Blog | Insicon Cyber

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

Written by Insicon Cyber | 5/8/26, 5:01 am

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company Directors with it.

The earlier ASD material, published on 9 April 2026 and updated on 30 April, spoke to accountable authorities, chief security officers and technical teams. Useful, but not the room where cyber risk is accepted or declined. The new publication, Frontier AI cyber threat considerations for boards of directors, is written for directors and senior leaders, and it is co-authored with the AICD. That co-authorship is the signal. This is not a technical advisory a director can delegate. It is a governance document, and it lands sixteen threshold questions squarely on the board table.

Most directors across Australia and New Zealand cannot yet answer them with evidence. That is the point of the exercise.

 

What ASD is telling the board

The regulator's framing is precise and it is worth reading slowly. Frontier AI models can identify vulnerabilities and rapidly weaponise them, chain together multiple low-severity vulnerabilities into high-impact compromises, and perform malicious cyber activities with little to no human oversight. The last of those three is the one that should hold a director's attention. Agentic activity, at machine speed, with no human in the loop.

ASD is blunt about what this does to a board's existing assumptions. These developments may rapidly invalidate an organisation's current risk tolerance. The risk appetite the board signed off last year was calibrated for a slower, human-led threat. It may no longer hold. ASD warns that vulnerability discovery and exploitation timelines are collapsing from days to hours, while the skill and knowledge barrier for malicious actors drops at the same time. Attackers who previously lacked the capability now have it.

There is a second dimension the earlier advisory underplayed and this one puts front and centre. Cyber supply chain risk, and specifically foreign ownership, control or influence over the AI vendors an organisation depends on. ASD asks boards whether they are relying on vendors and service providers without sufficient governance, including an understanding of who ultimately owns and controls them. For organisations across both countries that have adopted AI tooling quickly over the past two years, this is an uncomfortable question, because most cannot answer it.

 

The sixteen questions, and why they are hard

ASD groups its threshold questions around exposure, supply chain, fundamentals, and resilience. A director does not need all sixteen memorised. They need to notice the ones management will struggle to answer honestly.

On exposure,

ASD asks what assumptions underpin the current risk assessment, and how frontier AI might invalidate them. It asks which parts of the business would be most exposed if a frontier AI model were used to identify and exploit weaknesses across the organisation. These are not questions a maturity score answers. They require the organisation to reason about itself as an attacker would.

On the supply chain

ASD asks whether the board has visibility of the security posture of third and fourth-party suppliers. Fourth-party. Not just the vendor, but the vendor's vendor. Few organisations in Australia or New Zealand can produce that map today.

On fundamentals

ASD asks whether the organisation adheres to a recognised cyber security framework, what legacy technology risk it carries, and whether it is delaying remediation because a weakness looks low-severity in isolation. That last one is the trap. Frontier AI is precisely the tool that chains low-severity weaknesses into a major incident. A risk register that has parked a set of minor issues as tolerable was reasoning under the old model.

On resilience

ASD asks the sharpest question of the set. If attacks moved from taking days to hours, could we still detect and respond to them effectively? And have incident response and business continuity plans been updated and tested to capture frontier AI threats? Most plans across both markets have not been. They were written for a tempo that no longer exists.

 

Four horizons, not one project

ASD does not leave the board with questions alone. It sets out what management should be doing, sequenced across four horizons, and the sequencing itself is a governance instruction.

The immediate priorities are securing attack surfaces and reducing software vulnerabilities. Configuration baselines that are enforced and monitored for drift. Vulnerabilities identified, prioritised and remediated within risk-based timeframes, with the remediation verified rather than assumed. This is patch discipline, and ASD wants it now, not scheduled.

The short-term priorities are legacy systems, identity and access, least privilege, and incident preparedness. Note that ASD explicitly extends least privilege to AI agents. Personnel and services, including AI agents, granted only the minimum access required. An agent with standing broad access is now a named board-level concern.

