Australian insurance industry regulators signal that AI, cyber resilience and privacy are now board and executive-level regulatory priorities
-
Insight Article 29 July 2026 29 July 2026
-
Asia Pacific
-
Regulatory Spotlight
The Australian insurance industry is entering a new era of enhanced regulatory scrutiny with each of the Australian Prudential Regulation Authority (APRA), Australian Securities and Investments Commission (ASIC) and the Office of the Australian Information Commissioner (OAIC) signaling that they will not be waiting for the risk management and governance practices for regulated entities to catch up with the speed of adoption of artificial intelligence (AI) across the sector.
This synchronised approach to AI risks from the various Australian regulators was built upon by the Australian Government’s announcement in mid-July 2026 of the creation of an Office of AI within the Department of the Prime Minister and Cabinet, which will lead coordination of national AI policy and oversee the development of proposed national AI standards, which are expected to be legislated from early 2027.
See Regulatory Spotlight, a series from our Australian Regulatory Team, offering focused insight into the regulatory issues shaping the insurance and corporate landscape.
In the interim, the Australian regulators have set out their expectations in a series of letters to the Australian insurance industry over the past quarter in 2026 (summarised in the timeline below) in the wake of new frontier AI models such as Claude Mythos, which make it clear that cyber resilience and data governance in the age of AI are no longer emerging issues or technology projects alone. They are core governance, risk management and compliance obligations that go directly to an entity’s licence to operate in the highly regulated Australian insurance sector. Boards and senior executives must be able to demonstrate, with evidence, that they understand where AI is being used, how associated risks are controlled, and whether cyber and privacy frameworks remain fit for purpose:
April 2026
APRA issues its first Letter to Industry, outlining its concerns and expectations regarding the management of AI-related risks, including the increasing deployment of AI agents, based on its findings from a targeted engagement on a group of selected regulated entities (including insurers, bank and superannuation trustees) in late 2025. APRA observed that AI adoption is accelerating, but governance, assurance, supplier risk management and operational resilience practices are not keeping pace.
APRA set out its expectations for accountable executives in an attachment to its Letter to Industry, which are issued to assist Chief Risk Officers, Chief Technology Officers and Chief Information Security Officers in APRA-regulated entities to address gaps in the fast-moving regulatory environment.
At a minimum, APRA also expects Boards to:
- have sufficient AI literacy to set strategic direction and provide effective challenge and oversight, rather than relying on vendor assurance or management summaries alone; and
- oversee an AI strategy which is consistent with the APRA-regulated entity’s risk appetite and tolerance settings, supported by effective monitoring and reporting (including for third party dependencies), with clearly defined triggers aligned to resilience objectives to enable timely action when not operating as expected.
May 2026
ASIC
ASIC has reinforced the message from APRA’s letter through its own Letter to Industry issued to Australian Financial Services (AFS) licensees in the following month, warning that frontier AI models are materially changing the cyber threat landscape by increasing the speed, scale and accessibility of sophisticated attacks. ASIC urged AFS licensees to uplift their cyber resilience practices with the rapid development of AI and its associated risks, making it clear that AFS licensees cannot defer foundational cyber security improvements while waiting for more advanced technological solutions.
Coupled with the imposition of the first Court-imposed civil penalty for deficient cyber security risk management under core AFS licence obligations in the case of Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92, ASIC is taking an increasingly aligned and proactive regulatory approach to AI and cyber risk oversight for AFS licensees.
OAIC
As the Australian privacy regulator, the OAIC adds a further dimension to the concerns and expectations for the management of AI risks raised this year by APRA and ASIC for their regulated entities.
This is because the OAIC is overseeing reforms to the Privacy Act 1988 (Cth) (Privacy Act) seeking to address the widespread public and government concern regarding the impact of AI on individuals’ rights and interests.
From 10 December 2026, entities who are subject to the Privacy Act (APP Entities) must disclose specified information in their privacy policies about their use of automated decision making tools (ADM Obligation), where computer programs use personal information to make, or substantially and directly assist in making, decisions that could reasonably be expected to significantly affect an individual’s rights or interests.
The introduction of the ADM Obligation will be particularly relevant for financial services businesses using AI or automated tools in insurance, claims, fraud, pricing, onboarding, complaints or customer eligibility processes.
In May 2026, the OAIC published its ‘Automated Decision-Making Issues Paper’ seeking public feedback in relation to the development of an OAIC guidance on the ADM Obligation. The OAIC guidance will indicate how the OAIC will interpret and apply the ADM Obligation when it comes into effect in December 2026.
June 2026
APRA issued a further Letter to Industry highlighting its observations and expectations regarding the ability of its regulated entities to respond to and manage geopolitical shocks, including AI-related risks with reliance on critical third parties that are often located overseas. APRA reiterated themes from its April 2026 Letter to Industry and highlighted that it sees geopolitical risk as an amplifier of existing material risks, which are not often considered sufficiently by regulated entities, such as the heightened AI risks associated with reliance on offshore critical third-party providers which can complicate the assessment, mitigation, and management of risk exposures.
Looking ahead
For entities in the Australian insurance industry regulated by APRA, ASIC and the OAIC, the practical task is to bring all of the above regulatory considerations together for their businesses, ahead of any further impact arising from the introduction of proposed national AI standards that are expected to be legislated by the Australian Parliament from early 2027.
It is clear from the communications from these Australian regulators this year that AI governance cannot sit separately from cyber, operational resilience, privacy, outsourcing and conduct risk. Australian regulated entities who are subject to the overlapping requirements administered by APRA, ASIC and the OAIC should maintain an inventory of AI tools and use cases, including:
- embedded and third-party solutions;
- classification of high-risk uses;
- establishment of clear ownership and accountability across the AI lifecycle;
- requirement of human oversight for material decisions; and
- assurance that supplier contracts provide transparency, ability for audits to be undertaken, incident notification and exit options.
Immediate priorities for Boards (including risk committees) and senior executives should include refreshing AI and cyber risk appetite settings; testing cyber controls against AI-enabled threat scenarios; reviewing privacy policies and automated decision-making processes ahead of the introduction of the ADM Obligation in December 2026; and strengthening third-party due diligence for AI and data-intensive services.
It is clear that Australian regulators expect safe, responsible and sustainable AI adoption, underpinned by resilient cyber practices and transparent privacy governance under the existing technology-neutral regulatory framework. Australian regulated entities in the insurance sector that can evidence disciplined oversight, tested controls and accountable decision-making will be better placed to manage regulatory engagement as AI regulation continues to evolve in Australia.
End




