APRA's New Plan Asks Two AI Questions. Your Register Answers One., practitioner guidance from TheAICommand
← GRC
Regulatory analysis

APRA's New Plan Asks Two AI Questions. Your Register Answers One.

APRA published its 2026-27 Corporate Plan on 20 August 2026. Under a single supervision priority it puts AI in two places, under two separate headings, meaning two different things. Most AI risk registers are built to answer only the first of them, and the second arrives with a dated cryptography deadline attached.

·monthly

GRC content. Written for compliance, risk, and audit professionals in Australian financial services. General information. Not legal or compliance advice.

Quick answer

APRA's 2026-27 Corporate Plan, published 20 August 2026, makes AI and cyber resilience one of five prudential outcomes. Under it sit two separate headings: responsible adoption of AI, and cyber risks posed by frontier AI and quantum computing. They need different evidence. Build a second column for the threat side, and diarise the post-quantum planning date.

Your AI register describes your AI. Not theirs.

On 20 August 2026 the Australian Prudential Regulation Authority published its 2026-27 Corporate Plan. Buried in the supervision agenda is a structural choice worth more than the headline: APRA puts AI in two places, under two separate sub-headings, sitting under one prudential outcome. They are not two descriptions of the same problem. They are two different questions, and they call for two different sets of evidence.

Most AI governance functions in Australian financial services are built to answer the first one. The second is the one supervision is stepping up.

What is actually in the plan?

The plan sets out APRA's strategic priorities for the next four years, and under those objectives the specific policy, supervision and data initiatives planned for the next 12 to 24 months. Three strategic objectives frame it: maintaining financial safety and stability, getting the balance right, and improving APRA's organisational effectiveness.

Beneath the first, APRA names five prudential outcomes for 2026-27. The first listed is to "strengthen operational resilience in response to AI and cyber risks". The section under that heading opens with Prudential Standard CPS 230 Operational Risk Management, which commenced on 1 July 2025, then adds the sentence practitioners should read twice:

"This year, entities should expect more frequent and deeper engagement from APRA on cyber and AI risks in our supervisory interactions. APRA expects that entities will be readily able to demonstrate how risks are being managed."

Readily able to demonstrate is not the same as able to demonstrate. It describes evidence that exists in retrievable form before the question is asked.

Then comes the split. Under the sub-heading "Entity resilience", the plan sets out two further sub-headings.

The first, "Responsible adoption of AI", carries forward APRA's letter to industry on artificial intelligence of 30 April 2026. It states that AI can improve efficiency and innovation but can also create new risks and expose weaknesses in governance and control frameworks, and that APRA expects entities using AI to strengthen governance, risk management, operational resilience and board oversight.

The second is titled "Cyber risks posed by frontier AI and quantum computing". It opens: "Rapid advances in frontier AI capabilities require an urgent strengthening in technology and cyber resilience." It records that in June 2026 APRA, ASIC and the Australian Signals Directorate met with industry to discuss the changing threat environment. It then commits APRA, during 2026-27, to focus on "ensuring entities strengthen their resilience to AI-enabled cyber threats", expecting entities to maintain effective cyber controls as threats evolve, improve board oversight of technology and cyber risk, and participate in industry information-sharing.

APRA and ASIC have since published the public notes of two joint superannuation CEO roundtables held on 24 and 30 June 2026, released on 1 September 2026. The notes record broad recognition that AI is accelerating the speed, scale and sophistication of existing cyber threats, and that organisational maturity, including board engagement and director capability, varies across organisations. They are superannuation-specific, and they read as the threat half of the question rather than the adoption half.

Two questions under one supervision heading, the AI an entity adopts and the AI aimed at it
One prudential outcome, two supervisory questions, two different evidence sets.

Chair John Lonsdale's framing in the accompanying media release keeps both halves in view. The plan, he said, is "focused on strengthening industry's resilience to geopolitical tensions, cyber-attacks and frontier AI, growing interconnections across the financial sector and an increased reliance on service providers".

Why does the split matter to a compliance function?

Because an AI risk register cannot answer the second question, and quietly pretends it can.

Registers are asset inventories. They list models, vendors, use cases, owners, approval status and review dates, because that is the natural shape for an inventory of technology an organisation has chosen. Everything about the adoption question fits that structure. Almost nothing about the threat question does.

The facts that matter on the threat side are capability held outside the organisation, and controls that already exist inside it but were never filed under AI: identity and access management, email and payment verification, detection tuning, incident escalation, third-party assurance. Ask an AI governance forum how the organisation is placed against AI-enabled social engineering and the honest answer is usually that the controls sit elsewhere and the forum has never seen them.

