How to meet APRA's demands for improved AI security
What happened
APRA published a Letter to Industry that demands stronger AI governance, identity controls and continuous assurance for AI systems. The regulator explicitly requires identity and access controls to include non-human AI agents and suggests immediate steps for gap assessment and monitoring. Watch whether regulated suppliers and RFPs begin embedding these expectations into contractual and audit clauses
Why the category manager should care
Make AI agents first-class assets in sourcing: require identity governance, monitoring rights and explicit supplier commitments for non-human identities
Key facts
- APRA Letter to Industry on Artificial Intelligence (30 April 2026)
- Guidance includes immediate steps and gap-assessment advice for identity and monitoring
- Directs boards to demonstrate AI literacy and governance alignment