Regulator letters are usually easy to file and forget. This one is built not to be, for three reasons you can read in its own text: it names a court judgment as the operating standard, it lists what boards must be able to evidence, and it closes with an instruction: "Please ensure this letter is tabled and discussed at your ultimate board and risk governance committees."
The claim: not new risk, more pressure on old controls
The letter opens with a careful framing that is worth quoting precisely, because it is neither hype nor comfort: "The rapid evolution of frontier artificial intelligence models marks a significant shift in the cyber threat landscape... This does not mean entirely new categories of risk, but it does mean existing controls are more likely to be tested, more often, and under greater pressure." And then, plainly: "This is not a distant or hypothetical risk. It is here now."
The mechanism ASIC describes is aggregation: "a 'simple' phishing email can now more easily provide access to critical platforms or sensitive data", and weaknesses that were individually remote from harm "can now more readily be drawn together with other weaknesses into an incident."
The standard: FIIG is the anchor
The letter's legal spine is one sentence: "As set out in the court's judgment in ASIC's case against FIIG Securities Limited, cyber risk management must be demonstrably effective and proportionate to the size, nature and complexity of a business." That is the significant move. An open letter creates no new law, but this one points at existing law plus a live enforcement precedent and tells licensees the two together already cover AI-accelerated threats. A licensee that files this letter and does nothing has been told, in writing, what "demonstrably effective" will be measured against.
The twelve actions, and the four things boards must show
The letter lists twelve expected steps, verbatim in the document, summarised here: reassess cyber plans against today's threats; confirm risk frameworks handle cumulative, interrelated vulnerabilities at decision-making pace; identify and protect critical assets; validate core controls regularly; minimise attack surfaces; review user access and privileges (with a specific warning that "insider threats are increasing"); patch promptly, "recognising that AI is accelerating vulnerability discovery and exploitation"; strengthen patch management processes; build "layered, defence-in-depth architectures that assume breach"; maintain and exercise incident response plans; "actively manage third-party risks, particularly where services introduce concentration or systemic exposure"; and "use AI for defensive purposes, where appropriate".
For boards, the letter is specific about the evidentiary posture: directors are expected to be "satisfied that cyber resilience measures are proportionate", to ensure capability is "adequately resourced, prioritised and qualified", to receive "meaningful reporting on end-to-end control effectiveness, not just activity", and to oversee how AI risks are entering the risk framework. Then the line that turns governance theatre into a compliance question: "Governance should not rely only on assurances. It should be supported by evidence - test results, audit findings, lessons from incidents, and independent validation."
The context: two regulators, eight days apart
ASIC's letter did not arrive alone. Eight days earlier, on 30 April, APRA issued its own Letter to Industry on Artificial Intelligence, based on engagement with large banks, insurers and super trustees in late 2025. APRA's findings rhyme with ASIC's concerns: "many Boards are still developing the technical literacy required to provide effective challenge on AI related risks", "AI adoption is materially changing the cyber threat landscape", and "assurance practices are not keeping pace with the scale, speed and complexity of AI", including entities "heavily dependent on a single provider for multiple AI use cases". ASIC's letter points readers to APRA's, and both point to the Australian Signals Directorate's guidance on frontier models at cyber.gov.au. Two conduct-and-prudential regulators independently escalating the same message in the same fortnight is itself information: this is now the coordinated supervisory position, not one commissioner's enthusiasm.
What to do with this if you hold a licence
The letter's own closing is the practical answer, and it is more modest than the headlines it generated: "The time to act is now, not by reinventing your approach, but by ensuring the basics are robust, resourced, and working effectively." Table the letter, map the twelve actions against your current controls, and make sure the board pack contains evidence rather than assertions. The regulator has told you the test in advance. Few exams come with the marking guide attached.