Branch and Vault
Live
Access & branches

Australian regulators urge action on AI

ASIC and APRA warn financial firms must move from awareness to action on frontier AI risks, following roundtables with over 600 attendees.

ASIC and APRA warn financial firms must move from awareness to action on frontier AI risks, following roundtables with...

The Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) are urging financial market entities to take decisive action on risks linked to frontier artificial intelligence. The regulators hosted nine roundtables in June and July involving more than 600 attendees from across the financial system, supported by the Australian Signals Directorate and other government bodies.

Both APRA and ASIC have warned that frontier AI is increasing the speed, scale, and sophistication of cyber threats to the financial system. They argue that awareness of these risks must now translate into concrete preparedness and response plans.

Key themes from the roundtables

Several critical themes emerged from the discussions, according to the source. A primary focus was on getting fundamental cybersecurity practices right. This includes managing critical assets, timely patching, enforcing strong access controls, and ensuring robust third-party risk management.

Given that frontier AI compresses incident response timeframes, the need for board-level preparation was emphasized. Key decisions on risk appetite, escalation authority, and recovery priorities must be settled before a crisis occurs. There was also growing interest in using defensive AI for tasks like threat detection and code review, though current capability was acknowledged as limited.

The roundtables highlighted how dependency on common third-party service providers can turn isolated incidents into sector-wide disruptions. Finally, the importance of industry-wide collaboration was stressed, including sharing threat intelligence and coordinating incident responses.

Regulatory calls to action

ASIC Commissioner Simone Constant stated the urgency of the challenge cannot be overstated. She warned that threat actors are using frontier AI models to find and exploit vulnerabilities much faster than before. Constant urged boards and executives to move beyond awareness, ensuring their organizations have well-tested response plans and understand their vulnerabilities.

APRA Deputy Chair Therese McCarthy Hockey noted this was the first time the two regulators created such broad forums for rapid information-sharing across the financial sector. She said it highlights their commitment to better regulatory practices that support industry in facing complex risks.

Hockey pointed to an encouraging theme from the discussions: the willingness of more advanced entities to share practical insights with less mature peers. She described this as the type of 'Team Australia' mindset needed to strengthen resilience across the interconnected financial system. The regulators have published an information paper with further insights and a preparedness checklist for boards and executives.

Related coverage

More from Access & branches