Regulator letters are usually easy to file and forget. This one is built not to
be, for three reasons you can read in its own text: it names a court judgment as
the operating standard, it lists what boards must be able to evidence, and
it closes with an instruction: Please ensure this letter is tabled and discussed
at your ultimate board and risk governance committees.
The claim: not new risk, more pressure on old controls
The letter
opens with a careful framing that is worth quoting precisely, because it is
neither hype nor comfort: The rapid evolution of frontier artificial intelligence
models marks a significant shift in the cyber threat landscape... This does not
mean entirely new categories of risk, but it does mean existing controls are more
likely to be tested, more often, and under greater pressure.
And then, plainly:
This is not a distant or hypothetical risk. It is here now.
The mechanism ASIC describes is aggregation: a 'simple' phishing email can now
more easily provide access to critical platforms or sensitive data
, and
weaknesses that were individually remote from harm can now more readily be drawn
together with other weaknesses into an incident.
The standard: FIIG is the anchor
The letter's legal spine is one sentence: As set out in the court's judgment
in ASIC's case against FIIG Securities Limited, cyber risk management must be
demonstrably effective and proportionate to the size, nature and complexity of a
business.
That is the significant move. An open letter creates no new law, but
this one points at existing law plus a live enforcement precedent and tells
licensees the two together already cover AI-accelerated threats. A licensee that
files this letter and does nothing has been told, in writing, what "demonstrably
effective" will be measured against.
The twelve actions, and the four things boards must show
The letter lists twelve expected steps, verbatim in the document, summarised
here: reassess cyber plans against today's threats; confirm risk frameworks handle
cumulative, interrelated vulnerabilities at decision-making pace; identify and
protect critical assets; validate core controls regularly; minimise attack
surfaces; review user access and privileges (with a specific warning that "insider
threats are increasing"); patch promptly, recognising that AI is accelerating
vulnerability discovery and exploitation
; strengthen patch management processes;
build layered, defence-in-depth architectures that assume breach
; maintain and
exercise incident response plans; actively manage third-party risks, particularly
where services introduce concentration or systemic exposure
; and use AI for
defensive purposes, where appropriate
.
For boards, the letter is specific about the evidentiary posture: directors are
expected to be satisfied that cyber resilience measures are proportionate
, to
ensure capability is "adequately resourced, prioritised and qualified", to receive
meaningful reporting on end-to-end control effectiveness, not just activity
, and
to oversee how AI risks are entering the risk framework. Then the line that turns
governance theatre into a compliance question: Governance should not rely only on
assurances. It should be supported by evidence - test results, audit findings,
lessons from incidents, and independent validation.
The context: two regulators, eight days apart
ASIC's letter did not arrive alone. Eight days earlier, on 30 April, APRA
issued its own Letter
to Industry on Artificial Intelligence, based on engagement with large banks,
insurers and super trustees in late 2025. APRA's findings rhyme with ASIC's
concerns: many Boards are still developing the technical literacy required to
provide effective challenge on AI related risks
, AI adoption is materially
changing the cyber threat landscape
, and assurance practices are not keeping
pace with the scale, speed and complexity of AI
, including entities heavily
dependent on a single provider for multiple AI use cases
. ASIC's letter points
readers to APRA's, and both point to the Australian Signals Directorate's guidance
on frontier models at cyber.gov.au. Two
conduct-and-prudential regulators independently escalating the same message in the
same fortnight is itself information: this is now the coordinated supervisory
position, not one commissioner's enthusiasm.
What to do with this if you hold a licence
The letter's own closing is the practical answer, and it is more modest than
the headlines it generated: The time to act is now, not by reinventing your
approach, but by ensuring the basics are robust, resourced, and working
effectively.
Table the letter, map the twelve actions against your current
controls, and make sure the board pack contains evidence rather than assertions.
The regulator has told you the test in advance. Few exams come with the marking
guide attached.