Overview
For banks, insurers and superannuation trustees using AI, the regulatory message is becoming difficult to miss: existing obligations apply in full, and regulators expect firms to be able to demonstrate that their governance, risk management and resilience measures are keeping pace with the technology.
For boards and senior management, that means moving beyond awareness of AI risk. The focus is increasingly on whether an organisation can make effective decisions, maintain critical operations and recover when an AI-related incident develops faster or differently than anticipated. Governance arrangements need to work in practice, controls need to be tested and resilience needs to be measurable.
APRA and ASIC reinforced that message on 27 August 2026, when they published insights from frontier AI industry roundtables held across June and July. More than 380 representatives from banks, insurers, superannuation trustees and service providers participated, alongside the Australian Signals Directorate, Reserve Bank, Treasury and ACCC. The regulators' central message was to move from awareness of frontier AI risk to action.
The roundtables follow a series of regulatory warnings. In April, APRA said governance, risk management and assurance were not keeping pace with AI adoption and warned of stronger supervisory action and, where appropriate, enforcement. ASIC subsequently treated cyber resilience against frontier AI models as a core licensing obligation and directed that the issue be considered at board and risk committee level. Its 2026–27 Corporate Plan also identifies customer-facing AI as an area of intensified oversight.
Importantly, this is happening without a new AI-specific regulatory regime. The National AI Plan of December 2025 confirmed that Australia will not legislate mandatory guardrails for high-risk AI, and the Office of AI announced in July 2026 coordinates rather than regulates.
Australia's existing regulatory frameworks remain the primary mechanism for governing AI. APRA and ASIC describe their frameworks as principles-based and "technology neutral". For regulated entities, however, technology neutrality does not mean regulatory neutrality: existing obligations continue to apply, while firms must determine what controls are necessary to address the particular risks created by AI.
This article outlines the key issues regulated entities should consider when deploying AI under Australia's existing legal and regulatory framework.
The prudential layer
For APRA-regulated entities, the prudential standards need to be front of mind when planning and implementing AI.
CPS 230 requires entities to identify critical operations, set tolerance levels and manage material service providers. Where AI supports a critical operation, APRA’s April letter makes it clear that regulated entities require documented risk management steps, credible fallback processes and a map of the full AI supply chain, including foundation model providers.
CPS 234 is engaged because the cyber threat landscape has been fundamentally changed by AI. APRA lists prompt injection, data leakage, insecure integrations and manipulation of autonomous agents as examples of pathways it is already observing, and notes that identity and access frameworks have not adjusted to non-human actors. APRA's governance expectations provide guidance as to what is expected to meet the regulatory standard, including:
- an inventory of AI use cases;
- ownership across the lifecycle;
- human involvement in high-risk decisions;
- continuous monitoring of model drift; and
- second line and audit functions able to assess probabilistic and agentic systems.
The 27 August joint paper also adds cyber resilience as another key area for regulated entities. Its central observation is that governance and escalation, not just technical controls, are critical in an AI-accelerated incident, because compressed timeframes leave no room to debate authority or priorities in the moment. The regulators expect the key decisions to have been made and tested in advance. For example, who can order a shutdown, what the escalation triggers are, and which suppliers the entity will rely on under stress.
The licensing and accountability layer
For AFS licensees, the general obligations in section 912A apply to AI in the same way as to any other system. Financial services must still be provided efficiently, honestly and fairly, representatives must still be adequately trained and supervised, and resources and risk management systems must still be adequate for the way AI is being used.
ASIC’s position is that AI does not shift responsibility. An output generated by an AI tool is the licensee’s conduct. If a chatbot recommends a product, or produces content a reasonable person would take as a recommendation, the licensee is providing financial product advice. If the tool takes into account the customer’s objectives, financial situation or needs, or a reasonable person might expect it to, that is personal advice, and the best interests duty and advice documentation obligations follow. ASIC’s digital advice guidance (RG 255) has said this since 2016, and its October 2024 review of AI governance (Report 798) found licensees adopting AI faster than their governance was adapting. Statements an AI tool makes about products, fees or eligibility are the licensee’s representations for the purposes of the prohibitions on misleading or deceptive conduct. An AI tool used to market or distribute products is a distribution channel that must operate within the target market determination. An AI-driven error that amounts to a significant breach of a core obligation is reportable to ASIC under the breach reporting regime.
For entities subject to the Financial Accountability Regime (ADIs, insurers and RSE licensees, and their significant related entities) – governed by both ASIC and APRA - AI belongs in the accountability framework. Each accountable person must take reasonable steps in conducting their responsibilities, which includes appropriate governance, controls and risk management, safeguards against inappropriate delegation, and procedures for identifying and remediating problems. An AI system that supports a critical operation, makes customer decisions or generates customer-facing content sits within someone’s accountability statement, and that person needs to be able to show what they did to understand and control it. Reasonable steps reviews, and the evidence kept to support them, should now cover AI deployments expressly. The consequences under FAR are personal, including reduction of variable remuneration and disqualification.