That is not a failure of diligence. It is a filing problem, and it becomes a supervisory problem the moment a single conversation covers both halves.

The questionWhat it is aboutThe evidence a supervisor can be handed
Responsible adoption of AIGovernance of the AI the entity has chosen to useUse case inventory, approval records, model and vendor assurance, board reporting, control testing over AI-supported processes
Cyber risks posed by frontier AIResilience to AI capability held by an adversaryControl effectiveness against AI-assisted phishing, voice and video impersonation, verification steps for payment and identity changes, detection tuning evidence, incident exercises, information-sharing participation
Quantum computing riskCryptographic agility over a long horizonA dated transition plan, a cryptographic inventory, prioritised critical systems, progress reporting against milestones

The third row is the one nobody expects to find in an AI paper, and APRA has put it in the same sub-heading.

What are the quantum dates?

APRA states it will increase its focus on quantum computing risks, records that the ASD has recommended organisations have a plan to transition to post-quantum cryptography by the end of 2026 and begin implementing that plan by the end of 2028, and says APRA expects entities to make timely progress, prioritising their most critical information assets and operations.

The ASD's own published milestones run one step further. As at 18 September 2026, ASD's guidance recommends that by the end of 2026 organisations have a refined plan for their transition, accounting for security goals, risk tolerances, dependencies and the value of their data; by the end of 2028 that they have commenced the transition, starting with critical systems and data; and by the end of 2030 that they have completed it. ASD's Information Security Manual recommends ceasing the use of traditional asymmetric cryptography by the end of 2030.

A single timeline with three markers for the post-quantum cryptography milestones
Plan by end of 2026. Commence by end of 2028. Complete by end of 2030.

Read the first milestone against the calendar. As at 18 September 2026 the planning date is a little over three months away, and it is a planning milestone rather than an implementation one, which means it is achievable and also easy to miss quietly. Nothing fails on 31 December 2026. The exposure is that the next supervisory conversation about technology risk has a dated recommendation in it and no plan on your side of the table.

This is not an AI problem wearing a different hat, and it should not be managed as one. It shares a sub-heading with AI because both are technology risks moving faster than the controls built for them, not because the underlying problem is the same. What it shares practically is the audience: the same executives and the same board committee.

How is this different from AI cyber risk being a board issue?

That earlier proposition, that AI cyber risk belongs in front of the board, is about elevation. It concerns who is accountable and what reaches the board pack.

This is about separation. Elevating a single item labelled AI risk to the board is compatible with answering only half the question, and a board pack that discusses model governance, vendor concentration and use case approval can look complete while saying nothing about whether AI-assisted impersonation would defeat the payment verification process. The plan's own structure supplies the correction, because it declines to run the two together.

The related discipline that already exists in most functions is third-party assurance. Due diligence on AI vendors under CPS 234 and the contract remediation deadline that CPS 230 imposed on material arrangements both live on the adoption side of the line. They are necessary and they are not responsive to the threat question, which is worth saying plainly inside the function before a supervisor says it.

What should be built, and what should be left alone?

Build a second evidence set, not a bigger register.

TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened. Applied here, the model's job is to read the plan and your existing control documentation and produce a mapping. The judgement about whether a control is effective against an AI-assisted attack is not a mapping exercise, and it does not belong to the model.

Leave the register alone. Adding a threat column to an asset inventory produces rows that no owner can meaningfully populate and dilutes the one artefact that currently works. The threat evidence already exists in security and operations. What is missing is a route from the AI governance forum to it, and a person who has read both.

One caution on scope. The plan also commits APRA to increasing its focus on how entities identify, assess and manage risks associated with material service providers, including common technology platforms. That is a third question again, one whose AI form is concentrated reliance on a common foundation model, and folding it into either of the two here produces a paper that answers none of them well.

Do this Monday

  1. Read the two sub-headings out loud in your AI forum. Responsible adoption of AI. Cyber risks posed by frontier AI and quantum computing. Ask which one your standing pack addresses. The silence is the finding.
  2. Name an owner for the threat half. It is almost certainly not the person who owns the AI register. It is more likely the head of security or operational risk, who may not know the AI agenda now reaches them.
  3. Pick three controls and test them against an AI-capable attacker. Payment change verification, executive impersonation, and privileged access recovery are the usual three. Record the result with a date.
  4. Ask one question about cryptography. Does a post-quantum transition plan exist, and who holds it. If the answer takes more than a day to find, that is the planning milestone in front of you.
  5. Check the board pack against both halves. If technology and cyber risk oversight and AI oversight are separate agenda items reported by separate people, decide deliberately whether that stays.
  6. Diarise the supervisory conversation. The plan says engagement will be more frequent and deeper. Rehearse the answer to how you manage AI risk in a form that covers both questions in one sitting, because that is how it will be asked.

