APRA and ASIC put frontier AI, cyber and resilience on the board agenda

A resilience exercise fails if each risk team solves its own scenario while nobody makes the cross-business decisions.

The external development is APRA and ASIC’s 1 September 2026 account of superannuation CEO discussions on frontier AI, cyber and operational resilience.

The risk-management implication is that leaders should test the combined event, including authority to contain AI, manage a supplier failure, protect customers and restore critical operations at the same time.

The 30-second take

APRA and ASIC brought superannuation chief executives together on 24 and 30 June to discuss frontier AI, cyber threats, operational resilience and crisis preparedness.

APRA has separately warned that governance, assurance and resilience are not keeping pace with AI adoption.

The business response should be an integrated decision exercise built around critical outcomes, dependencies and trade-offs—not three disconnected control reviews.

Key focus areas

On 1 September 2026, APRA and ASIC published their account of superannuation CEO roundtables held on 24 and 30 June. The discussions covered frontier artificial intelligence, cyber security, operational resilience and crisis preparedness. The agencies highlighted AI-enabled threats, uneven capability and the importance of responding to disruptions that can cut across organisations and service providers.

The timing matters. APRA’s CPS 230 Operational Risk Management standard came into force on 1 July 2026. It requires regulated institutions to maintain critical operations through disruption and to manage risks arising from material service providers.

APRA’s April 2026 letter on AI adds another layer. The regulator said AI governance, assurance and resilience were not keeping pace with adoption. It identified risks including prompt injection, information leakage, insecure integrations, autonomous agents and gaps in security testing, identity management and change control. APRA also observed that boards were still developing AI literacy and could rely too heavily on vendor presentations.

Taken together, the sources point to one current issue: AI, cyber and supplier disruption can be different parts of the same incident.

A compromised integration can corrupt outputs, expose information, interrupt a critical service and force customer or regulator communication within hours.

Why this matters for your business

Organisations often govern these risks through separate structures. Cyber teams manage threat response. Technology teams manage availability. Business continuity teams manage workarounds. AI governance groups review models. Procurement manages the supplier. Legal and communications join when impact becomes visible.

That division may be efficient in normal operations, but it can create hesitation during a compound event. One team wants to isolate the system, another wants to keep serving customers, a third waits for supplier evidence and a fourth cannot determine whether affected outputs must be withdrawn. The control gap is not the absence of expertise. It is the absence of a rehearsed decision that reconciles competing objectives.

The issue is relevant beyond superannuation. A retailer using AI for fraud screening can face a cyber attack that degrades the model and delays orders. A health provider can lose access to an AI-supported workflow through a cloud outage while needing to protect sensitive data. A manufacturer can receive unsafe predictions after a compromised sensor or integration. A professional-services firm can discover confidential information has been exposed through a supplier while client work continues.

In each case, the business must decide what to stop, what to continue, which fallback to use, how to identify affected decisions and when to escalate. Separate risk registers do not make those decisions.

Where the risk can surface

The first weakness is conflicting authority. Cyber can disable access, but the business owner believes only an executive can suspend the customer service. Time is lost while exposure continues.

The second is incomplete dependency information. The crisis team knows the contracted vendor but not the underlying model, data service, identity provider or cloud region. It cannot tell whether an apparently separate process is affected by the same failure.

The third is untested degraded operation. A manual fallback exists, but it cannot handle real volume, lacks current data or creates unacceptable customer harm. Recovery plans therefore protect the system rather than the business outcome.

The fourth is poor decision traceability. The organisation cannot identify which AI-assisted decisions were made during the affected period, who approved continued use or which customers need remediation.

What leaders should do now

The chief operating officer or accountable executive should choose one critical AI-enabled service and define its maximum tolerable disruption, minimum acceptable service and prohibited outcomes. This anchors the exercise in a customer or business result.

The crisis owner should build a scenario in which AI output quality falls while a cyber event affects an integration and a material supplier is slow to respond. The injects should force decisions about isolation, fallback, customer impact, notification, data integrity and recovery order.

Technology, cyber, risk, legal, communications, procurement and the business owner should participate together. Record who has authority to suspend the system, accept degraded service, invoke supplier obligations, notify stakeholders and approve restoration. Any unresolved conflict should become a named remediation action.

Internal audit or independent assurance should examine the evidence produced by the exercise: timestamps, decision logs, dependency gaps, recovery performance, affected-output traceability and actions closed. The test should demonstrate that the business can make and execute decisions under pressure, not simply that everyone attended.

Questions for your business

  • Which AI-enabled service would create the greatest customer or operational harm if compromised?
  • Who can suspend that service when cyber, supplier and business priorities conflict?
  • Can we identify every underlying dependency and every decision made during an affected period?
  • Has the fallback been tested at realistic volume and for the full tolerable outage?
  • What evidence must be available before leaders approve restoration?

Visit the Innovation of Risk for practical prompts on integrated scenarios, decision authority and recovery evidence.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.

APRA and ASIC put FAR streamlining on the table

APRA and ASIC’s September 2026 FAR proposal could halve accountability-map updates, but internal decision visibility still matters. Firms should preserve authority, dependencies and escalation paths even as regulator-facing requirements become simpler.