ASIC - Australian Securities and Investments Commission

08/27/2026 | Press release | Distributed by Public on 08/26/2026 17:05

ASIC and APRA warn frontier AI awareness must turn to action

The Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) are urging financial market entities to move from gaining awareness of risks linked to frontier AI to taking decisive action.

Both APRA and ASIC have warned publicly in recent months that frontier AI is increasing the speed, scale and sophistication of cyber threats to the financial system while also accelerating technology and operational risks.

Building on those messages, the regulators hosted nine roundtables in June and July involving more than 600 attendees from across the financial system.

They were supported by the Australian Signals Directorate (ASD) and included participation from the Reserve Bank of Australia, Treasury and the Australian Competition and Consumer Commission, signalling a whole-of-government response to this urgent threat.

Key themes to emerge included:

  • the importance of getting the cyber fundamentals right, including identifying and managing critical assets and systems, timely patching, strong identity and access controls, attack surface reduction, backup integrity, tested response and recovery arrangements, and third-party risk management;
  • the need to consider key decisions such as risk appetite, escalation authority, recovery priorities and communication strategies at board level before a crisis hits, given that frontier AI compresses incident response timeframes;
  • a growing interest in defensive AI, including for threat intelligence, vulnerability detection, code review and incident response, however it was also acknowledged that capability remains limited;
  • common dependency and concentration risk associated with third-party service providers can turn isolated individual incidents into much broader sector-wide disruption; and
  • the importance of actively contributing to industry-led collaboration, including sector-wide threat intelligence sharing, dependency mapping, supplier assurance and sector incident coordination.

ASIC Commissioner Simone Constant said, 'The urgency of this challenge cannot be overstated. Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find.

'Now is the time to ensure you have a strong, tested plan to respond when the worst happens. Australia's financial system is only as resilient as its weakest link. Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans and understand where they are vulnerable, so they can respond effectively under pressure.'

APRA Deputy Chair Therese McCarthy Hockey said, 'This was the first time APRA and ASIC have created forums for rapid information-sharing across such a broad cross-section of the financial sector. It highlights both regulators' commitment to better regulatory practices that support and enable industry - especially in the face of complex and evolving risks.

'Something encouraging things that stood out was the willingness of more advanced entities to share practical insights, lessons and approaches with peers and less mature entities. This is precisely the type of 'Team Australia' mindset that is needed to shore up resilience across our highly interconnected financial system.'

An information paper with more insights from the roundtables, as well as a preparedness checklist for boards and executives, are available below.

Download

Background

On 30 April 2026, APRA called for a step-change in how banks, insurers and superannuation trustees manage AI-related risks (media release).

On 8 May 2026, ASIC called on all licensees and market participants to urgently strengthen their cyber resilience measures, as frontier AI intensifies the global cyber risk environment (26-092MR).

ASIC - Australian Securities and Investments Commission published this content on August 27, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 26, 2026 at 23:05 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]