NIBA - Logo small
Need A Broker Logo
Insure Your Future logo
niba-insure-your-future-horizontal_logo

Regulators to Industry: It’s Time to Translate AI Awareness into Action

News Insurance

Regulators have cautioned that awareness of frontier AI cyber risks is no longer enough. In a joint publication released recently, ASIC and APRA have urged all financial market entities — including brokers and their material service providers — to move decisively from understanding these risks to demonstrably managing them.

The message follows a series of nine industry roundtables the regulators ran in June and July, drawing more than 600 attendees from over 380 entities, and industry associations representing upwards of 70,000 members. The forums were supported by the Australian Signals Directorate and included the Reserve Bank of Australia, Treasury and the ACCC, signalling a whole-of-government response.

ASIC Commissioner Simone Constant did not understate the stakes, warning that threat actors are using frontier AI to find and exploit vulnerabilities that once would have taken a team of professionals months to uncover. She said the financial system is only as resilient as its weakest link, and that boards and executives must ensure their organisations have well-tested response plans and know where they are vulnerable.

NIBA’s landmark thought-leadership report ‘Ready or Reacting? Shaping the Future of the Broking Profession’ highlighted that brokers have identified technological disruption as the top disruptive force over the coming decade. While 83% of respondents expect technology and automation to have significant impact by 2035, only 61% feel prepared, signalling that there is a major gap between technological disruption and preparedness across the profession.

Five themes emerged from the roundtables.

First, frontier AI raises the cost of weak cyber fundamentals — patching, identity and access controls, backup integrity and tested recovery arrangements all matter more in a faster threat environment.

Second, governance and escalation are pressure points: key decisions on risk appetite, escalation authority, recovery priorities and communications need to be made and tested before a crisis hits, because compressed incident timeframes leave little room to improvise.

Third, defensive AI is drawing growing interest for threat intelligence and incident response, though capability remains limited and is no substitute for strong fundamentals.

Fourth, shared dependencies on third-party providers can turn an isolated incident into sector-wide disruption. Fifth, collaboration is now part of resilience.

APRA Deputy Chair Therese McCarthy Hockey pointed to an encouraging trend — more advanced entities sharing practical lessons with less mature peers, the kind of 'Team Australia' mindset needed across an interconnected system.

For the broking profession, the practical takeaway is clear: map your critical dependencies, test your response plans, and settle the hard decisions at board level now. The insights paper includes a preparedness checklist for boards and executives.

Read the ASIC and APRA joint media release here.

Read the Insights Paper here.