Skip to the main content.

3 min read

APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.

APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.
APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.
8:57

On 30th April 2026, APRA published a letter to all regulated entities on artificial intelligence. It is not a discussion paper. It is not a consultation. It is a statement of observed failure and a formal declaration of supervisory intent.

Read it carefully. Every APRA-regulated organisation in Australia needs to.

The letter documents findings from a targeted engagement APRA conducted across a group of large banks, insurers and superannuation trustees in late 2025. What it found was not a technology problem. It was a governance problem. Four of them, to be specific.


What APRA found

Boards are not ready

APRA was direct. Many boards are still developing the technical literacy required to provide effective challenge on AI-related risks. They are pursuing AI's benefits and accepting vendor briefings at face value. They are not asking the hard questions.

APRA has now set a formal minimum expectation: boards must maintain sufficient understanding of AI to set strategic direction and provide effective challenge and oversight. That expectation is live as of 30 April 2026.

Information security has not caught up

The attack surface has changed. AI systems introduce attack pathways that conventional security controls were not designed to detect. Prompt injection. Data exfiltration through model interfaces. Multi-agent privilege escalation. Autonomous agents operating outside access management frameworks built for human users.

APRA observed that identity and access management capabilities have not yet adjusted to non-human actors such as AI agents. It found gaps in the scope and coverage of security testing for AI implementations. The tools and testing programmes that protected your environment yesterday are not sufficient for the environment you are operating in today.

Governance frameworks are not operational

APRA found that most regulated entities recognise existing prudential standards apply to AI risk. Few have operationalised governance in practice. AI systems are being deployed without inventory. Lifecycle ownership is unclear. Post-deployment monitoring is weak. Governance documentation exists at the policy level. At the operational level, there is very little.

Assurance is running behind deployment

AI models learn, adapt, and degrade over time. APRA found that most regulated entities are relying on point-in-time, sample-based assurance methods that are structurally ill-suited to probabilistic AI systems. Internal audit functions lack the specialist skills and tools to independently assess AI.


Where do you actually stand?

Australian and New Zealand regulators are now asking for evidence, not assurances.

APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.

The enforcement signal

APRA states clearly: where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, APRA will take stronger supervisory action and, where appropriate, pursue enforcement.

That is not boilerplate. APRA has a track record of following through. The sector should read this as a signal that AI governance will now be a feature of entity prudential reviews, not a footnote.


What Australian and New Zealand organisations should do now

First, test what you have. If your organisation is running AI systems in production, you need to know what the attack surface looks like. That means AI-specific adversarial testing, not conventional penetration testing. Prompt injection, jailbreak chaining, data exfiltration scenarios, and assessment of agentic workflows.

Second, build a governance framework that regulators can audit. ISO/IEC 42001:2023, the international standard for AI Management Systems, is how organisations demonstrate structured AI governance to boards, regulators, and clients. For APRA-regulated entities, ISO 42001 maps directly to CPS 234 and CPS 230 obligations.

Third, move from point-in-time to continuous. AI systems change after deployment. Assurance needs to keep pace. Continuous testing and runtime protection, combined with ongoing compliance management and board-ready reporting, is the operating model APRA is implicitly describing.

Fourth, brief your board properly. Not a vendor presentation. A structured, regulator-aware briefing on AI risk that enables your board to provide effective challenge and set AI risk appetite.


Where Insicon Cyber stands

Insicon Cyber's AI Security and Governance practice contains three connected services built for Australian and New Zealand organisations operating in regulated environments.

AI Assurance provides expert-led adversarial testing of AI systems, powered by F5 AI Red Team, with findings feeding into F5 AI Guardrails for runtime protection.

ISO 42001 implementation guides organisations through gap assessment, AI Management System development, policy and process design, and certification readiness. Mapped to APRA CPS 234, CPS 230, the Australian Privacy Act 1988, and the New Zealand Privacy Act 2020.

Managed Compliance covers Essential Eight, ISO 27001, ISO 42001, and NZISM under one programme. Continuous evidence management. Board-ready quarterly reporting. Fractional CISO attendance at board risk committees and audit committees.


The starting point

Matt Miller, Co-Founder and CEO of Insicon Cyber, put it plainly in a recent interview:

"The honest starting point for most organisations is not a framework. It is a question: do you know where AI is being used inside your business, and do you know what would happen if one of those systems was compromised or manipulated? If you cannot answer that, you are not ready to govern it. And you are definitely not ready to defend it."

APRA has now asked that question on behalf of every regulator in the country. The organisations that answer it clearly, and quickly, are the ones that will be in the strongest position when supervisory reviews begin.


Further reading

  • APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026: https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai
  • ASD: Frontier models and their impact on cyber security: https://www.cyber.gov.au/about-us/view-all-content/news/frontier-models-and-their-impact-on-cyber-security
  • Insicon Cyber AI Security and Governance: https://insiconcyber.com/ai-security-governance
  • Insicon Cyber ISO 42001: https://insiconcyber.com/iso-42001-compliance
What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...

Read More
You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...

Read More
ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company...

Read More
ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

1 min read

ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

On 8 May 2026, ASIC Commissioner Simone Constant issued an open letter to AFS licensees and market participants. It runs to four pages. It is not a...

Read More
AI-Empowered Botnets and the 77/27 API Gap: What New Research Means for ANZ Financial Services

1 min read

AI-Empowered Botnets and the 77/27 API Gap: What New Research Means for ANZ Financial Services

Financial Services Threat Intelligence A blunt 77% of financial services security leaders in APAC say they have a full picture of their API...

Read More
You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

4 min read

You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...

Read More