ASIC and APRA signal growing concern over AI-enabled cyber risks

Cyber Liability IT Professionals Executive & Professional Risk
Jennifer Clancy - Bellrock Advisory

Jennifer Clancy

Modern society now relies on digital infrastructure in much the same way previous generations relied on physical systems. Financial records, communications, transport networks and business operations are all built on software that is assumed to be secure and resilient. That assumption is increasingly being tested by the rapid advancement of artificial intelligence capabilities. 

In an open letter1 released on May 8th by the Australian Securities and Investments Commission (ASIC) highlighted that the rapid advancement of artificial intelligence is materially increasing the sophistication, speed and scale of cyber threats. ASIC has urged entities to act now and not wait for advanced AI tools to uplift their cyber security fundamentals and ensure their systems can withstand AI-accelerated threats. The regulator continues to emphasise the responsibility on Boards and senior management to ensure cyber resilience frameworks are effective and actively monitored. 

ASIC joins a growing chorus of Australian regulators, including the Australian Transaction Reports and Analysis Centre (AUSTRAC), the Australian Prudential Regulation Authority (APRA), the Australian Communications Media Authority (ACMA) and the Australian Competition and Consumer Commission (ACCC), which have commented on the emerging risks as businesses increasingly rely on AI systems within their day-to-day operations. 

Small weaknesses can have serious, cascading consequences

All of this comes amid the announcement of Anthropic’s Claude Mythos, a frontier model evaluated as highly capable in offensive security research. Reportedly the model was able to identify and chain together vulnerabilities across widely used operating systems and web browsers, including long-standing flaws that had persisted through years of conventional security review2 

The findings are framed as evidence of a step-change in AI-assisted vulnerability discovery, and a warning that defensive security practices may need to evolve quickly to keep pace with emerging model capabilities.3 

After the transition to the Internet in the early 2000s, the following two decades have largely reflected a relatively stable security equilibrium. While attacks have become more sophisticated, many of the underlying threat patterns remain structurally similar to those seen in the mid-2000s.  

This stability reflects the long-standing idiom that “given enough eyeballs, all bugs are shallow”, suggesting that with enough widespread review and time, software vulnerabilities are more likely to be discovered. The emergence of Mythos has the potential to disrupt that equilibrium, shifting the balance between attackers and defenders by accelerating the discovery and exploitation of vulnerabilities across systems at scale. In practice, this could lower the barrier to more scalable and automated forms of cyber activity, including ransomware campaigns, data theft for espionage purposes, and broader exploitation of weaknesses in interconnected digital infrastructure. 

AI adoption is moving fast, but governance maturity is lagging

The message from ASIC is straightforward:  

Do not wait for perfect clarity to address the threat posed by new AI models. Instead, act now, and act with discipline, to strengthen the cyber resilience fundamentals that underpin your business.  

The letter from ASIC reinforces that cyber risk management frameworks must be demonstrably effective and appropriately proportionate to the size, nature and complexity of the business. This is reinforced by the reference to ASIC’s proceedings against FIIG Securities Limited as the regulator states that it increasingly expects organisations to take an active approach to manage cyber and emerging AI-related risks.  

As outlined by ASIC Commissioner Simone Constant: 

 “appropriate cyber risk management starts at the leadership of licensees and participants. Boards and executives must ensure systems are tested, weaknesses are addressed early and that action is taken before threats can be exploited”.4

As previously noted, ASIC is not the only regulator increasing pressure on Boards in response to the changing AI risk environment. Concurrently, in a letter released by APRA6 , the regulator stated it expects Boards, at a minimum, to: 

  • Maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight. 
  • Oversee an AI strategy which is consistent with the entity’s risk appetite and tolerance settings, supported by effective monitoring and reporting (including for third party dependencies), with clearly defined triggers aligned to resilience objectives to enable timely action when not operating as expected. 

Both the ASIC Letter and the APRA Letter signal that where entities fail to adequately identify, or control AI-related risks, regulators will apply stronger supervisory action and if required, pursue enforcement. 

Cyber resilience good practice

The regulatory focus on cyber resilience is expanding well beyond APRA and ASIC. Australia’s privacy regulator, the Office of the Australian Information Commissioner (OAIC), has taken an increasingly proactive approach to organisations that fail to adequately protect personal information, particularly following major data breaches across the healthcare, telecommunications, local government and retail sectors.  

At the same time, the introduction of mandatory ransomware payment reporting obligations under recent cyber security reforms, signal a broader shift toward stricter accountability for how organisations prevent, manage, assess and disclose cyber incidents. 

In preparation for the continued release of improved frontier models with enhanced capabilities, organisations should continue to focus on good security practices. Although no mitigation strategy can provide complete protection, organisations can start by implementing a strong cyber security baseline aligned with ASD’s Information security manual (ISM) and the Essential Eight, to materially reduce cyber security risk.  

As a starting point, the ASD’s ACSC states organisations should aim to: 

  1. Reduce attack surfaces: Restrict unnecessary access and segment networks to limit pathways for compromise.  
  2. Patch continuously: Promptly patch systems and software to reduce exposure to known vulnerabilities.  
  3. Use AI for vulnerability detection: Apply AI tools and secure development practices to identify and remediate weaknesses earlier.  
  4. Implement layered security: Use multiple overlapping security controls across systems, users and networks. 

The pace and capability of AI-driven systems is accelerating faster than many existing governance and cyber security frameworks were designed to manage. Regulators are increasingly signalling that traditional approaches to operational resilience, information security and oversight may no longer be sufficient in a world where AI can identify and exploit risks rapidly. For ASIC and APRA, the expectation is that businesses must prepare now. This is no longer a future risk; it is a present-day governance challenge that will continue to intensify.

Stay informed with the latest risk trends and market updates delivered direct to your inbox each month.


Subscribe to Bellrock Insight

Stay informed with the latest risk trends and market updates delivered direct to your inbox each month


Subscribe to Bellrock Insight Illustration

Browse by category

Risk Trending

Risk Trending

Recent articles by our Team reporting on the latest trends, legislation and key events impacting insurance.

Market Updates

Market Updates

Bellrock's biannual reports on the state of the insurance market subject to risk area, insurance product and industry sector.

Product Fundamentals

Product Fundamentals

Simple guides to a range of insurance products, outlining coverage, benefits, common exclusions, and claims examples.

News & Events

News & Events

Upcoming events for clients and industry partners. Plus Important developments across our organisation