APRA's AI letter: what it expects, and how to evidence it
On 30 April 2026 APRA wrote to every regulated entity to say that governance, risk management, assurance and operational resilience are not keeping pace with AI adoption. Below is a plain summary of what the letter expects, with each expectation mapped to the evidence it calls for.
The letter in brief
Who it covers. Every APRA-regulated entity: banks, credit unions, insurers and superannuation trustees. APRA drew its observations from a deep dive in late 2025 with a group of large banks, insurers and super trustees, and published them to help entities that are earlier in their AI adoption.
What it is. Supervisory guidance, not a new prudential standard. APRA's existing, technology-neutral standards already apply to AI risk, and the letter applies in proportion to an entity's size, scale and complexity. APRA says it will focus supervision on AI risk and may take stronger action, including enforcement, where an entity does not manage it proportionately.
What comes next. APRA is finalising a forward plan that covers entity reviews, thematic work and engagement with AI suppliers, and it invites entities to raise heightened AI concerns with their supervisor early.
Who it addresses. Boards, with observations aimed at chief risk officers, chief technology officers and chief information security officers.
The four areas APRA expects entities to address
-
Information security for AI-specific threats
Security controls sized to how AI changes the attack surface: access and identity for AI agents, controls over autonomous and agentic workflows, security testing that covers AI-generated code and components, and preventative controls on how staff use AI rather than detection after the fact. Where AI supports a critical operation, a credible fallback.
-
Governance across the AI lifecycle
A consistent framework with clear reporting lines; named ownership from design to decommissioning; an inventory of AI tools and use cases; human involvement in high-risk decisions; and training for staff on safe use.
-
Supplier risk
Visibility of the whole AI supply chain, including third and fourth parties; contract terms that give transparency and auditability; the ability to understand a model's behaviour and material changes; and tested substitution and exit arrangements for critical AI providers.
-
Change management and assurance
Recognised control frameworks and change control for AI; assurance that joins up cyber, data, model performance, resilience, privacy and conduct risk; monitoring that is continuous and proportionate to the use case rather than point in time; and second-line and internal audit teams with the capability and tooling to assess AI independently.
Boards. The letter expects boards to understand AI well enough to set direction and challenge management, to oversee an AI strategy within their risk appetite, and to set triggers that prompt action when AI-supported operations drift from expected performance.
How Heliast helps you evidence it
Heliast supplies controls, evidence and documentation. Your organisation remains responsible for its own compliance, and decides what the evidence is worth.
| APRA expectation | What Heliast provides | Status | Limits |
|---|---|---|---|
| APRA expectationPreventative, enforceable controls rather than policy or detection after the fact | What Heliast providesA fail-closed enforcement point: only admitted models are reachable, and every decision is recorded | StatusAvailable | LimitsGoverns only AI traffic routed through Heliast; blocking unapproved tools is your network control |
| APRA expectationIdentity and access for AI agents, and controls over agentic workflows | What Heliast providesPer-agent virtual keys, entitlement tied to admitted models, and per-workload policy in your own Git | StatusPartial or in pilot scope | LimitsFederation to a commercial identity provider is in build; the tools an agent runs on the client side are not observed |
| APRA expectationAn inventory of AI tooling and use cases | What Heliast providesThe catalogue of admitted models, and a ledger showing which models are used and by whom | StatusPartial or in pilot scope | LimitsThere is no use-case register yet |
| APRA expectationMapping the AI supply chain, including third and fourth parties | What Heliast providesProvenance traced to the original publisher, including the base model behind a derivative | StatusPartial or in pilot scope | LimitsHosted provider records are in build; export screening is not yet assessed |
| APRA expectationUnderstanding model behaviour, material changes and performance | What Heliast providesCompare tests candidate models on your own tasks, with versioned results; every verdict is tied to an exact revision | StatusPartial or in pilot scope | LimitsCompare has not yet been run on a customer dataset |
| APRA expectationTested substitution, portability and exit for critical AI providers | What Heliast providesA published exit path; the estate keeps running with no dependency on us; Compare can test a substitute model | StatusPartial or in pilot scope | LimitsSubstitution testing across environments needs hosted routes, which are in build |
| APRA expectationContinuous monitoring rather than point-in-time assurance | What Heliast providesA continuous, tamper-evident record of every request, and scheduled re-testing of admitted models | StatusPartial or in pilot scope | LimitsModel re-testing is periodic, not continuous, and there is no drift alerting yet |
| APRA expectationTooling for second line and internal audit to assess AI independently | What Heliast providesSigned verdicts and a hash-chained ledger your own team can check offline, with published keys and instructions | StatusAvailable | LimitsThe signing key is held locally, not in a hardware security module |
| APRA expectationSecurity testing of AI-generated code and libraries | What Heliast providesNot provided | StatusNot covered | LimitsUse application security tooling for this |
| APRA expectationDefences against prompt injection and similar attacks | What Heliast providesNot provided | StatusNot covered | LimitsNot in the current product |
| APRA expectationBoard AI literacy and strategy | What Heliast providesNot provided | StatusNot covered | LimitsA matter for your board |
Rows marked Not covered are listed so risk teams can see the whole picture; Heliast works alongside the tools that cover them. Current status for every capability is in the capability status table.
Related obligations
CPS 230 Operational Risk Management has applied since 1 July 2025, with an updated version from 1 July 2026, and governs how entities manage material service providers. CPS 234 Information Security governs information security, including for assets that third parties manage. Whether an on-premise AI platform is a material service provider is a question for your organisation and its advisers.
Talk it through
A discovery session is a short working session on your highest-value AI workload, the data that cannot leave your environment, and what a successful pilot would need to prove. It is free.
This summary of APRA's letter is for general information. It is not legal or regulatory advice. Read the original letter, and seek your own advice on how it applies to your organisation.
We supply controls, evidence and documentation that support your obligations. We do not deliver compliance.
Source: https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai · Last reviewed 27 September 2026