reading roomThought Leadership

Monday, September 21, 2026
The Innovation of Risk Reading Room provides independent analysis of risk management, AI governance, board oversight, regulation, operational resilience, compliance and culture. Our articles translate current events and regulatory developments into practical questions for boards, executives, auditors and risk professionals.

Recent news

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

Why AI Operational Resilience Must Be a Boardroom Priority Now

AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

Featured

Cyber risk is not a compliance project, it is great business

The deeper lesson is that cyber risk maturity must be embedded into normal strategic, operational, supplier and technology assessments.

Effective Risk Committees

The practice of effective risk management requires the management team to take ownership for the risks of their business through an effective and efficient decision making process.

Every Risk Moment Matters

In each of our working and personal lives every moment matters. This applies just as much for risk moments as customer facing moments.

Thought Starters

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

APRA’s Level 3 conglomerate standard reset is a governance issue

APRA has published its response to consultation on remaking the Level 3 conglomerate standards. This is a substantive prudential and governance update for groups with complex conglomerate structures, especially where superannuation, insurance and banking interests…

Why AI Policy Must Be Practical: Turning Guardrails into Actionable Risk Controls

Many organisations have AI policies, but these often fail to guide day-to-day decision making. To manage AI risks effectively, policies need clear guardrails that business teams can apply consistently. This article explains how to translate high-level AI principles into practical standards and controls that enable confident, accountable AI use.

APRA’s Final Push on Governance: What Boards Need to Do Before 2028

APRA has entered the final phase of its governance reform, releasing a unified CPS 510 standard that replaces five prudential standards and raises the bar for board independence, conflicts management, and fit and proper obligations. With a 2028 effective date and consultation closing August 2026, banks, insurers, and super funds need to start their gap analysis now.

Categories

Learn more about Innovation of Risk subscription services