# How does the APRA / ASIC regulate AI in banking?

Source: https://www.bankingnewsai.com/ai-regulation/australia
Last updated: Oct 5, 2026

Australia has no AI-specific statute or prudential standard for banks. APRA applies binding technology-neutral standards, CPS 230 Operational Risk Management (in force since 1 July 2025, amended text from 1 July 2026) and CPS 234 Information Security (since 1 July 2019), and in a letter to industry on 30 April 2026 called for a step-change in AI risk management and said it will take stronger supervisory action and, where appropriate, pursue enforcement. ASIC's Report 798 (29 October 2024) found a governance gap at licensees adopting AI and reminded them that existing obligations are technology neutral. APRA and ASIC jointly ran frontier AI roundtables in June and July 2026 and urged entities on 27 August 2026 to move from awareness to action.

## At a glance

| Field | Value |
| --- | --- |
| Full name | Australian Prudential Regulation Authority and Australian Securities and Investments Commission |
| Jurisdiction | Australia (APRA: authorised deposit-taking institutions, insurers and superannuation trustees; ASIC: financial services and credit licensees) |
| Role | Australia's prudential regulator (APRA) and conduct regulator (ASIC), supervising AI in banks through technology-neutral standards and supervisory letters rather than an AI-specific law |
| How binding | Supervisory guidance |
| Applies to | APRA-regulated entities (banks, insurers and superannuation trustees) under binding prudential standards CPS 230 and CPS 234; AFS and credit licensees under ASIC's conduct regime. APRA's April 2026 AI letter and ASIC's REP 798 are guidance and review findings, not new rules |
| Key document | APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026, with the binding standards CPS 230 (Operational Risk Management) and CPS 234 (Information Security) and ASIC Report 798 (29 October 2024) |
| Latest move | On 27 August 2026 APRA and ASIC urged financial entities to move from awareness of frontier AI risks to decisive action after nine roundtables in June and July 2026; on 30 April 2026 APRA's AI letter called for a step-change in AI risk management and the amended CPS 230 took effect on 1 July 2026 |

## Overview

APRA's AI position is set out in its April 2026 letter to all APRA-regulated entities, based on a targeted engagement with large banks, insurers and superannuation trustees in late 2025. It describes its prudential framework as technology and vendor agnostic and sets expectations for boards (AI literacy and an AI strategy aligned to risk appetite) and for executives on information security, governance, supplier concentration and assurance. The binding hooks are CPS 230, which regulates operational risk, critical operations and material service providers including fourth parties, and CPS 234, which requires information security capability and 72-hour incident notification for information assets, including those managed by third parties.

ASIC approaches AI as a conduct and consumer-outcomes question. REP 798 analysed 624 AI use cases at 23 licensees and found governance arrangements lagging AI use at some, with heavy reliance on third-party models. ASIC says licensees' general obligations, consumer protection provisions and directors' duties are technology neutral and apply to AI. The two regulators now act together on cyber: their media release of 27 August 2026 reports nine roundtables with more than 600 attendees on frontier AI and cyber resilience, with an information paper and board preparedness checklist on APRA's website.

## Documents (4)

- Apr 30, 2026 — [APRA AI Letter to Industry (April 2026)](https://www.bankingnewsai.com/ai-regulation/documents/apra-letter-industry-ai-2026): APRA Letter to Industry on Artificial Intelligence (AI) (Final)
- Oct 29, 2024 — [ASIC REP 798](https://www.bankingnewsai.com/ai-regulation/documents/asic-rep-798): REP 798 Beware the gap: Governance arrangements in the face of AI innovation (Final)
- Jul 17, 2023 — [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230): Prudential Standard CPS 230 Operational Risk Management (In force)
- Nov 30, 2018 — [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234): Prudential Standard CPS 234 Information Security (In force)

