惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
博客园_首页
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
B
Blog
D
DataBreaches.Net
腾讯CDC
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
月光博客
月光博客
V
V2EX
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
The Cloudflare Blog
博客园 - 叶小钗
Y
Y Combinator Blog

Digital Transformation

Aussie Treasurer outlines government goals with AI – productivity up, interest rates down PODCAST: AI won’t replace security teams – it will decide whether they keep you, with Securonix’s Ajay Biyani Op-Ed: If we want to lead the world in AI, we must start in primary school classrooms The Industry Speaks, Part 3: AI Appreciation Day 2026 CBA chief economist doesn’t believe the AI bubble is ‘dotcom 2.0’ The Industry Reacts: Can we make AI work in Australia’s national interest? Visa Visa new AI banking assistant to be adopted by financial firms Australians using AI to guide purchasing finds Zip The industry speaks – part 2: AI Appreciation Day 2026 51% of banks boosting productivity with pilot AI Submissions and nominations are now open for the Australian AI Awards 2026 PODCAST: Trust is the new attack surface, with ThreatLocker APAC director of operations Emile Barakat Need to Know: Aussie workers are increasingly exposing customer data to public AI OpenAI’s Altman won’t accept anything under a $1tn IPO valuation Bendigo Bank has over 3k ideas for agentic AI use AI is running two races – revenue growth and stable economy, says Citi CEO ANZ Bank CIO announces new technology strategy ABC’s Anthropic partnership will see AI generate articles Nine, Microsoft partner for AI use in news Op-Ed: What happens when access to intelligence is no longer your decision? Legal trouble: Misleading AI images could lead to millions in fines PODCAST: Why cyber security’s next battle will be won by speed, with Qualys CEO Sumedh Thakar AI costs lead businesses to rethink their AI investment Bendigo Bank wants to have Australia’s first agentic SOC, but will human workers pay the price? 3 in 4 consumers would ditch a company if it suffered a major cyber attack Bankers warn of central market crash thanks to AI boom Artificial intelligence adoption surged in 2024–25, ABS reports PODCAST: Beware AI and influencers, NSW Rural Fire Service hacked, and say goodbye to the Essential Eight! Productivity Commission says the productivity slump can be cured by AI
APRA warns of cyber and governance risk due to lagging AI...
Charlie Tchetchenian · 2026-05-06 · via Digital Transformation

The Australian Prudential Regulation Authority (APRA) has warned banks that their safeguards around artificial intelligence have fallen behind a rapid rollout of new tools – urging a decisive lift in how AI‑driven risks are governed and controlled.

APRA’s intervention follows a supervisory review it ran late last year across the main segments of the financial sector, examining where firms were using AI and how those systems are overseen.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The review found that algorithms are no longer confined to pilots, with many institutions now weaving AI into core operations and customer interactions.

APRA concluded that key risk disciplines – including governance, operational risk, and cyber security – had not evolved at the same speed.

It highlighted that AI capabilities were often hidden inside large software suites, meaning some organisations struggled to see exactly which models they relied on, how those models were trained or updated, and what that implied for risk.

APRA member Therese McCarthy Hockey said financial institutions needed to continually recalibrate their AI governance methods.

“The AI revolution presents tremendous opportunities for banks, insurers and superannuation trustees to deliver improved efficiency and enhanced customer services,” she said.

“But we cannot be blind to the risks of such powerful technology – whether in our own hands or the hands of those with malign intent.”

Frontier models raise the stakes on cyber

The letter also named frontier‑grade models as a specific source of prudential concern.

APRA warned that tools such as Anthropic’s Claude Mythos could be used by malicious actors to probe systems more effectively.

McCarthy Hockey said the tempo of defensive worked needed to accelerate.

“What we’ve observed from our supervisory engagement is that while AI adoption is continuing apace, the systems and processes required to safely govern its use aren’t keeping up,” she said.

“Likewise, the speed at which entities can identify and patch vulnerabilities needs to operate much faster, commensurate with the AI‑accelerated threat.”

Boardroom blind spots

The review focused heavily on how AI was handled in the boardroom, with the regulator finding that many boards did not yet have enough technical understanding to probe management on AI‑related decisions.

The letter also highlighted a build‑up of concentration risk where organisations had leaned heavily on a small number of AI providers for multiple use cases.

APRA said boards needed to develop enough AI literacy to set a clear strategic direction and to offer a genuine challenge.

They are also expected to oversee a coherent AI strategy that fits within the organisation’s risk appetite, supported by reporting on how AI systems are performing.

No bespoke AI standard yet but expectations tighten

For now, APRA is not writing a standalone AI prudential standard, yet it has made it explicit that existing requirements apply to AI‑enabled processes.

It reiterated that companies could not treat AI as a special case that sits outside the current regulations.

McCarthy Hockey said the package of findings in the letter was intended to clarify exactly how the regulator expected institutions to lift their game.

“The findings outlined in today’s letter emphasise our expectations for how entities should be managing these risks in alignment with our prudential standards in areas such as information security, operational risk management, governance and data risk,” she said.

“While we are not proposing to introduce additional requirements at this stage, we expect to see a significant improvement in how entities are closing the gaps between the power of the technology they are using and their ability to monitor and control it.”

Supervision roadmap and international context

APRA said it was finalising a multi‑year plan for how it would supervise AI‑related risks.

That roadmap is expected to combine targeted reviews at individual entities with cross‑industry work and more active engagement with AI suppliers.

The regulator also plans to increase its own use of AI‑based analytics to spot emerging prudential issues.

APRA said it was working with agencies and peer regulators offshore as authorities worldwide grapple with how models intersect with financial stability.


This story was originally published by Cyber Daily’s sister brand, The Adviser.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.