APRA and ASIC AI Governance in Australia 2026: CPS 230, CPS 234, and What Businesses Must Do Now
APRA and ASIC issued landmark AI governance letters in 2026. Learn how CPS 230 and CPS 234 apply to AI vendors and what a cyber consultant can do for you.
In April and May 2026, Australia's two most powerful financial regulators issued landmark letters that changed the AI governance landscape for every organisation operating in the financial services sector — and sent a clear signal to businesses across all industries. The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) both confirmed that existing prudential and conduct obligations apply in full to artificial intelligence systems, including AI supplied by third-party vendors. For Australian businesses, the message is unambiguous: AI is not a regulatory carve-out. It is a risk that must be governed, tested, and continuously monitored.
Understanding the 2026 APRA and ASIC AI Governance Letters
On 30 April 2026, APRA issued a supervisory letter to all regulated entities — banks, insurers, and superannuation trustees — clarifying that its existing prudential standards apply to AI systems and the vendors that supply them. The letter identified four critical gaps in how regulated entities were managing AI: insufficient board-level technical literacy, unclear lifecycle accountability for AI models, inadequate third-party vendor management, and weak cyber resilience controls around AI infrastructure.
On 8 May 2026, ASIC followed with its own letter to industry, emphasising that existing licensee obligations — including best interests duties, responsible lending obligations, and market integrity rules — apply fully to AI-driven interactions and decisions. ASIC specifically highlighted the cyber resilience risks posed by increasingly capable frontier AI models and the need for stronger controls around AI-generated outputs that affect consumers.
Together, these letters represent the most significant regulatory guidance on AI governance that Australian businesses have received to date. They do not create new law — but they confirm that regulators are actively scrutinising AI deployments and will hold organisations accountable under existing frameworks.
How CPS 230 and CPS 234 Apply to AI Vendors
APRA's Prudential Standard CPS 230 (Operational Risk Management) and CPS 234 (Information Security) are the two standards most directly implicated by the April 2026 letter. Understanding how they apply to AI is essential for any organisation in the financial services sector — and instructive for businesses in other sectors that handle sensitive data.
CPS 230: AI Vendors as Material Service Providers
CPS 230 requires APRA-regulated entities to identify and manage risks associated with material service providers — third parties whose failure or underperformance could significantly disrupt the entity's operations. From 1 July 2026, all contracts with material service providers were required to include provisions for audit rights, incident notification, and exit strategies.
APRA's 2026 letter confirmed that AI vendors — including large language model providers, AI-as-a-service platforms, and automated decision-making systems — must be assessed against the material service provider framework. This means regulated entities must conduct due diligence on AI vendors' operational resilience, data handling practices, model governance, and incident response capabilities before deployment, and on an ongoing basis thereafter.
CPS 234: AI Infrastructure as an Information Asset
CPS 234 requires regulated entities to maintain information security capabilities commensurate with the size and extent of threats to their information assets. APRA's guidance confirms that AI systems — including the data pipelines that feed them, the models themselves, and the outputs they generate — are information assets subject to CPS 234 controls.
This has significant practical implications. Organisations must assess the security of AI vendor infrastructure, including data residency, access controls, encryption standards, and vulnerability management practices. They must also consider the adversarial risks specific to AI systems, such as prompt injection attacks, model poisoning, and data exfiltration through AI interfaces.
Key Governance Requirements for AI Deployments
Based on the APRA and ASIC letters, the Guidance for AI Adoption (GfAA) released in late 2025, and the ASD's 2026 advisories on frontier AI security, Australian organisations should be implementing the following governance controls for any AI system in production.
- Board-level AI accountability — Boards and senior management must understand the AI systems their organisation uses, the risks they pose, and the controls in place. APRA specifically flagged insufficient board technical literacy as a gap requiring urgent attention.
- AI model lifecycle management — Organisations must document the full lifecycle of each AI model: development, testing, deployment, monitoring, and decommissioning. Accountability for each stage must be clearly assigned.
- Third-party AI vendor due diligence — Before deploying any AI system supplied by a third party, organisations must assess the vendor's security posture, data handling practices, model governance, and contractual obligations under CPS 230.
- Continuous monitoring, not point-in-time testing — Both APRA and ASIC have signalled that point-in-time security assessments are insufficient for AI systems, which are probabilistic and can behave differently over time as underlying models are updated. Continuous monitoring is required.
