ASIC, APRA urge finance firms to act on frontier AI risks

ASIC and APRA told more than 600 attendees at nine June–July roundtables to move from awareness to practical preparedness for frontier AI amid rising cyber and operational threats.

The Australian Securities and Investments Commission and the Australian Prudential Regulation Authority ran nine roundtables in June and July that drew more than 600 representatives from banks, insurers, superannuation funds, payments firms and market infrastructure. The sessions were supported by the Australian Signals Directorate and included participation from the Reserve Bank of Australia, Treasury and the Australian Competition and Consumer Commission. Regulators urged firms to shift from awareness to concrete preparedness for frontier AI risks, citing faster, larger and more sophisticated cyber and operational threats to the financial system.

Participants identified a set of immediate technical and operational priorities. Firms were asked to identify and protect critical assets and systems, apply timely software patches, enforce strong identity and access controls, reduce attack surfaces, verify backup integrity and maintain tested incident response and recovery arrangements. Heavy reliance on external providers led attendees to push for stronger third-party risk management and clearer supplier assurance processes.

Speakers recommended boards and senior executives set clear positions on risk appetite, escalation authority, recovery priorities and communications before incidents occur, because frontier AI can shorten the time available to detect and respond to breaches. Delegates reported growing interest in defensive AI tools for threat intelligence, vulnerability detection, code review and incident response, while noting those capabilities remain limited and require careful assessment.

Roundtable discussions highlighted dependency and concentration risks tied to widely used third-party services and shared infrastructure, which can turn isolated breaches into broader sector disruption. Attendees encouraged active industry collaboration on threat intelligence sharing, dependency mapping and coordinated incident management across the sector.

ASIC Commissioner Simone Constant warned: “Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find. Now is the time to ensure you have a strong, tested plan to respond when the worst happens.” APRA Deputy Chair Therese McCarthy Hockey described the forums as a new model for rapid information sharing and welcomed more advanced entities sharing practical insights with peers.

ASIC and APRA published an information paper summarising the roundtable findings and released a preparedness checklist for boards and executives to assess and strengthen readiness for frontier-AI-driven threats.

Articles by this author