Back to Insights
    Regulatory Update
    30 April 2026 · 8 min read

    APRA Letter to Industry on Artificial Intelligence, What It Means for Australian Regulated Entities

    In April 2026 the Australian Prudential Regulation Authority issued a formal letter to all APRA-regulated entities setting out its observations and expectations on AI. This is the clearest signal yet that AI governance is now a prudential supervision priority for banks, insurers and superannuation trustees, and that enforcement action is on the table where entities fall short.

    Who This Letter Applies To

    APRA addressed the letter to all APRA-regulated entities, every Australian bank (ADI), general and life insurer, private health insurer, and superannuation trustee. While the underlying observations were drawn from a deep-dive engagement with the largest entities in late 2025, APRA is explicit that smaller and earlier-stage adopters are expected to apply the same lessons in proportion to their size, scale and complexity.

    Why This Letter Matters Now

    APRA's principle-based prudential framework is technology and vendor agnostic. That means existing standards, including CPS 230 (Operational Risk Management), CPS 234 (Information Security), CPG 235 (Data Risk) and the Board accountability requirements under CPS 510, already apply to AI. APRA is now making clear that supervisory focus is shifting to how well entities are actually operationalising those standards against AI risk, with stronger supervisory action and enforcement where they fall short.

    The letter is signed by Therese McCarthy Hockey, APRA Member, and was accompanied by a detailed observations attachment for CROs, CTOs and CISOs.

    APRA's Four Core Observations

    APRA's targeted engagement surfaced four areas where current practice is not keeping pace with the speed and complexity of AI adoption:

    1. AI threats are increasing, but information security practices are struggling to keep pace

    APRA observed new attack pathways including prompt injection, data leakage, insecure integrations, exploit injection and the manipulation of autonomous AI agents. Identity and access management has not adjusted to non-human actors such as AI agents, and AI-assisted software development is straining change and release management controls. Use of enterprise AI outside approved frameworks was a particular concern, with entities relying on policy direction rather than enforceable technical restrictions.

    2. AI adoption is moving fast, but governance maturity is lagging

    APRA observed a tendency to treat AI risk as "just another technology", missing the distinct characteristics of probabilistic and adaptive systems, inherent bias, and privacy and data risks. Gaps were most acute in post-deployment monitoring, model behaviour monitoring, change management and decommissioning. Few entities had operationalised AI governance in practice.

    3. Supplier risk management is in place, but concentration and opacity present challenges

    Entities were often heavily dependent on a single AI provider across multiple use cases, with few demonstrating tested exit or substitution strategies. Contractual arrangements lagged practice on audit rights, model updates, incident notification and data handling. Upstream dependencies, foundation models, training data and fourth parties, remained opaque, limiting independent assurance.

    4. Traditional change management and assurance is in place but is not sufficient for dynamic AI

    Point-in-time and sample-based assurance methods are poorly suited to probabilistic models that learn, adapt and degrade over time. Few entities had continuous validation in place to detect model drift, bias or control breakdowns. Internal audit and second-line risk functions frequently lacked the specialist skills and tooling to independently assess agentic systems and AI-generated code.

    What APRA Expects of Boards

    APRA expects Boards, at a minimum, to:

    • Maintain sufficient AI literacy to set strategic direction and provide effective challenge and oversight, not rely on vendor presentations and summaries
    • Oversee an AI strategy consistent with the entity's risk appetite and tolerance, supported by effective monitoring and reporting (including for third-party dependencies)
    • Ensure clearly defined triggers aligned to resilience objectives, so timely action can be taken when AI is not operating as expected

    What APRA Expects of CROs, CTOs and CISOs

    The accountable executive expectations are detailed in the attachment to the letter. In summary, APRA expects:

    • Operational resilience assessments that account for AI reliance, with credible fallback processes where AI supports critical operations
    • AI-specific security controls, privileged access management, timely patching, hardened configurations, automated vulnerability discovery, penetration testing, and controls over agentic and autonomous workflows
    • Robust security testing of AI-generated code, components and libraries
    • A complete inventory of AI tooling and use cases, with ownership and accountability across the full AI lifecycle
    • Human involvement and accountability for high-risk decisions, supported by staff training on AI use, misuse, limitations and secure practices
    • Mapped visibility over the full AI supply chain including material third- and fourth-party dependencies, with active management of concentration risk and tested substitution arrangements
    • Integrated, continuous assurance across cyber security, data governance, model performance, operational resilience, privacy and conduct, with second-line and internal audit equipped to assess probabilistic models and agentic workflows

    How SafegateAI Helps You Meet APRA's Expectations

    SafegateAI's AI advisory and strategy practice is designed to give regulated entities the structure, control and visibility APRA is now requiring. Each of APRA's four expectation areas maps directly to a capability we deliver:

    Shadow AI Monitoring → controls over unsanctioned use

    Real-time detection of every AI tool operating across your environment, with risk categorisation and enforceable preventative controls, directly addressing APRA's concern about staff use of enterprise AI outside approved frameworks.

    AI Inventory & Governance Framework → lifecycle accountability

    A live inventory of every AI use case with defined ownership across design, deployment, monitoring and decommissioning. Policies, standards and reporting lines mapped to CPS 230, CPS 234 and the AI6 framework.

    Supplier & Concentration Risk Management

    Mapping of material third- and fourth-party AI dependencies, contract review for audit rights, model update notification and data handling, plus tested exit and substitution playbooks for critical providers.

    Continuous Compliance & Assurance (SmartHub)

    Continuous monitoring of model behaviour, drift, bias and control performance, replacing point-in-time assurance with integrated, real-time evidence for second-line risk, internal audit and the Board.

    Board & Executive AI Literacy Programs

    Role-specific training for Boards, CROs, CTOs and CISOs so leadership can provide the effective challenge APRA expects, without overreliance on vendor narratives.

    What You Should Do Now

    APRA strongly encourages entities to engage early with its Non-Financial Risk Team where existing risk management approaches may be challenged by AI. In the meantime, regulated entities should treat this letter as a supervisory checklist:

    • Brief the Board on the letter and assess current AI literacy gaps at director level
    • Confirm a complete, current inventory of AI tooling and use cases, including shadow AI
    • Reassess AI supplier concentration and test the credibility of exit and substitution arrangements
    • Move assurance from point-in-time to continuous, with second-line and internal audit equipped for probabilistic and agentic systems
    • Document how existing CPS 230, CPS 234 and CPG 235 obligations are being met for AI specifically

    Read the Source Material

    The full APRA letter (including the executive observations attachment) is available below and on the APRA website.

    Source: Australian Prudential Regulation Authority, APRA Letter to Industry on Artificial Intelligence (AI), April 2026. Republished for informational purposes. This article is general commentary and is not legal or compliance advice.

    Ready to align your AI program with APRA's expectations?

    SafegateAI's Discovery session benchmarks your current AI governance, inventory, supplier and assurance posture against APRA's April 2026 expectations, and gives you a prioritised remediation roadmap within two weeks.