ASIC, APRA urge action on frontier AI risks
Australian regulators ASIC and APRA warn frontier AI is accelerating cyber and operational risks, urging firms to move from awareness to action.

The Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) are pushing financial market entities to take decisive action against risks linked to frontier artificial intelligence. Both regulators have publicly warned in recent months that frontier AI is increasing the speed, scale, and sophistication of cyber threats to the financial system while also accelerating technology and operational risks.
To drive this message home, the regulators hosted nine roundtables in June and July. These sessions involved more than 600 attendees from across the financial system. The Australian Signals Directorate (ASD) supported the effort. Participation from the Reserve Bank of Australia, Treasury, and the Australian Competition and Consumer Commission signalled a whole-of-government response to what is seen as an urgent threat.
Key themes from regulator roundtables
Several critical themes emerged from the discussions. The importance of getting cyber fundamentals right was emphasised. This includes identifying and managing critical assets, timely patching, strong identity controls, attack surface reduction, backup integrity, tested response plans, and third-party risk management.
Boards must consider key decisions before a crisis hits. Given that frontier AI compresses incident response timeframes, setting risk appetite, escalation authority, recovery priorities, and communication strategies at board level is now essential.
There is growing interest in using defensive AI for threat intelligence, vulnerability detection, code review, and incident response. However, participants acknowledged that current capability in this area remains limited.
Common dependency on third-party service providers creates concentration risk. This can turn an isolated incident into a broader sector-wide disruption. Actively contributing to industry-led collaboration was highlighted as vital. This includes sector-wide threat intelligence sharing, dependency mapping, supplier assurance, and sector incident coordination.
Regulator statements on urgency and collaboration
ASIC Commissioner Simone Constant stated the urgency of the challenge cannot be overstated. "Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find," she said. Constant urged boards and executives to move beyond awareness. They must ensure their organisations have well-tested response plans and understand their vulnerabilities to respond effectively under pressure.
APRA Deputy Chair Therese McCarthy Hockey noted this was the first time the two regulators created forums for rapid information-sharing across such a broad cross-section of the financial sector. It highlights their commitment to better regulatory practices that support industry against complex risks.
Hockey pointed to an encouraging theme. More advanced entities showed a willingness to share practical insights, lessons, and approaches with peers and less mature entities. She described this as precisely the type of 'Team Australia' mindset needed to shore up resilience across the highly interconnected financial system.
The regulators have published an information paper with further insights from the roundtables. A preparedness checklist for boards and executives is also available.





