The earlier ASD material, published on 9 April 2026 and updated on 30 April, spoke to accountable authorities, chief security officers and technical teams. Useful, but not the room where cyber risk is accepted or declined. The new publication, Frontier AI cyber threat considerations for boards of directors, is written for directors and senior leaders, and it is co-authored with the AICD. That co-authorship is the signal. This is not a technical advisory a director can delegate. It is a governance document, and it lands sixteen threshold questions squarely on the board table.
Most directors across Australia and New Zealand cannot yet answer them with evidence. That is the point of the exercise.
The regulator's framing is precise and it is worth reading slowly. Frontier AI models can identify vulnerabilities and rapidly weaponise them, chain together multiple low-severity vulnerabilities into high-impact compromises, and perform malicious cyber activities with little to no human oversight. The last of those three is the one that should hold a director's attention. Agentic activity, at machine speed, with no human in the loop.
ASD is blunt about what this does to a board's existing assumptions. These developments may rapidly invalidate an organisation's current risk tolerance. The risk appetite the board signed off last year was calibrated for a slower, human-led threat. It may no longer hold. ASD warns that vulnerability discovery and exploitation timelines are collapsing from days to hours, while the skill and knowledge barrier for malicious actors drops at the same time. Attackers who previously lacked the capability now have it.
There is a second dimension the earlier advisory underplayed and this one puts front and centre. Cyber supply chain risk, and specifically foreign ownership, control or influence over the AI vendors an organisation depends on. ASD asks boards whether they are relying on vendors and service providers without sufficient governance, including an understanding of who ultimately owns and controls them.
ASD groups its threshold questions around exposure, supply chain, fundamentals, and resilience. A director does not need all sixteen memorised. They need to notice the ones management will struggle to answer honestly.
ASD asks what assumptions underpin the current risk assessment, and how frontier AI might invalidate them. It asks which parts of the business would be most exposed if a frontier AI model were used to identify and exploit weaknesses across the organisation. These are not questions a maturity score answers. They require the organisation to reason about itself as an attacker would.
ASD asks whether the board has visibility of the security posture of third and fourth-party suppliers. Fourth-party. Not just the vendor, but the vendor's vendor. Few organisations in Australia or New Zealand can produce that map today.
ASD asks whether the organisation adheres to a recognised cyber security framework, what legacy technology risk it carries, and whether it is delaying remediation because a weakness looks low-severity in isolation. That last one is the trap. Frontier AI is precisely the tool that chains low-severity weaknesses into a major incident.
ASD asks the sharpest question of the set. If attacks moved from taking days to hours, could we still detect and respond to them effectively? And have incident response and business continuity plans been updated and tested to capture frontier AI threats? Most plans across both markets have not been.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
ASD does not leave the board with questions alone. It sets out what management should be doing, sequenced across four horizons, and the sequencing itself is a governance instruction.
The immediate priorities are securing attack surfaces and reducing software vulnerabilities. Configuration baselines that are enforced and monitored for drift. Vulnerabilities identified, prioritised and remediated within risk-based timeframes, with the remediation verified rather than assumed.
The short-term priorities are legacy systems, identity and access, least privilege, and incident preparedness. Note that ASD explicitly extends least privilege to AI agents.
The medium-term priority is adopting AI for cyber defence, on the condition that it is secure, controllable, human-supervised, and used ethically and accountably.
The longer-term priority is modernising to Secure by Design and Secure by Default.
Directors of trans-Tasman organisations should not treat this as an Australia-only development. ASD monitors frontier AI in close consultation with its Five Eyes partners, and New Zealand's National Cyber Security Centre sits inside that same relationship. The threat model does not stop at the Tasman, and the regulatory expectation is converging across both markets.
The publication gives directors the questions. It does not produce the artefacts that turn a boardroom conversation into governable practice. Those have to be commissioned from management, with named owners and dates.
A director in Australia or New Zealand should be asking for four things before the next risk committee meeting.
A patch velocity figure for internet-facing systems, with a target and a plan to close the gap to it.
An inventory of where AI is in use across the organisation and its critical suppliers, extended to fourth-party dependencies.
A control evidence review that shows which controls have been tested, not merely documented, and
A business continuity and incident response plan that has been re-exercised against a scenario where an attack unfolds in hours rather than days.
Insicon Cyber works with boards across Australia and New Zealand at exactly this seam, between the assurance a board receives and the evidence a regulator now expects.
Matt Miller, Co-Founder and CEO, and Greg Bunt, Co-Founder and Director, both work with customers each week as trusted Fractional CISOs. They can take ASD's sixteen questions into the boardroom and turn them into artefacts a director can stand behind.
Control evidence reviews. AI-adjusted threat models. Patch velocity baselining. Supply chain mapping to fourth-party. The AI Security and Governance practice pairs that governance work with the technical assurance to test AI systems, the ISO 42001 pathway to certify them, and the aSOC to maintain compliance around the clock.
ASD has written the board sixteen questions. The directors who do well out of this will be the ones who can answer with documents in the room.
To discuss how your board evidences cyber resilience against frontier AI threats, contact Insicon Cyber.
info@insiconcyber.com or visit https://insiconcyber.com/
Sources