Skip to content

What APRA's AI Letter Signals for Every Regulated Business

blank

In April 2026, APRA wrote to industry with a message that was hard to misread. It called for a step-change in how banks, insurers and superannuation trustees manage the risks that come with artificial intelligence, warning that governance, risk management, assurance and operational resilience are not keeping pace with how quickly AI is being adopted.

The letter followed a targeted review of some of the country’s largest financial institutions. While it is directed at APRA-regulated entities, the observations read like a checklist for any organisation now weaving AI into everyday work. The themes are familiar to anyone who has watched a new technology move faster than the structures built to govern it.

Here is what the letter actually says, and why it matters well beyond the entities it was addressed to.

Adoption is racing ahead of governance

APRA found that every entity it engaged with is actively adopting AI, and many are moving beyond internal productivity experiments into customer facing uses such as claims triage, loan processing, fraud detection and customer interaction.

Governance has not matured at the same speed. APRA noted a tendency to treat AI risk as just another technology, which misses what makes AI different. Models can adapt over time, produce unpredictable outputs and carry considerations such as bias and data handling that traditional systems do not. The result is gaps across the AI lifecycle, particularly in monitoring how models behave once they are deployed.

At board level, APRA observed strong enthusiasm for the benefits of AI, but also that many boards are still building the technical literacy needed to challenge and oversee AI decisions. In some cases there was an overreliance on vendor presentations rather than independent examination of the risks.

AI is changing the cyber threat landscape

The letter is clear that AI is not only a productivity story. It is also reshaping how organisations are attacked.

APRA pointed to new attack pathways, including prompt injection, data leakage through AI tools, insecure integrations and the misuse of autonomous AI agents. AI can shorten the attack cycle, allowing incidents to move with more speed and coordination than before.

One observation deserves particular attention as adoption grows. Identity and access controls in many organisations have not yet adjusted to non-human actors, such as AI agents that can act inside systems on a user’s behalf. At the same time, staff use of AI tools outside approved control frameworks remains a concern, with many organisations relying on policy rather than enforceable technical controls.

Supplier concentration and opacity are real risks

APRA observed some entities heavily dependent on a single provider for multiple AI use cases, often without tested exit or substitution plans. Because AI capability is increasingly embedded inside software and platforms, the upstream dependencies, such as foundation models and the data behind them, can be opaque. That makes it harder for an organisation to independently assess how a model performs, where its data goes and how resilient it is.

blank
blank

Assurance built for static systems is not enough

Traditional change management and point-in-time assurance were built for systems that behave the same way each time. APRA noted these methods are ill-suited to probabilistic models that learn, adapt and degrade over time, and that few entities had continuous monitoring in place to detect issues such as model drift. Internal audit and risk functions were often found to lack the specialist skills and tooling to assess AI systems.

What APRA expects

Underneath the observations, APRA set out clear expectations. At a minimum, entities should

  • Maintain board and executive literacy sufficient to set strategic direction and provide genuine challenge on AI risk.
  • Run an AI strategy aligned to the organisation’s risk appetite, supported by monitoring and reporting.
  • Keep an inventory of AI tooling and AI use cases.
  • Assign ownership and accountability across the AI lifecycle, from design through to decommissioning.
  • Keep people involved in high-risk decisions.
  • Train staff on AI use, misuse, limitations and secure practices.
  • Map the full AI supply chain, including third and fourth-party dependencies.
  • Apply continuous, integrated assurance across security, data governance, model performance and privacy.

APRA also signaled that where entities fail to manage AI risks proportionately, it will take stronger supervisory action and, where appropriate, pursue enforcement.

Why this matters beyond APRA-regulated entities

APRA regulates banks, insurers and superannuation trustees. Financial advice licensees sit under ASIC, which delivered a strikingly similar message in its own May 2026 letter describing cyber resilience as being at a minute to midnight and stressing that boards must be able to evidence that controls are actually working, not just designed.

Two regulators, weeks apart, landed on the same point. AI adoption is moving faster than governance, and the expectation is shifting from intent to evidence.

Where to start

For most organisations, the honest starting point is simpler than a strategy document. It is visibility.

Many businesses cannot yet answer a basic question: where is AI already being used across the organisation, including the AI features quietly switched on inside the software we already run? Building that inventory is where responsible adoption begins. From there, the familiar disciplines apply. Align access to what each person, and each agent, genuinely needs. Keep people accountable for high-risk decisions. Make sure the information AI can reach is well organised and governed underneath.

That last point is where much of the real work sits. Tools like Microsoft Copilot operate on the information users already have access to, which means the value they deliver, and the risk they carry, is shaped by how well that environment is structured. For many organisations, AI is not creating new governance questions so much as bringing existing ones into sharper focus.

At Danet, this is the conversation we are having with clients across regulated industries. Not whether to adopt AI, but how to build the visibility, identity controls and information governance that let an organisation adopt it with confidence.

If your organisation is working through what responsible AI adoption looks like in practice, get in touch.

Sources

APRA, Letter to Industry on Artificial Intelligence (published 30 April 2026): https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai

ASIC, open letter on cyber resilience and AI (May 2026), as summarised by Clayton Utz, “The clock is at a minute to midnight”: “The clock is at a minute to midnight”: ASIC’s ope… | Clayton Utz

ASIC, Cyber resilience regulatory resources: Cyber resilience | ASIC

Australian Signals Directorate (ASD), Annual Cyber Threat Report 2024-25 (context on the evolving threat environment): https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025