Following the publication of open letters outlining the risks and expected response, APRA and ASIC organised nine ‘Frontier AI Roundtables’, bringing together more than 600 attendees from 380 entities to discuss the problems and potential solutions surrounding frontier AI risks.
Participants comprised financial entities of all sizes, including but not limited to mortgage brokers, aggregators, and banks.
With banks spending millions on implementing AI into processing loans, handling customers, and combating fraud, APRA has previously warned that the rapid pace of AI development was outstripping the governance, risk management, and operational practices needed to manage it.
Other research has found that data systems are also not ready for the current rate of deployment.
However, while the speed of development may be the problem, particularly when assessing models such as Anthropic’s Claude Mythos, APRA’s solution was not to slow down.
APRA executive board member Therese McCarthy Hockey said: “If AI is the problem, it can also be the solution. As we race to identify and patch vulnerabilities before they can be exploited by bad actors, nothing will achieve this faster than AI – whether frontier models or the advanced models already in circulation.
“By harnessing AI to build the fire breaks we need to keep the flames from spreading, we can fight fire with fire.”
The roundtables come just months after Broker Daily broke the news that fintech platform youX had suffered a major cyber attack, compromising the personal and financial information of almost 500,000 borrowers and bringing cyber-security risks sharply into focus.
‘Collaboration critical to resistance’
APRA and ASIC said collaboration across the financial services industry would be critical to building resilience against frontier AI risks.
“This was the first time that APRA and ASIC created rapid information-sharing forums across such a broad cross-section of the financial services industry,” APRA said.
“The key message from the roundtable participants was that the financial services industry needs to move from awareness of frontier AI risk to action.”
APRA added it expected the entire industry to make clear steps not just in awareness, but in capability and responsibility in the event of an incident.
“This includes demonstrating they can respond and recover under compressed time frames while still meeting governance, cyber security, operational resilience and third-party risk management obligations,” it said.
“For critical market infrastructure providers, the roundtables highlighted the importance of enhancing the resilience of systems and processes that are relied upon by entities or groups of entities across the economy and markets more broadly.
“Frontier AI risk traverses firms, markets, providers and borders, and participants reflected that effective industry collaboration will be critical to building resilience.
“The roundtables provided an opportunity for some larger entities to actively share their insights and resources with less well-resourced and smaller entities, and APRA and ASIC welcome this ‘Team Australia’ mindset.”
Key themes emerge
The roundtables identified several areas where financial entities need to strengthen their preparedness, particularly as AI increases the speed and scale of cyber and operational risks.
- Cyber basics still matter: Participants stressed the need for strong fundamentals, including patching, access controls, monitoring, reliable backups, and tested recovery plans. Legacy systems were also flagged as a potential vulnerability.
- Governance needs to be clear: Boards are increasingly engaging with AI risks, but participants said firms need clear incident plans, escalation triggers, and decision-making responsibilities before a crisis hits.
- Defensive AI has potential: Participants highlighted opportunities to use AI for threat intelligence, vulnerability detection, code review, and incident response, but said it should not replace strong cyber controls, testing, and human oversight.
- Third parties could spread disruption: Reliance on cloud providers, software services, AI model providers, payments infrastructure, and telecommunications could see an incident at one organisation have broader consequences.
- Collaboration matters: Participants highlighted the need for industry-wide information sharing around threats, suppliers, and incident response. APRA also said larger entities were willing to share insights and resources with smaller and less mature businesses.
A new AI framework
Separately, a recent survey by the UTS Human Technology Institute (HTI) found that 93 per cent of financial services respondents reported using AI, with the remainder planning on doing so, but less than half had conducted risk assessments on their internal use of the technology.
The survey formed part of a new framework developed by the Actuaries Institute and HTI to help financial services organisations identify, assess, and manage AI risks.
The resource, AI Risk Management in the Financial Services Sector, is designed to sit within existing enterprise risk management structures rather than replace them, providing an AI-specific overlay for the risks created or amplified by the technology.
The framework is built around four areas: governance, classification, quantification, and controls.
Governance focuses on who is accountable for AI risks, while classification considers how those risks should be categorised and reported. Quantification looks at how organisations can estimate the likelihood and financial impact of AI-related loss events, while controls are intended to help organisations determine which safeguards are appropriate for different AI use cases.
Rather than providing a one-size-fits-all checklist, the framework is designed to be adapted to an organisation’s size, maturity, AI deployment, and risk appetite.
Actuaries Institute co-lead author Victor Bajanov said that managing AI risk needed to be “more than a tick-box exercise”.
“The financial services sector has well-established processes for managing traditional risks, but AI creates a vastly different risk profile, meaning organisations need to go back to first principles when deciding how to manage AI risks and assign responsibility for oversight,” he said.
HTI co-director Professor Nicholas Davis said getting the approach right for financial services was crucial due to its far-reaching impact.
“As AI becomes increasingly embedded in these decisions and services, effective risk management and governance are vital to maintaining trust and confidence in the sector,” he said.
“This collaboration between the Actuaries Institute and UTS HTI brings together deep expertise in financial risk management and human-centred AI governance to help the sector respond to the opportunities and risks presented by AI.”
[Related: Is AI coming for brokers? Industry weighs impact]
Want to see more stories from trusted news sources?Make Broker Daily a preferred news source on Google.