The medium-term priority is adopting AI for cyber defence, on the condition that it is secure, controllable, human-supervised, and used ethically and accountably.

The longer-term priority is modernising to Secure by Design and Secure by Default. A board that hears management propose a single AI security project has misread the document. This is a staged programme with a defined order.

 

This is a Five Eyes expectation, not an Australian one

Directors of trans-Tasman organisations should not treat this as an Australia-only development.

ASD monitors frontier AI in close consultation with its Five Eyes partners, and New Zealand's National Cyber Security Centre sits inside that same relationship. The threat model does not stop at the Tasman, and the regulatory expectation is converging across both markets. The same operational logic has already appeared in the United Kingdom, where the Bank of England, Financial Conduct Authority and HM Treasury issued a joint statement in May 2026 pressing regulated firms on frontier AI risk, vulnerability management at speed, third-party exposure, and response and recovery.

A board that has answered ASD's sixteen questions in Sydney or Auckland has answered them for every market it operates in.

 

What the board should commission this quarter

The publication gives directors the questions. It does not produce the artefacts that turn a boardroom conversation into governable practice. Those have to be commissioned from management, with named owners and dates.

A director in Australia or New Zealand should be asking for four things before the next risk committee meeting.

  1. A patch velocity figure for internet-facing systems, with a target and a plan to close the gap to it.

  2. An inventory of where AI is in use across the organisation and its critical suppliers, extended to fourth-party dependencies.

  3. A control evidence review that shows which controls have been tested, not merely documented, and

  4. A business continuity and incident response plan that has been re-exercised against a scenario where an attack unfolds in hours rather than days.

None of this requires rebuilding the security programme. It requires the organisation to act, document and recover at a pace that matches the environment it now faces.

 

Where Insicon Cyber fits

Insicon Cyber works with boards across Australia and New Zealand at exactly this seam, between the assurance a board receives and the evidence a regulator now expects.

Matt Miller, Co-Founder and CEO, and Greg Bunt, Co-Founder and Director, both work with customers each week as trusted Fractional CISOs. They can take ASD's sixteen questions into the boardroom and turn them into artefacts a director can stand behind.

Control evidence reviews.

AI-adjusted threat models that show where frontier AI changes attacker speed and scale for the specific business.

Patch velocity baselining.

Supply chain mapping to fourth-party.

The AI Security and Governance practice pairs that governance work with the technical assurance to test AI systems, the ISO 42001 pathway to certify them, and the aSOC to maintain compliance around the clock, from an Australian sovereign base with trans-Tasman reach.

ASD has written the board sixteen questions. The directors who do well out of this will be the ones who can answer with documents in the room.

 

To discuss how your board evidences cyber resilience against frontier AI threats, contact Insicon Cyber at info@insiconcyber.com or visit https://insiconcyber.com/

Sources

  • Australian Signals Directorate and Australian Institute of Company Directors, Frontier AI cyber threat considerations for boards of directors: https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-business-leaders/frontier-ai-cyber-threat-considerations-for-boards-of-directors
  • Australian Signals Directorate, Frontier models and their impact on cyber security (30 April 2026 update): https://www.cyber.gov.au/about-us/view-all-content/news/frontier-models-and-their-impact-on-cyber-security-update
  • Australian Signals Directorate, Frontier models and their impact on cyber security: https://www.cyber.gov.au/about-us/view-all-content/news/frontier-models-and-their-impact-on-cyber-security
  • Australian Signals Directorate, Opportunities for AI in cyber defence: https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/opportunities-for-ai-in-cyber-defence
  • Bank of England, Financial Conduct Authority and HM Treasury joint statement on frontier AI, May 2026 (reported): https://www.lowenstein.com/news-insights/publications/articles/frontier-ai-models-and-cybersecurity-readiness-recalibrating-risk-for-a-faster-threat-environment-mushahwar-overton