Bottom line

APRA has published what it intends to supervise, and its structure is the message. One prudential outcome, two AI questions, and a dated cryptography commitment riding alongside them. The adoption question is the one every AI governance function has spent a year building for. The threat question needs evidence that already exists in the organisation but has never been assembled under this heading, and it will be asked in the same conversation. Assemble the second half before the conversation, not during it.

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. A corporate plan sets out a regulator's priorities and creates no new prudential obligation; obligations arise under the prudential standards and the law. Statements attributed to APRA, ASIC and the Australian Signals Directorate are drawn from their published documents as at 18 September 2026. Regulatory obligations vary by entity type, licence and circumstance. Always refer to primary source guidance from APRA, ASIC or the relevant regulatory authority.

References

  1. APRA, APRA publishes 2026-27 Corporate Plan, media release, 20 August 2026. https://www.apra.gov.au/news-and-publications/apra-publishes-2026-27-corporate-plan
  2. APRA, APRA Corporate Plan 2026-27, 20 August 2026. https://www.apra.gov.au/news-and-publications/apra-corporate-plan-2026-27
  3. APRA, APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026. https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai
  4. APRA and ASIC, APRA and ASIC host Superannuation CEO Roundtables, June 2026, information paper, 1 September 2026. https://www.apra.gov.au/news-and-publications/apra-and-asic-host-superannuation-ceo-roundtables-june-2026
  5. Australian Signals Directorate, Planning for post-quantum cryptography, cyber.gov.au, accessed 18 September 2026. https://www.cyber.gov.au/business-government/secure-design/quantum/planning-for-post-quantum-cryptography

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What did APRA publish on 20 August 2026?
Its 2026-27 Corporate Plan, setting out APRA's strategic priorities for the next four years and, under those objectives, the policy, supervision and data initiatives planned for the next 12 to 24 months. Three strategic objectives frame it: maintaining financial safety and stability, getting the balance right, and improving APRA's organisational effectiveness. Beneath the first sit five prudential outcomes for 2026-27, and the first of those is to strengthen operational resilience in response to AI and cyber risks.
Why does the plan discuss AI under two separate headings?
Because they are different supervisory questions. Under Entity resilience, the heading Responsible adoption of AI carries the April 2026 letter forward and addresses governance of the AI an entity chooses to use. The heading Cyber risks posed by frontier AI and quantum computing addresses the threat environment, where AI capability sits on the other side. One asks how you govern your tools. The other asks how you withstand someone else's.
What does APRA say it expects entities to be able to do?
The plan states that entities should expect more frequent and deeper engagement from APRA on cyber and AI risks in supervisory interactions, and that APRA expects entities will be readily able to demonstrate how risks are being managed. Readily able to demonstrate is the operative phrase. It describes evidence that already exists in a retrievable form, not evidence assembled after a request arrives.
What are the post-quantum cryptography dates?
As at 18 September 2026, the Australian Signals Directorate recommends organisations have a refined transition plan by the end of 2026, have commenced the transition by the end of 2028 starting with critical systems and data, and have completed it by the end of 2030. APRA's plan states it expects entities to make timely progress, prioritising their most critical information assets and operations.
Is quantum an AI problem?
No, and treating it as one would be a mistake. It sits under the same sub-heading of APRA's plan because both are technology risks that outrun current controls, not because the underlying problem is shared. The reason it matters to an AI governance function is practical rather than conceptual: the plan puts a dated cryptography commitment in front of the same executives and the same board committee that own the AI agenda.

Context

A corporate plan is not a prudential standard and creates no new obligation. Its value is different and, for planning purposes, sometimes greater: it is the public statement of what a supervisor has resourced itself to ask about over the next 12 to 24 months. Under the Public Governance, Performance and Accountability Act 2013 every Commonwealth entity must publish one, which is why the document is unusually candid about sequencing and priorities compared with guidance written for enforcement.

AI angle

AI risk registers are almost always asset registers. They enumerate models, vendors, use cases and owners, because that is what an inventory of your own technology looks like. The threat half of APRA's supervision priority has no natural home in that structure, since the relevant facts are about capability outside the organisation and controls that were never filed under AI. The fix is not a bigger register. It is a second, deliberately separate evidence set.

Primary sources

APRACorporate PlanOperational ResilienceCyber RiskPost-Quantum CryptographyAI GovernanceSupervision
← Back to GRC

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.