For financial services, health, energy and critical infrastructure
You already live with regulators. AI just gave them a new question.
If APRA, the TGA, AER or the SOCI regime already supervises you, AI does not create a new rulebook; it activates the one you have. APRA's April 2026 letter set board expectations and flagged enforcement. CPS 230's transition closed on 1 July 2026 with AI vendors inside the perimeter, and the standard now applies in full. Clinical AI brushes the medical device boundary. Critical infrastructure risk programs must absorb AI hazards.
The supervisory question has been asked
APRA's letter to industry names the weaknesses it found: boards without AI literacy, assurance lagging adoption, identity systems blind to AI agents, shadow AI outside approved frameworks. Answering it is no longer optional homework.
Personal accountability is in scope
FAR for financial services executives, officer duties everywhere else: the regulated sectors are where AI governance failures attach to named individuals first.
Your suppliers are your perimeter
Material service provider rules pull every AI vendor into your compliance envelope. The check maps the obligations; your vendor register does the rest.
“We have a risk team for this”
Good. Hand them a 15-minute instrument that produces the obligation map, the deadlines and the board paper, and let them spend their hours on the remediation instead of the research.
Find out in 15 minutes