The Four Decisions Boards Should Make Before an Incident
The joint APRA and ASIC information paper says weaknesses in governance and escalation can be as disruptive as weak technical controls. A firm may detect an intrusion quickly and still lose critical time if management cannot determine who can isolate a system, suspend a service, activate an alternative provider or notify customers.
| Board Decision | Evidence the Regulators Expect |
|---|---|
| Risk appetite | Evidence that frontier AI has changed risk limits, priorities or resilience investment where necessary |
| Escalation authority | Named decision-makers, tested delegation arrangements and clear triggers for shutdown or containment |
| Recovery priorities | Agreed critical services, restoration sequence, acceptable downtime and tested fallback arrangements |
| Communications | Pre-agreed internal, customer, market and regulator communications tested through crisis exercises |
The checklist gives firms a simple test. If those decisions would be debated for the first time during an incident, the regulators consider that a priority gap. Preparation should be demonstrated through crisis exercises, tested escalation routes and evidence that findings have changed controls or investment decisions.
ASIC Commissioner Simone Constant said: “Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans.” Her emphasis is on proof of execution, not another policy document approved at a scheduled meeting.
The Checklist Sits on Top of Existing Obligations
The legal position differs according to the entity. APRA-regulated banks, insurers and superannuation trustees are subject to CPS 230 Operational Risk Management, whose revised version took effect on 1 July 2026. The standard requires firms to identify critical operations, set tolerance levels for disruption, maintain credible continuity plans and test them against severe but plausible scenarios.
CPS 230 also makes the board ultimately accountable for oversight of operational risk. The board must approve business continuity plans and tolerance levels, review testing results and oversee action on weaknesses. Material service providers must be identified, monitored and covered by formal agreements, including attention to fourth parties used to deliver critical operations.
The information-security layer comes from CPS 234 Information Security. It requires security capabilities proportionate to vulnerabilities and threats, systematic testing of controls and response plans covering detection through post-incident review. Those plans must include escalation and reporting routes and be reviewed and tested annually.
Frontier AI changes the assumptions under those standards rather than replacing them. A patching timetable, escalation route or recovery target that was adequate against human-led attacks may no longer remain adequate when models can identify weaknesses, combine several minor flaws and automate parts of an intrusion.
For entities overseen by ASIC, the regulator’s May letter said cyber resilience is a core licensing obligation. The enforcement basis is not theoretical. ASIC previously pursued RI Advice over failures to maintain adequate cyber controls across authorised representatives, a case that showed how cyber weaknesses can become a financial-services licensing matter.
Cyber Fundamentals Still Come Before Defensive AI
The roundtable participants reported growing interest in using AI for threat intelligence, vulnerability detection, code review and incident response. The regulators did not present that technology as a replacement for asset visibility, timely patching, strong access controls, secure backups or tested recovery.
Defensive AI remains limited across the sector and introduces its own risks. A security model needs governance, secure configuration, monitoring, reliability testing and human oversight. If a firm depends on one model provider for vulnerability scanning or incident response, an outage, access restriction or flawed output can weaken the control intended to improve resilience.
The Australian Signals Directorate has reached a similar conclusion. Its frontier AI guidance for boards says newer models can find vulnerabilities, chain lower-severity weaknesses into larger compromises and conduct malicious activity with little human oversight. It tells organisations to review current risk assumptions, reduce exposed attack surfaces and test whether incident plans still work when attacks move faster.
The concern extends beyond Australia. UK financial authorities issued their own frontier AI warning in May, while exchange operators have continued to rank AI and cyber resilience ahead of longer-dated risks such as quantum computing. The World Federation of Exchanges has urged regulators to keep immediate AI-enabled threats in proportion when allocating attention to emerging technologies.
One Provider Failure Can Become a Sector Incident
The roundtables placed unusual weight on shared dependencies. Several apparently independent financial firms may rely on the same cloud platform, software service, AI model, telecommunications route, payment provider or open-source component. A failure at that common point can therefore interrupt multiple firms at once.
The regulators want dependency maps showing which providers support critical operations, where concentration exists and how a disruption could spread. Firms should be able to demonstrate that fallback, restoration and reconnection arrangements work within the shorter timeframes created by AI-assisted attacks.
This goes further than counting vendors or reviewing contracts. Two suppliers may still depend on the same cloud region or identity service, while one provider may support several customer-facing operations. The relevant measure is how much of the business fails through one technical or operational dependency.
The requirement is particularly consequential under CPS 230 because regulated entities must maintain a register of material service providers and identify the fourth parties on which those providers depend. A firm cannot assume that outsourcing a process also outsources responsibility for keeping a critical operation within its disruption tolerance.
ASIC has been raising the issue for years. A 2017 cyber-resilience survey found weaknesses in incident response and visibility over externally managed systems. Frontier AI changes the urgency, but the underlying gaps in provider oversight, access management and recovery are familiar.
Collaboration Does Not Transfer Accountability
APRA and ASIC want firms to participate in sector threat-intelligence sharing, dependency mapping, supplier assurance and coordinated incident exercises. Larger organisations with earlier access to advanced models are also being encouraged to share lessons with smaller firms that may lack the same security resources.
APRA Deputy Chair Therese McCarthy Hockey described that approach as a “Team Australia” mindset. The paper makes clear that collaboration complements each entity’s obligations and does not replace them. A firm remains accountable for its own controls, provider arrangements and ability to recover.
Information sharing can itself require governance. The paper directs firms to manage confidentiality, commercial and competition-law issues when coordinating with peers. Where collaboration could involve commercially sensitive information, participants may need to consider the Australian Competition and Consumer Commission’s authorisation process.
The warning also lands one day after ASIC published a corporate plan that puts AI in three roles: a risk used against consumers and markets, a technology deployed by regulated firms and a tool ASIC intends to use internally. The plan says the regulator will examine customer-facing AI at banks and respond to deepfakes, misinformation and AI-enabled manipulation. Its 2026 to 2027 targets also include at least 30 civil cases, placing the resilience message beside a measurable enforcement programme.
What Firms Now Need to Show
The joint paper does not impose a separate filing deadline or require firms to buy a particular defensive model. Its practical demand is evidence. Boards should be able to show who can make crisis decisions, which operations matter most, how provider failures propagate and whether recovery plans survive an AI-accelerated scenario.
Technology teams need evidence that vulnerabilities affecting critical operations are identified and remediated within acceptable timeframes. Risk teams need current dependency and concentration assessments. Executives need test results showing that backup, recovery, escalation and communications arrangements work under pressure.
The regulators have also signalled that this will remain a heightened supervisory focus. Awareness was the threshold in the April and May warnings. After nine roundtables and a published checklist, firms will increasingly be judged on implementation, testing and measurable resilience outcomes.
Takeaway
ASIC and APRA have not introduced a standalone frontier AI rule. They have translated the threat into a board-level preparedness test built around four pre-agreed decisions, working cyber controls, mapped dependencies and tested recovery. For APRA entities, those expectations already connect to binding duties under CPS 230 and CPS 234. For ASIC licensees, cyber resilience remains part of the systems and resources needed to meet existing licensing obligations.
