The Australian Prudential Regulation Authority (APRA) has called for a step-change in how banks, insurers, and superannuation trustees manage AI-related risks as the technology continues to rapidly evolve.
In a published letter, APRA warned that governance, risk management, assurance, and operational resilience practices are not keeping pace with the scale, speed, and complexity of AI adoption.
The letter outlines the findings of a targeted supervisory review that APRA undertook late last year across all its regulated industries examining how AI was being deployed and governed. The review noted that the expanded use of advanced AI is introducing a range of new financial and operational vulnerabilities for entities, but that practices are struggling to keep up with the pace of change.
It also warns that frontier AI models such as Anthropic’s Claude Mythos, which could enhance the discovery of vulnerabilities by bad actors, are expected to further increase the probability, speed, and scale of cyber attacks.
Other key points highlighted include:
- AI use is accelerating across all APRA-regulated industries with entities moving from experimentation towards more operationally embedded and customer-facing applications. However, governance arrangements have not matured at the same pace.
- Boards have strong interest in AI’s potential benefits, but many lack the technical literacy required to provide effective challenge to management on AI-related risks and oversight.
- Heightened concentration risk was noted with some entities heavily dependent on a single provider for multiple AI use cases and gaps in contingency planning.
- AI functionality is often embedded within broader software platforms or developer tooling, reducing transparency over where and how models are trained, updated, or constrained and limiting entities’ ability to completely assess and manage risks.
AI risks can cut across multiple domains, such as operational resilience, cyber security, information security, privacy, and procurement. Existing change and assurance management approaches are often fragmented and may not effectively provide sufficient assurance for AI.






