APRA letter to industry on artificial intelligence
The prudential regulator's April 2026 letter setting out what it expects of banks, insurers and superannuation trustees as they adopt AI. Binding in practice for APRA-regulated entities; a useful benchmark for everyone else.
- Status
- In force · Australia (Commonwealth) · APRA
- Applies to
- APRA-regulated entities: banks, insurers, superannuation trustees. Not other businesses.
- Key date
- 30 April 2026: Letter published
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
A letter from APRA to every entity it regulates, dated 30 April 2026, reporting what it found when it looked at how banks, insurers and superannuation trustees are adopting AI, and setting out what it expects them to do about it. It is not a new prudential standard. APRA says its framework is technology and vendor agnostic and that the existing standards already apply to AI risk. The letter tells regulated entities how APRA will read those standards when AI is involved, and warns that it will take stronger supervisory action, and enforcement where appropriate, where AI risks are not managed.
What it requires
APRA’s findings are blunt: adoption is accelerating and governance is lagging. It found information security gaps (new attack paths such as prompt injection and data leakage, identity and access controls that do not account for AI agents), governance that treats AI as “just another technology” and misses its adaptive behaviour and bias, heavy dependence on single suppliers with opaque upstream dependencies, and assurance that is point-in-time rather than continuous.
Against that, the letter sets expectations at two levels. Boards must “maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight”, and must oversee an AI strategy consistent with the entity’s risk appetite, with monitoring, reporting and clearly defined triggers for action when AI is not operating as expected. Management must actively manage AI-specific security vulnerabilities, put in place “frameworks (policy, standard, guidance) and reporting lines to promote safe, responsible and sustainable adoption of AI” with clear ownership across the AI lifecycle and staff training, keep “visibility over the full AI supply chain, including material, third-party and fourth-party dependencies”, and run assurance using recognised control frameworks with continuous monitoring proportionate to how critical each use is. No deadlines are set; APRA says it is finalising its supervisory plan and invites early engagement where an entity has heightened concerns.
Does this reach your business?
Only if APRA regulates you: an authorised deposit-taking institution, a general, life or private health insurer, or a registrable superannuation entity. If you are one of those, treat the letter as the standard your next supervisory conversation about AI will be measured against. If you are not, it does not bind you, but it is the clearest statement any Australian regulator has made about what good AI governance looks like, and it maps closely onto what a customer in financial services will ask of its suppliers.
What we recommend
For a regulated entity, our advice is to start with the two things APRA can check quickly: a board that can show it understands the AI the business uses, and a named owner for every AI system across its lifecycle. Then work through the four gaps the letter names, in order: an inventory of AI systems and their suppliers (including who sits behind the supplier), controls for AI-specific attack paths, monitoring that runs continuously rather than at sign-off, and a fallback for any critical operation that AI supports. For a business outside APRA’s reach that sells to one, our advice is to expect these questions in due diligence and to keep the same record: what AI you use, who owns it, what it touches, and how you would know if it misbehaved.
Questions people ask
No. It is a letter setting out how APRA expects existing standards to be applied to AI. It creates no new rule, but APRA says it will act on the expectations through supervision and, where appropriate, enforcement.
Banks and other authorised deposit-taking institutions, general, life and private health insurers, and superannuation trustees. It does not apply to businesses outside APRA's remit.
No. APRA says it is finalising its forward supervisory plan and encourages entities with heightened AI concerns to engage its Non-Financial Risk team early.
Understand the AI the entity uses well enough to challenge management, approve an AI strategy that fits the entity's risk appetite, and oversee monitoring and reporting with defined triggers for action when AI stops behaving as expected.