover AI use and that supervisory action will follow identified gaps.

3 min read

The Australian Prudential Regulation Authority (APRA) published an open letter dated 30 April 2026 to all APRA-regulated entities. The letter sets observations and supervisory expectations for managing AI-related risk, including the use of AI agents in production. The Australian Securities and Investments Commission (ASIC) followed with an open letter dated 8 May 2026 to all Australian Financial Services licensees, credit licensees, and market participants. The ASIC letter calls for urgent action to strengthen cyber resilience against AI-enabled threats. Both letters are final supervisory communications. Both regulators announced that stronger supervisory and enforcement action will follow where boards and management fail to close identified gaps.

APRA's letter ties to its prudential standards CPS 230 on Operational Risk Management, CPS 234 on Information Security, CPS 220 on Risk Management, and CPS 510 on Governance. APRA states that those standards are sufficient legal hooks to govern AI deployment and AI agent use, without new instruments. The letter names four control gaps: missing model inventories, weak third-party model assurance, inadequate accountability mapping under CPS 510, and gaps in incident response for AI-related events. ASIC's letter ties to the Corporations Act 2001 obligations under section 912A on efficient, honest, and fair conduct, section 912A(1)(d) on adequate resources, and section 912A(1)(h) on adequate risk management. ASIC names eight control priorities: critical asset identification, access reviews, prompt patching, reduced attack surfaces, incident response plans, third-party risk management, defensive AI use, and ongoing supervision.

The letters reach Australian banks, insurers, superannuation trustees, AFSL holders, ACL holders, market operators, clearing and settlement participants, and registered managed investment scheme operators. Boards must approve AI use policies and confirm accountability under the Financial Accountability Regime (FAR). Operators must maintain a model inventory, evidence of pre-deployment testing, and run-time monitoring records. Third-party AI vendor contracts require new diligence on training data, model lineage, and incident notification. Cyber incident response plans must cover prompt injection, model theft, and deepfake-enabled social engineering.

Neither letter is a legislative instrument and neither imposes new obligations beyond the existing prudential and corporations rules. APRA flagged that CPS 230 applies in full to non-significant financial institutions from 1 July 2026 and that AI controls will be tested at that point. The Financial Accountability Regime extends to APRA-regulated insurers and superannuation trustees from 15 March 2025 and to authorised deposit-taking institutions from 14 March 2024. ASIC has flagged further guidance on AI in financial advice. Civil penalty exposure under section 1317G of the Corporations Act applies to identified breaches.

Licentium advises Australian financial services and crypto firms on AI governance, CPS 230 readiness, and ASIC cyber resilience programmes through a partner network. Contact us to discuss AI inventory builds, board policy drafting, or third-party vendor due diligence. Work we undertake includes APRA prudential reviews, FAR accountability mapping, AI risk policy drafting, AFSL compliance audits, cyber incident response planning, and model risk management.

Source: Australian Prudential Regulation Authority, "APRA Letter to Industry on Artificial Intelligence (AI)," 30 April 2026, https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai

The information provided is not legal, tax, investment, or accounting advice and should not be used as such. It is for discussion purposes only. Seek guidance from your own legal counsel and advisors on any matters. The views presented are those of the author and not any other individual or organization. Some parts of the text may be automatically generated. The author of this material makes no guarantees or warranties about the accuracy or completeness of the information.

AI Regulatory

More from the journal

See all

Colorado Enacts SB 26-189 Replacing Prior AI Consumer Rules with Automated Decision-Making Technology Obligations, 2026

Colorado SB 26-189, the Automated Decision-Making Technology Act, repeals and replaces the consumer AI protections in SB 24-205, establishing new obligations for developers and deployers of covered automated decision-making technology in consequential decisions. Developer obligations take effect 1 January 2027. Violations constitute deceptive trade practices under the Colorado Consumer Protection Act, enforceable by the Attorney General.

UK Designates 18 Cryptocurrency Exchanges Under Russia Sanctions Regulations, 26 May 2026

On 26 May 2026, the UK designated 18 cryptocurrency exchanges under The Russia (Sanctions) (EU Exit) Regulations 2019, including Huobi Global S.A., operator of HTX, and three Georgian Russia-focused exchanges. OFSI confirmed HTX is subject to UK financial sanctions by reason of Huobi's ownership. The action marks the first time the UK has directly sanctioned cryptocurrency exchanges in connection with Russian sanctions evasion.

European Commission Opens Consultation on Draft Guidelines for High-Risk AI System Classification Under Article 6, June 2026

The European Commission has published draft guidelines clarifying when an AI system qualifies as high-risk under Article 6 of Regulation (EU) 2024/1689 (AI Act). A targeted consultation is open until 23 June 2026. The guidelines are not legally binding but reflect the Commission's interpretation and will guide market surveillance authorities and AI providers in applying the high-risk classification rules.

Ready to launch without the regulatory guesswork?

Book a 30-minute consultation. We'll map your AI or licensing path and tell you exactly what's required, in plain language.