## Timeline

- Aug 27, 2026 — [APRA and ASIC urge action on frontier AI after industry roundtables](https://www.apra.gov.au/news-and-publications/apra-and-asic-warn-frontier-ai-awareness-must-turn-action) — Following nine roundtables in June and July 2026 with more than 600 attendees, the regulators urged financial entities to move from awareness to decisive action on frontier AI risks, highlighting cyber fundamentals, board-level decisions before a crisis, defensive AI and third-party concentration risk.
- Jul 1, 2026 — [Amended CPS 230 and CPG 230 commence](https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-cps-230-operational-risk-management) — The updated CPS 230 and CPG 230 commence on 1 July 2026, with an updated Material Service Provider Register template for the 2026 submission.
- Apr 30, 2026 — [APRA finalises targeted amendments to CPS 230](https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-cps-230-operational-risk-management) — APRA finalised amendments to CPS 230, CPG 230 and the Material Service Provider Register template introducing limited exemptions from specific contractual requirements for material arrangements with certain categories of non-traditional service providers, such as central banks and clearing and settlement facilities.
- Apr 30, 2026 — [APRA AI Letter to Industry (April 2026)](https://www.bankingnewsai.com/ai-regulation/documents/apra-letter-industry-ai-2026): APRA AI Letter to Industry (April 2026) — APRA Letter to Industry on Artificial Intelligence (AI) — APRA's Letter to Industry on Artificial Intelligence, published on 30 April 2026 and addressed to all APRA-regulated entities, calls for a step-change in how banks, insurers and superannuation trustees manage AI-related risk.
- Oct 29, 2024 — [ASIC REP 798](https://www.bankingnewsai.com/ai-regulation/documents/asic-rep-798): ASIC REP 798 — REP 798 Beware the gap: Governance arrangements in the face of AI innovation — ASIC Report 798, 'Beware the gap: Governance arrangements in the face of AI innovation', released on 29 October 2024, is the Australian Securities and Investments Commission's first examination of how financial services and credit licensees use AI where it affects consumers.
- Jul 17, 2023 — [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230): APRA CPS 230 — Prudential Standard CPS 230 Operational Risk Management — CPS 230 Operational Risk Management is the Australian Prudential Regulation Authority's binding prudential standard on operational risk, business continuity and service providers.
- Nov 30, 2018 — [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234): APRA CPS 234 — Prudential Standard CPS 234 Information Security — CPS 234 Information Security is APRA's binding prudential standard requiring banks and other APRA-regulated entities to maintain an information security capability commensurate with the size and extent of threats to their information assets.

## What to watch next

- APRA's forward plan for AI supervision, which the April 2026 letter says is being finalised and will cover entity prudential reviews, thematic activities and AI supplier engagement, and whether APRA decides further policy action is needed
- Supervisory follow-up on the letter's expectations for boards and executives on AI literacy, AI supply-chain mapping, concentration and exit planning, and continuous assurance
- Further APRA-ASIC work on frontier AI and cyber resilience, building on the August 2026 roundtable information paper and board preparedness checklist
- Australian Government AI-specific regulation, to which ASIC said in REP 798 it would contribute, and how licensees embed any future obligations

## FAQ

### Does Australia have AI rules for banks?

There is no AI-specific statute or prudential standard for banks. APRA applies technology-neutral binding standards (CPS 230 on operational risk and service providers, CPS 234 on information security) and its April 2026 letter sets AI expectations on top of them. ASIC applies the existing conduct framework and set out its findings in REP 798.

### Is the APRA AI letter binding?

No. It outlines observations and expectations. APRA says its framework is technology and vendor agnostic and that where entities fail to manage AI risks proportionately it will take stronger supervisory action and, where appropriate, pursue enforcement.

### What is the difference between APRA and ASIC on AI?

APRA is the prudential regulator, focused on resilience, operational risk, information security and supplier risk at banks, insurers and superannuation trustees. ASIC is the conduct regulator, focused on how licensees' AI use affects consumers and compliance with licensee obligations, consumer protection law and directors' duties.

Related authorities: [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi), [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk), [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act), [FSB](https://www.bankingnewsai.com/ai-regulation/fsb), [Basel Committee](https://www.bankingnewsai.com/ai-regulation/basel-committee).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/australia
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
