AI Regulation Tracker · APRA / ASIC · Letter

What does APRA AI Letter to Industry (April 2026) say about AI in banking?

Published Apr 30, 2026 · Last reviewed Oct 5, 2026

APRA's Letter to Industry on Artificial Intelligence, published on 30 April 2026 and addressed to all APRA-regulated entities, calls for a step-change in how banks, insurers and superannuation trustees manage AI-related risk. Based on a targeted engagement with selected large entities in late 2025, APRA found that AI adoption is accelerating but governance, risk management, assurance and operational resilience practices are not keeping pace. It sets minimum expectations for boards (AI literacy, a risk-appetite-aligned AI strategy with third-party monitoring) and for executives on information security, governance, supplier risk and assurance. APRA says its framework is technology and vendor agnostic, no new standard was issued, and entities that fail to manage AI risks proportionately will face stronger supervisory action and, where appropriate, enforcement.

OFFICIAL TEXT: apra.gov.au ↗ · FINAL · APRA / ASIC

DocumentAPRA AI Letter to Industry (April 2026) — APRA Letter to Industry on Artificial Intelligence (AI)
Issued byAustralian Prudential Regulation Authority and Australian Securities and Investments Commission
TypeLetter
StatusFinal
PublishedApr 30, 2026
Applies toAll APRA-regulated entities: banks (ADIs), insurers and superannuation trustees. The observations come from a targeted engagement with a group of selected large banks, insurers and superannuation trustees in late 2025, published for the benefit of all regulated entities. The letter is guidance based on observations; the binding requirements are in APRA's prudential standards
Official sourceapra.gov.au ↗
Use casesAI governance (general) · Third-party & vendor AI · Cybersecurity · Model risk management · Generative & agentic AI · AI-generated code & coding agents

What are the key points of APRA AI Letter to Industry (April 2026)?

  • Evidence base: a targeted engagement on selected large banks, insurers and superannuation trustees in late 2025; the letter's attachment is an 'AI Supervisory Engagement Debrief: Observations for Executive Management'.
  • Boards: APRA observed many boards still developing the technical literacy to challenge AI risk and an overreliance on vendor presentations and summaries; it expects boards at a minimum to maintain sufficient AI literacy and oversee an AI strategy consistent with risk appetite and tolerance, with monitoring and reporting including third-party dependencies and clear triggers.
  • Information security: attack pathways include prompt injection, data leakage, insecure integrations, exploit injection and manipulation of autonomous AI agents; identity and access management has not yet adjusted to non-human actors, and AI-assisted development strains change and release controls.
  • Governance: few entities have operationalised governance for AI; APRA expects frameworks and reporting lines, ownership across the AI lifecycle, an inventory of AI tooling and use cases, human involvement for high-risk decisions, and staff training.
  • Suppliers: some entities depend heavily on a single provider for multiple AI use cases and few had tested exit and substitution; APRA expects mapping of the full AI supply chain including third and fourth parties, contractual transparency and auditability, and active concentration risk management.
  • Assurance: point-in-time and sample-based methods are ill suited to probabilistic models that learn, adapt and degrade; APRA expects integrated assurance, technically capable second-line and internal audit functions, and continuous monitoring proportionate to criticality.
  • Supervision: APRA is finalising a forward plan for AI supervision covering entity prudential reviews, thematic activities and AI supplier engagement, and says it will consider whether further policy action is needed.
  • Enforcement: where entities fail to identify, manage or control AI risks proportionately to size, scale and complexity, 'we will take stronger supervisory action and, where appropriate, pursue enforcement'; the letter was signed by APRA Member Therese McCarthy Hockey.

What did APRA AI Letter to Industry (April 2026) change for banks?

It introduced no new standard but converted existing technology-neutral requirements (chiefly CPS 230 on service providers and operational resilience and CPS 234 on information security) into specific supervisory expectations for AI, and put banks on notice that AI supervision, including engagement with AI suppliers, is being built. It preceded APRA and ASIC's joint frontier AI roundtables, summarised in a media release on 27 August 2026.

What does APRA expect of banks managing AI risk?

APRA's 30 April 2026 letter expects banks to manage AI risk within existing prudential standards across five areas. Boards must hold enough AI literacy to challenge and oversee an AI strategy that fits risk appetite and covers third-party dependencies. Information security must address AI-specific attack paths, with privileged access management, timely patching, security testing of AI-generated code and controls over agentic workflows. Governance must include frameworks, lifecycle ownership, an inventory of AI tools and use cases, human involvement in high-risk decisions and staff training. Supplier risk management must map the whole AI supply chain including fourth parties, secure contractual transparency and manage concentration and exit. Assurance must be integrated and continuous, with second-line and internal audit capable of assessing probabilistic and agentic systems. APRA says it will take stronger supervisory action and, where appropriate, pursue enforcement.