The privacy and data layer
AI in financial services often involves substantial amounts of personal information, and the Privacy Act’s new automated decision-making rules increase the complexity. From 10 December 2026, an APP entity that uses a computer program to make, or substantially and directly support, a decision that could reasonably be expected to significantly affect an individual’s rights or interests must describe those decisions and the personal information involved in its privacy policy. Credit, insurance claims, product eligibility decisions, and customer onboarding are all good examples of automated decisions within the financial services sector that will be impacted by these new laws.
The OAIC has also been explicit about its expectations in respect of AI, including undertaking privacy impact assessments (PIA). A PIA considers the particular risks of a project and records what personal information the system ingests and generates, whether each use is necessary and within reasonable expectations, where the data goes, and what the organisation decided to do about the risks it found. For a financial services entity the PIA performs multiple compliance and governance tasks: it identifies the information privacy risks and the decisions that will need automated decision-making disclosure, and it is evidence that the entity examined the risk before deployment in accordance with its prudential regulatory requirements.
Reasonable steps for cyber risk, demonstrated in advance
Cyber risk is a key issue when implementing AI and defending against new cyber threats brought about by AI. Under the Privacy Act, APP 11 requires steps reasonable in the circumstances to protect personal information. The licensing obligation to provide financial services efficiently, honestly and fairly has also been held to require adequate cyber security resources and controls. CPS 234 requires information security capability commensurate with the threats to the entity’s information assets.
Each applies a relative test and are considered by reference to what the entity knew or ought to have known. That is why the letters and the joint paper matter not only as guidance, but are relevant to whether or not the above standards are being satisfied, as an entity told by both regulators that frontier AI has increased cyber risk cannot say, after an incident, that the threat was unforeseeable or that pre-2026 controls were reasonable.
The recent decisions show how the standard is applied. In Australian Clinical Labs, the first civil penalty proceeding under the Privacy Act , the Federal Court imposed a $5.8 million penalty where security logs were deleted after an hour, no cyber risk assessment was undertaken on the acquisition that introduced the vulnerability, policies referenced standards never implemented and the security budget sat well below industry norms.
ASIC’s section 912A cases run the same way: RI Advice, for the absence of consistent controls across an adviser network; FIIG Securities, penalised $2.5 million this year for inadequate technological, financial and human resources; and the proceedings against Fortnum, which remain on foot. The common thread is adequate systems, adequate resources and follow-through.
The OAIC’s articulation of reasonable steps is the frame a regulator will apply, being technical and organisational measures such as governance, documented and implemented internal practices, ICT and access security, third-party assurance, physical security, destruction of information no longer needed, and recognised standards such as the Essential Eight.
But the key issue remains the actual implementation of policy, because a policy that references a standard but is not implemented within an organisation is not going to meet the relevant standard. All of these steps need to be documented, because reasonable steps are proved by records made before the incident: risk assessments, board papers, test results and exercise reports. That is the joint paper’s demand for evidence of preparedness in another form.
Where to start
The gap the regulators have identified is between recognising that obligations apply and being able to demonstrate how. Closing it starts with:
- an inventory of AI use cases, mapped against the decisions they touch and the obligations those decisions engage;
- a decision on which use cases require a human in the loop, and who is accountable for each;
- a check that each AI use case is mapped to an accountable person under FAR, and that reasonable steps evidence and AFSL compliance arrangements treat AI outputs as the entity’s own conduct;
- a privacy impact assessment for each AI deployment that handles personal information, and a review of the privacy policy and data flows ahead of 10 December 2026;
- a review of AI supplier contracts against CPS 230 and APRA’s expectations, with a map of the dependencies shared with the rest of the sector;
- board-level decisions on shutdown authority, escalation triggers, supplier reliance and recovery priorities, made and exercised before an incident rather than during one; and
- a board that can ask the right questions when management presents the technology vendor’s marketing materials.
Technology neutral regulation does not lower the bar. It simply declines to describe the bar, and leaves the organisation to prove it has been cleared. The joint paper has made clear that proof is what the regulators will now be asking for.
Thomsons can help your organisation navigate and manage these emerging technical and regulatory risks.
This article was written by Partner Hayden Delaney, a specialist technology, privacy and intellectual property lawyer at Thomsons. Assistance was provided by Liam Hennessy, Partner in financial service regulation. For further assistance on the legal and risk issues in adopting AI, contact our Technology and Digital Innovation team.