On 30th April 2026, APRA published a letter to all regulated entities on artificial intelligence. It is not a discussion paper. It is not a consultation. It is a statement of observed failure and a formal declaration of supervisory intent.
Read it carefully. Every APRA-regulated organisation in Australia needs to.
The letter documents findings from a targeted engagement APRA conducted across a group of large banks, insurers and superannuation trustees in late 2025. What it found was not a technology problem. It was a governance problem. Four of them, to be specific.
APRA was direct. Many boards are still developing the technical literacy required to provide effective challenge on AI-related risks. They are pursuing AI's benefits and accepting vendor briefings at face value. They are not asking the hard questions.
APRA has now set a formal minimum expectation: boards must maintain sufficient understanding of AI to set strategic direction and provide effective challenge and oversight. That expectation is live as of 30 April 2026.
The attack surface has changed. AI systems introduce attack pathways that conventional security controls were not designed to detect. Prompt injection. Data exfiltration through model interfaces. Multi-agent privilege escalation. Autonomous agents operating outside access management frameworks built for human users.
APRA observed that identity and access management capabilities have not yet adjusted to non-human actors such as AI agents. It found gaps in the scope and coverage of security testing for AI implementations. The tools and testing programmes that protected your environment yesterday are not sufficient for the environment you are operating in today.
APRA found that most regulated entities recognise existing prudential standards apply to AI risk. Few have operationalised governance in practice. AI systems are being deployed without inventory. Lifecycle ownership is unclear. Post-deployment monitoring is weak. Governance documentation exists at the policy level. At the operational level, there is very little.
AI models learn, adapt, and degrade over time. APRA found that most regulated entities are relying on point-in-time, sample-based assurance methods that are structurally ill-suited to probabilistic AI systems. Internal audit functions lack the specialist skills and tools to independently assess AI.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
APRA states clearly: where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, APRA will take stronger supervisory action and, where appropriate, pursue enforcement.
That is not boilerplate. APRA has a track record of following through. The sector should read this as a signal that AI governance will now be a feature of entity prudential reviews, not a footnote.
First, test what you have. If your organisation is running AI systems in production, you need to know what the attack surface looks like. That means AI-specific adversarial testing, not conventional penetration testing. Prompt injection, jailbreak chaining, data exfiltration scenarios, and assessment of agentic workflows.
Second, build a governance framework that regulators can audit. ISO/IEC 42001:2023, the international standard for AI Management Systems, is how organisations demonstrate structured AI governance to boards, regulators, and clients. For APRA-regulated entities, ISO 42001 maps directly to CPS 234 and CPS 230 obligations.
Third, move from point-in-time to continuous. AI systems change after deployment. Assurance needs to keep pace. Continuous testing and runtime protection, combined with ongoing compliance management and board-ready reporting, is the operating model APRA is implicitly describing.
Fourth, brief your board properly. Not a vendor presentation. A structured, regulator-aware briefing on AI risk that enables your board to provide effective challenge and set AI risk appetite.
Insicon Cyber's AI Security and Governance practice contains three connected services built for Australian and New Zealand organisations operating in regulated environments.
AI Assurance provides expert-led adversarial testing of AI systems, powered by F5 AI Red Team, with findings feeding into F5 AI Guardrails for runtime protection.
ISO 42001 implementation guides organisations through gap assessment, AI Management System development, policy and process design, and certification readiness. Mapped to APRA CPS 234, CPS 230, the Australian Privacy Act 1988, and the New Zealand Privacy Act 2020.
Managed Compliance covers Essential Eight, ISO 27001, ISO 42001, and NZISM under one programme. Continuous evidence management. Board-ready quarterly reporting. Fractional CISO attendance at board risk committees and audit committees.
Matt Miller, Co-Founder and CEO of Insicon Cyber, put it plainly in a recent interview:
"The honest starting point for most organisations is not a framework. It is a question: do you know where AI is being used inside your business, and do you know what would happen if one of those systems was compromised or manipulated? If you cannot answer that, you are not ready to govern it. And you are definitely not ready to defend it."
APRA has now asked that question on behalf of every regulator in the country. The organisations that answer it clearly, and quickly, are the ones that will be in the strongest position when supervisory reviews begin.
Further reading