How to meet APRA's demands for improved AI security
What happened
APRA issued a Letter to Industry that raises the regulatory bar for AI governance, explicitly calling out machine identities, persistent credentials and the need for continuous monitoring. The regulator's supervisory deep dive found governance and identity gaps across major institutions, making AI-agent controls an operational procurement item to show during engagements and audits
Why the category manager should care
Explicitly include machine or AI-agent identities in IAM scopes, telemetry export clauses and supplier runbook obligations because APRA expects continuous governance for non-human actors
Key facts
- Letter to Industry dated 30 April 2026
- Regulator conducted a supervisory deep dive across major institutions and found systemic gove
- Immediate steps recommended include adding AI agents into IAM and continuous monitoring