On 8 May 2026, ASIC Commissioner Simone Constant issued an open letter to AFS licensees and market participants. It runs to four pages. It is not a discussion paper. It is not a consultation. It is a statement of expectation, and it should be read by every board across Australia and New Zealand whose business relies on regulated trust.
The subject is frontier artificial intelligence. The message is straightforward: do not wait for perfect clarity to address the threat posed by new AI models. Act now, and act with discipline, to strengthen the cyber resilience fundamentals that underpin your business.
This is the second formal regulatory signal from a major Australian regulator in less than ten days. APRA wrote to its regulated population on 30 April 2026. ASIC has now followed. Read together, the two letters describe a regulatory environment in which frontier AI is no longer a future agenda item. It is a present supervisory concern.
What is frontier AI?
The leading edge. Frontier AI refers to highly capable, general-purpose AI models at or near the limits of current capability. They are typically foundation models trained at significant scale, with broad capabilities across language, reasoning, code generation, and agentic action.What makes them a cyber concern is dual-use. The same capability that accelerates productivity accelerates reconnaissance, social engineering, vulnerability discovery, and multi-stage attack orchestration. That is the shift ASIC is responding to.
ASIC's framing is precise. Frontier AI models are accelerating both capability and accessibility of cyber activity, lowering the barrier for sophisticated attack, and increasing the speed and scale at which existing weaknesses are tested. This does not create entirely new categories of risk. It places existing controls under greater pressure, more often, and under conditions that traditional point-in-time assurance was never built to handle.
The letter then lists twelve actions ASIC expects entities to take:
Reassess cyber plans.
Confirm governance frameworks consider cumulative vulnerabilities.
Identify and protect critical assets.
Strengthen the fundamentals.
Minimise attack surfaces.
Review user access.
Patch promptly.
Strengthen patch management.
Implement layered, defence-in-depth architectures that assume breach.
Prepare for incident response.
Manage third-party risks.
Use AI for defensive purposes.
None of these are new expectations. The environment in which they must operate has changed.
The letter cites the court's judgment in ASIC v FIIG Securities Limited as the standard. Cyber risk management must be demonstrably effective and proportionate to the size, nature and complexity of the business. Built on consistent execution of well-established controls. Supported by clear governance and adequate resourcing.
Boards and senior executives are expected to understand their organisation's position, ask the right questions, and be able to evidence the basis for their assurance. Governance should not rely on assurances. It should be supported by evidence. Test results. Audit findings. Lessons from incidents. Independent validation.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
In our work across Australia and New Zealand, the same pattern appears. A board paper that summarises cyber posture in a single colour-coded slide. A risk register that lists "AI" as an emerging risk without controls. A penetration test from eighteen months ago. A managed service contract with a quarterly report. Policies written for a threat environment that no longer exists.
None of that is negligent. It is the legacy of how cyber risk used to be managed. ASIC is saying it is no longer sufficient.
This is what our Cyber Readiness Assessment is built for, and ASIC's letter sharpens the case for it in two distinct ways.
For organisations that have not recently tested their position against the current threat environment, the assessment is the structured first step. It maps the entity's posture against the obligations that apply, including APRA CPS 230 and CPS 234, the Privacy Act 1988, the Essential Eight, ISO 27001, ISO 42001, and, for New Zealand entities, NZISM. The output is a prioritised view of risk, ranked by what matters most to the business and to the regulator, with a remediation pathway the board can defend.
For organisations that believe they already have a robust posture, the assessment serves a different purpose. ASIC is explicit that governance should be supported by independent validation. An external, structured review by an experienced cybersecurity professional provides the second pair of eyes the regulator is looking for.
Where the gaps relate specifically to AI, our AI Security and Governance practice is built around three connected services that map directly to ASIC's expectations.
AI Assurance tests AI systems and agents for prompt injection, exfiltration and agentic privilege escalation.
ISO 42001 implementation establishes the AI Management System that integrates AI risk into the broader risk framework.
Managed Compliance maintains the controls and produces the monthly evidence record that replaces annual point-in-time assurance.
ASIC's letter is addressed under Australian law. The threat environment is not. The NCSC New Zealand Cyber Threat Report 2025 documents the same acceleration of AI-enabled threats. For New Zealand boards, the mapping is the same. ISO 42001 is jurisdiction-neutral. NZISM compliance sits inside the Managed Compliance scope.
ASIC closed its letter with a directive. Boards and risk governance committees are expected to table and discuss the letter. That meeting is coming. The question every director should be asking before it is simple: can we evidence, with documents in the room, that our cyber resilience is demonstrably effective and proportionate to our size, nature and complexity?
Start with a Cyber Readiness Assessment or talk to Insicon Cyber about how our team can support your response to the ASIC letter.
Background Reading