Australian AI Governance Briefing: Week Ending 3 May 2026
APRA threatens stronger supervisory and enforcement action over AI governance gaps in financial services, and the ARC and NHMRC issue a joint policy on generative AI in research grants.
The week’s headline development was APRA’s 30 April industry letter on artificial intelligence — the most consequential AI regulator communication for Australian financial services so far in 2026. Drawing on a late-2025 targeted review of selected large banks, insurers and superannuation trustees, APRA found that governance, risk management, assurance and operational resilience practices are not keeping pace with AI deployment. The regulator stopped short of proposing new prudential standards but made clear that existing standards on operational risk, information security, governance and risk management are sufficient legal hooks — and that stronger supervisory and enforcement action will follow where boards and management fail to close identified gaps. The letter took the unusual step of naming a specific frontier AI model — Anthropic’s Mythos — as part of an emerging cyber threat picture.
The same week, the Australian Research Council and NHMRC released a joint policy on the use of generative AI in grant applications and peer review, effective 28 April. Applicants may use AI as a support tool but retain full responsibility for output integrity; assessors are limited to using AI for grammar, spelling, formatting and readability, never for evaluation or scoring. The policy will become the de facto standard for AI use in research administration across Australian universities and medical research institutes.
Beyond those two developments, the week was quieter on AI-specific regulator activity, with Parliament in recess and the OAIC and state regulators rolling out promotional materials for Privacy Awareness Week 2026 — notable for a split in framing, with Queensland and Victoria adopting an explicitly AI-focused theme that signals continuing regulator attention on automated decision-making transparency ahead of the December 2026 commencement of new APP obligations.
The week in review
APRA calls for a “step-change” in financial services AI risk management
APRA’s industry letter, published on Thursday 30 April, is the clearest signal yet that Australia’s financial services prudential regulator views AI governance not as a future regulatory project but as a present-day supervisory priority enforceable under existing standards. APRA Member Therese McCarthy Hockey framed the letter as a call for a step-change, drawing on a targeted review APRA ran in late 2025 covering selected large banks, insurers and superannuation trustees and assessing how AI was being deployed and governed.
The findings are pointed. Boards are described as showing strong interest in AI’s commercial upside but as still developing the technical literacy required to provide effective challenge on AI-related risks and oversight. APRA observed over-reliance on vendor presentations and summaries without sufficient examination of issues such as unpredictable model behaviour and impacts on critical operations. Concentration risk is flagged where entities depend heavily on a single provider for multiple AI use cases, with weak contingency planning and limited testing of exit or substitution strategies. Identity and access management capabilities have not yet adjusted to non-human actors such as AI agents. The volume and speed of AI-assisted software development is straining change and release management controls. Existing internal audit and risk functions lack specialist skills for assessing AI systems, particularly agentic behaviour, automated decision-making, and AI-assisted code generation. Point-in-time and sample-based assurance methods are described as ill-suited to probabilistic models that learn, adapt and degrade over time.
On cyber, APRA names specific attack vectors — prompt injection, data leakage, insecure integrations, exploit injection, and manipulation or misuse of autonomous AI agents — and is unusually direct in identifying frontier AI models, citing Anthropic’s Mythos as an example of a high-capability model that could enhance the discovery of vulnerabilities by bad actors and increase the probability, speed and scale of cyber attacks. Shadow AI is flagged as an area where entities are relying primarily on policy direction or detective measures rather than enforceable technical preventative controls.
The enforcement posture matters. APRA has not announced new prudential standards. Instead, it is signalling that the existing suite — CPS 230 on operational resilience, CPS 234 on information security, CPS 220 on risk management, and CPS 510 on governance — already covers AI-related conduct, and that stronger supervisory action and, where appropriate, enforcement will follow where entities fail to identify, manage or control AI risks proportionate to their size, scale and complexity. This is consistent with the Australian Government’s broader posture under the National AI Plan released in December 2025, which favoured working through technology-neutral existing law rather than a standalone AI Act. It also aligns the prudential regulator’s posture with ASIC’s October 2024 REP 798 on governance arrangements in AI, with public reporting indicating APRA and ASIC have been engaging the industry jointly in the run-up to this letter.
For Australian financial services compliance teams, the practical implications are immediate. Boards should expect their AI literacy and oversight to be tested in supervisory engagement. Concentration risk on a single AI vendor — increasingly common as Microsoft, Google and Anthropic embed capabilities deep in productivity tooling — needs documented contingency and exit plans. Identity and access management programs need to extend to non-human agents. Internal audit needs specialist AI assurance skills, and assurance methods need to move beyond point-in-time sampling. Shadow AI policy alone will not pass supervisory muster — preventative technical controls are required. The findings map closely to the structure of ISO/IEC 42001 AI management systems, and entities not already pursuing certification or equivalent assurance now have a clear regulator-articulated reason to consider it.
Primary sources: APRA media release | APRA letter to industry
ARC and NHMRC release a joint policy on generative AI in grant applications and peer review
Effective Tuesday 28 April, the Australian Research Council and the National Health and Medical Research Council released parallel policies — accompanied by a joint statement from their CEOs — covering the use of generative AI in grant applications and peer review across the ARC’s National Competitive Grants Program and NHMRC’s Medical Research Endowment Account schemes. The policies apply to ARC scheme rounds opening on or after the effective date, including the Discovery Indigenous 2027 round.
The position is calibrated rather than prohibitionist. Applicants may use generative AI as a support tool, for example to refine text for clarity or to summarise material, but retain full responsibility for the accuracy and integrity of any generated content. Assessors and peer reviewers, by contrast, may use generative AI only to assist with grammar, spelling, formatting and readability of drafted assessments — not for evaluation, scoring or expert judgement, which must remain human. Both groups are directed to enter only the minimum necessary information into generative AI tools and to treat anything entered as potentially public, with explicit confidentiality and bias-checking expectations.
Substantively, the policies operate as a cross-walk between the public sector AI assurance framework and the research sector. They reference and align with Australia’s AI Ethics Principles, the Australian Code for the Responsible Conduct of Research, the Digital Transformation Agency’s Policy for the Responsible Use of AI in Government version 2.0, and APS staff guidance on public generative AI from digital.gov.au. NHMRC also points reviewers to the DTA’s AI fundamentals training, including the version available outside the APS — a small but useful endorsement of training that is now becoming the lingua franca of public sector AI literacy.
For universities, medical research institutes and other Commonwealth grant recipients, the practical effect is significant. The two agencies fund the bulk of Australian competitive research, and their alignment on generative AI use will rapidly become the de facto standard against which institutional research integrity policies, HREC processes and assessor briefings are judged. Pro-Vice-Chancellor Research portfolios and research integrity teams should plan policy and training updates ahead of the next major scheme rounds. The policies also serve as a template that other Commonwealth grant-making agencies are likely to follow as they face similar pressure to provide clear AI guidance to applicants and reviewers.
Primary sources: ARC and NHMRC joint statement | NHMRC policy | NHMRC CEO statement
Privacy Awareness Week mobilises with a split AI-focused framing
The week closed with the OAIC and state and territory privacy regulators completing mobilisation for Privacy Awareness Week 2026, which runs Monday 4 to Sunday 10 May. The interesting development is the divergence in framing across regulators. The OAIC’s national theme is “Trust is built here — In every privacy complaint. In every resolution,” focused on privacy dispute resolution. The Queensland Office of the Information Commissioner and the Victorian Office of the Information Commissioner adopted a different and explicitly AI-focused theme: “Smart tech, smarter choices — Protecting your privacy in the age of AI.”
For compliance leads, the split is more than a branding choice. State regulators choosing to spotlight AI in 2026 reinforces that automated decision-making transparency is moving up the regulatory agenda ahead of the 10 December 2026 commencement of new APP 1.7 to 1.9 obligations, which will require APP entities to disclose substantially automated decisions affecting individuals. Privacy Commissioner Carly Kind is scheduled to participate in an OAIC panel discussion on 6 May, and a number of state and territory regulators, professional bodies and law firms have lined up AI-themed sessions for the week. Organisations that have not begun mapping their automated decision-making for APP 1.7 disclosure should treat the next eight months as the design and implementation window, not a buffer period.
Primary sources: OAIC Privacy Awareness Week 2026 | OIC Queensland
Stories
APRA threatens stronger supervisory action on AI governance gaps in financial services
APRA’s 30 April industry letter draws on a late-2025 targeted review of large banks, insurers and superannuation trustees and finds that AI governance is not keeping pace with deployment. APRA has not proposed new prudential standards but has signalled that existing standards on operational resilience, information security, governance and risk management already cover AI, and that stronger supervisory action and, where appropriate, enforcement will follow where gaps remain. The letter explicitly names Anthropic’s Mythos as an example of a frontier AI model elevating the cyber threat picture for regulated entities.
ARC and NHMRC release joint policy on generative AI in grant applications and peer review
Effective 28 April, the Australian Research Council and NHMRC have published parallel policies allowing applicants to use generative AI as a support tool while retaining full responsibility for output integrity, and limiting assessor use to grammar, spelling and formatting. The policies expressly cross-reference Australia’s AI Ethics Principles, the Australian Code for the Responsible Conduct of Research, and the DTA’s Policy for the Responsible Use of AI in Government, and will rapidly become the de facto standard for AI use in research administration across Australian universities and medical research institutes.
Privacy Awareness Week 2026 launches with split AI-focused framing across regulators
The OAIC and state and territory privacy regulators completed mobilisation for Privacy Awareness Week, running 4 to 10 May 2026. The OAIC’s national theme focuses on privacy dispute resolution, while Queensland and Victoria have adopted an explicitly AI-focused theme — “Smart tech, smarter choices: Protecting your privacy in the age of AI” — signalling continuing state regulator attention on automated decision-making transparency ahead of the December 2026 commencement of new APP 1.7 to 1.9 obligations.
This briefing was researched and written with AI assistance.
Stay across Australian AI governance
Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.