- Incident response planning for AI failures — Organisations must have documented procedures for responding to AI-related incidents, including model failures, adversarial attacks, and data breaches involving AI systems.
- Consumer-facing AI transparency — ASIC's letter emphasised that AI-driven consumer interactions must comply with existing disclosure and conduct obligations. Organisations must be able to explain AI-generated recommendations or decisions to affected consumers.
Common Gaps and Red Flags in AI Governance
A cyber consultant conducting an AI governance review will typically look for the following gaps, which are among the most common findings in Australian organisations that have deployed AI without a structured governance framework.
- No AI asset register — Many organisations cannot enumerate all the AI systems they use, including AI features embedded in existing software platforms. Without an asset register, governance is impossible.
- Vendor contracts without AI-specific provisions — Standard software contracts often do not address AI-specific risks such as model updates, training data changes, or output accuracy obligations. Contracts must be reviewed and updated.
- No adversarial testing — AI systems face unique attack vectors that traditional penetration testing does not cover. Prompt injection, jailbreaking, and model inversion attacks require specialised testing methodologies.
- Shadow AI deployments — Employees using consumer AI tools (such as public large language model interfaces) for work purposes without organisational oversight create data leakage risks that are invisible to IT and security teams.
- Inadequate data governance for AI training — AI systems trained on customer data may inadvertently encode sensitive information that can be extracted through adversarial queries. Data governance frameworks must extend to AI training datasets.
Australian Regulatory Context
The regulatory framework governing AI in Australia in 2026 is a patchwork of existing laws applied to new technology, rather than a standalone AI Act. Key instruments include the Privacy Act 1988, which will impose new automated decision-making transparency obligations from December 2026; the Cyber Security Act 2024, which introduced mandatory ransomware payment reporting and incident notification obligations; and the Online Safety Act 2021, under which enforceable industry codes covering generative AI services took effect on 9 March 2026.
APRA's prudential standards CPS 230 and CPS 234 apply to authorised deposit-taking institutions, general insurers, life insurers, and superannuation trustees. ASIC's conduct obligations apply to Australian Financial Services (AFS) licensees and Australian Credit licensees. The Australian Signals Directorate (ASD) provides non-binding but influential guidance on AI security through its advisories and the Essential Eight framework.
The government has announced plans to introduce Australian Standards for AI in early 2027, to be overseen by a newly established Office of AI. Organisations that build robust AI governance frameworks now will be better positioned to meet these forthcoming requirements without significant remediation effort.
Questions to Ask When Engaging a Cyber Consultant for AI Governance
AI governance is a specialised discipline that sits at the intersection of cybersecurity, legal compliance, and technology risk management. When evaluating a cyber consultant for AI governance work, consider the following questions.
- Do you have experience with APRA CPS 230 and CPS 234 compliance assessments? — Relevant for financial services organisations and their service providers.
- Can you conduct an AI asset discovery exercise? — The first step in any AI governance program is knowing what AI systems are in use, including embedded AI features in existing platforms.
- What adversarial AI testing methodologies do you use? — Look for experience with prompt injection testing, model robustness assessments, and AI-specific threat modelling.
- How do you assess third-party AI vendor risk? — They should have a structured vendor due diligence framework that covers security, data handling, contractual obligations, and exit planning.
- Are you familiar with the GfAA and ASD AI security advisories? — These are the primary non-binding guidance documents shaping AI governance expectations in Australia.
- What does your continuous AI monitoring service include? — Point-in-time assessments are insufficient; ask about ongoing monitoring capabilities.
How MyMoney® Can Help
Navigating the intersection of AI deployment and regulatory compliance requires a cyber consultant with specific expertise in Australian prudential and conduct frameworks. The 2026 APRA and ASIC letters have raised the stakes considerably — organisations that cannot demonstrate structured AI governance are exposed to regulatory action, reputational damage, and the financial consequences of AI-related security incidents.
MyMoney® connects Australian businesses with qualified cyber consultants who specialise in AI governance, APRA and ASIC compliance, and the practical implementation of security controls for AI systems. Our platform allows you to describe your specific AI governance challenge and receive competing proposals from experienced professionals.
Post a Brief to outline your AI governance requirements and receive proposals from qualified cyber consultants. Or Browse Cyber Consultants to explore professionals with the expertise your organisation needs.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).