RuleAuthorityWhat it requiresApplies
Board expectationsAPRA / ASICMaintain sufficient AI literacy to set direction and challenge, and oversee an AI strategy consistent with risk appetite and tolerance, with monitoring and reporting including third-party dependencies and clear triggers for action.Published 30 April 2026
Information security expectationsAPRA / ASICAssess implications of AI reliance for resilience, with credible fallback where AI supports critical operations; deploy controls for AI-specific attack paths; test AI-generated code, components and libraries; consider third-party and concentration implications.Published 30 April 2026
Governance expectationsAPRA / ASICMaintain AI frameworks and reporting lines, lifecycle ownership and accountability, an inventory of AI tooling and use cases, human involvement in high-risk decisions, and staff training on use, misuse, limitations and secure practice.Published 30 April 2026
Supplier risk expectationsAPRA / ASICMap the full AI supply chain including material, third-party and fourth-party dependencies; secure contractual transparency, auditability and assurance; manage concentration, substitution, portability and exit for critical AI providers.Published 30 April 2026
Assurance expectationsAPRA / ASICUse recognised control frameworks and change control, integrated assurance across cyber, data, model, resilience, privacy and conduct risks, technically capable second line and internal audit, and continuous monitoring proportionate to criticality.Published 30 April 2026
Supervisory consequencesAPRA / ASICEntities that fail to identify, manage or control AI risks proportionately face stronger supervisory action and, where appropriate, enforcement; APRA is finalising its AI supervision plan.Published 30 April 2026
CPS 230 Operational Risk ManagementAPRA / ASICThe binding standard on service providers, critical operations and business continuity that underpins the supplier and resilience expectations.In force since 1 July 2025
CPS 234 Information SecurityAPRA / ASICThe binding standard on information assets, testing and 72-hour incident notification that underpins the security expectations.In force since 1 July 2019

The letter is APRA's way of saying AI does not need a new standard to be supervised. Most entities, APRA found, recognise that existing prudential standards apply to AI risk but few have operationalised that, and many treat AI as 'just another technology', missing the distinct characteristics of predictive systems, adaptive model behaviour, bias, and privacy and data risks. Weak controls were found over post-deployment monitoring, model behaviour monitoring, change management and decommissioning of AI capabilities.

APRA also states that it is engaging across the sector on the potential for increased cyber threats from high-capability frontier AI models, has been engaged with the Council of Financial Regulators and government agencies, and refers entities to current Australian Signals Directorate advice on frontier models. That thread continued in the joint APRA-ASIC statement of 27 August 2026, which reports nine industry roundtables in June and July 2026 attended by more than 600 people.

ASIC's REP 798 covers the conduct and consumer side of the same governance-gap theme. APRA's letter is the prudential side, concentrated on boards, executives and cyber and supplier resilience.

WHAT THIS MEANS IN PRACTICE

  • Brief the board with an AI-risk pack covering the strategy, risk-appetite alignment, third-party dependency reporting and triggers; avoid relying on vendor presentations alone.
  • Build and maintain an inventory of AI tooling and use cases, with named owners across design, deployment, monitoring and decommissioning.
  • Replace policy-only controls on staff use of enterprise AI tools with enforceable technical restrictions and preventative controls.
  • Map AI supply chains to fourth parties, test exit and substitution for critical AI providers, and review contracts for audit rights, model updates, incident notification and data-handling changes.
  • Upskill second-line risk and internal audit so they can assess probabilistic models and agentic workflows, and move from point-in-time sampling to continuous validation.

Is the APRA AI letter binding?

The letter is guidance that outlines observations and APRA's expectations; it does not create new prudential requirements. APRA says its principle-based prudential framework is technology and vendor agnostic and that entities must ensure appropriate risk management of AI within it, and that where entities fail to do so it will take stronger supervisory action and, where appropriate, pursue enforcement.

Does the APRA AI letter apply to banks?

Yes. It is addressed to all APRA-regulated entities, including banks, insurers and superannuation trustees. The observations come from large entities in all three sectors, and APRA says lessons from them will help entities earlier in their AI adoption.

What does APRA expect of boards on AI?

At a minimum, boards should maintain sufficient understanding and literacy of AI to set strategic direction and provide effective challenge and oversight, and oversee an AI strategy consistent with risk appetite and tolerance settings. That strategy should be supported by monitoring and reporting, including on third-party dependencies, with clearly defined triggers aligned to resilience objectives.

Which APRA standards underpin the AI letter?

The letter does not list paragraph references, but its supplier, resilience and security expectations map to CPS 230 Operational Risk Management (service providers, critical operations, business continuity) and CPS 234 Information Security. It also notes APRA's engagement with the Council of Financial Regulators and government agencies and refers entities to Australian Signals Directorate advice on frontier AI models.

DateDocumentStatus
Oct 29, 2024ASIC REP 798 — REP 798 Beware the gap: Governance arrangements in the face of AI innovationFinal
Jul 17, 2023APRA CPS 230 — Prudential Standard CPS 230 Operational Risk ManagementIn force
Nov 30, 2018APRA CPS 234 — Prudential Standard CPS 234 Information SecurityIn force
Sep 30, 2026SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act)Final
Sep 30, 2026Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew BaileyFinal
Sep 28, 2026AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act)Final

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning