Launching APRA's 2026-27 Corporate Plan at a media conference on 19 August, chair John Lonsdale told reporters that rapid developments in frontier AI had further heightened the cyber threat facing APRA-regulated entities, listing it alongside geopolitical risk as one of the biggest drivers of non-financial risk on the regulator's radar.
Twelve days later, on the other side of the world, Andrew Bailey made almost exactly the same point on a much bigger stage. Writing to G20 finance ministers in his capacity as chair of the international Financial Stability Board (FSB), the Bank of England governor named frontier AI's impact on cyber risk as the most immediate threat to financial stability worldwide.
Two prudential regulators, on opposite sides of the planet, landing on the same conclusion within a fortnight of each other. For Australian insurers, that's not a coincidence worth ignoring.
Lonsdale's comments weren't a one-off. APRA's new corporate plan commits the regulator to assessing how insurers and banks manage their concentrated reliance on common technology platforms and material third-party service providers. That's the same "concentration risk" argument Bailey later made to the G20 about a financial system that depends on a small number of dominant AI and cloud providers. APRA has also flagged AI-enabled cyber threats as one of a small number of top-tier non-financial risks it will actively supervise through the year ahead.
QBE's own research into Australian businesses gives the regulatory concern some hard numbers. Half of Australian businesses surveyed reported a cyber incident in the past 12 months, and just over a quarter of those affected believed AI played a role, whether through AI-driven vulnerability discovery, AI-generated malware, phishing, deepfakes or business email compromise. Two-thirds of businesses that experienced an incident traced it back to a third-party supplier, which lines up neatly with the concentration-risk theme both APRA and the FSB are now raising at the regulatory level.

Both regulators are writing in the shadow of an actual event. In July, OpenAI disclosed that two of its own AI models broke out of a sealed testing environment during an internal evaluation, with no human directing them, and used a security flaw to reach systems belonging to Hugging Face in an attempt to obtain the answers to a cybersecurity benchmark they were being scored on. OpenAI called it an unprecedented cyber incident.
Despite the warnings, Australia's cyber class has recorded a positive insurance service result for three consecutive quarters, even as gross written premium remains a thin sliver of total industry premium and cyber rates continue to soften. Rising AI-linked incident rates sitting alongside a still-profitable, still-competitive market is exactly the kind of gap regulators are trying to close before it widens further.
For brokers and underwriters, the practical follow-through will likely mean closer scrutiny of how policies respond when a loss originates at a shared AI or cloud provider rather than the policyholder's own systems, and continued pressure to link pricing to demonstrable AI governance and supplier due diligence.