Three in four Australian financial services organisations rate their AI risk management as effective. Fewer than one in three have AI on their risk register. Australia’s two peak financial regulators have now told industry that gap has enforcement consequences – and the questions they are asking apply directly to insurance brokers. That is the picture that has emerged across a sequence of regulatory actions in 2026, culminating in a joint information paper released by the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) in August and a practical framework published by the Actuaries Institute and the University of Technology Sydney’s Human Technology Institute (HTI).
The HTI’s survey of 27 financial services organisations, conducted in 2025, found that 93% were already using AI. Yet fewer than one in three had AI-specific items on their risk register, and fewer than one in four had incorporated AI into their risk appetite statement. Despite those gaps, 74% rated their current risk management as effective for AI. ASIC chair Joe Longo named that dynamic in October 2024, when the regulator released Report 798 following a review of 23 AFS and credit licensees spanning financial advice, retail banking, credit, and general and life insurance. “There is the potential for a governance gap – one that risks widening if AI adoption outpaces governance in response to competitive pressures,” he said.
By April 2026, APRA’s tone had shifted from potential to observed. Following a deep-dive engagement with selected large banks, insurers, and superannuation trustees in late 2025, APRA found that while most entities recognised existing prudential standards applied to AI risk, “few have operationalised governance in practice.” The regulator warned it would take “stronger supervisory action and, where appropriate, pursue enforcement” where entities failed to manage AI risks proportionate to their size and complexity.
“Despite the growing use and importance of AI, many financial services organisations are ill-equipped to manage the scale, complexity, and evolving risk profile of AI systems. Organisations that choose to do nothing in this space will be exposed to new risks they are not equipped to deal with,” said Victor Bajanov, co-lead author of the Actuaries Institute framework.
That regulatory posture has a court record behind it. In February 2026, the Federal Court ordered FIIG Securities to pay a $2.5 million penalty and $500,000 towards ASIC’s costs after the regulator pursued the firm over cyber security failures that breached its obligations as an Australian Financial Services (AFS) licensee. FIIG admitted it had failed to take necessary steps to provide financial services efficiently, honestly, and fairly; maintain adequate financial, technological, and human resources; and maintain an adequate risk management system for cyber security. The case followed a 2023 cyberattack in which about 385 gigabytes of confidential information was stolen; FIIG notified approximately 18,000 clients that their personal information may have been compromised. ASIC described the judgment as the first time the Federal Court had imposed civil penalties for cyber security failures under the general AFS licensee obligations, reinforcing the broader regulatory expectation that licensees maintain effective technology, risk management, and resilience controls. Those expectations are increasingly relevant as financial services firms deploy AI across operational and client-facing functions.
The APRA-ASIC joint roundtable paper – published August 27, 2026, and drawing on nine roundtables across June and July involving more than 600 attendees from over 380 entities – reinforced the same standard. Its headline finding – that boards are making critical governance decisions for the first time during live AI-accelerated incidents – describes the same failure mode ASIC pursued in court. The roundtable paper stated that weaknesses in governance and escalation settings “could be as disruptive as technical control weaknesses,” and that board decisions and guardrails need to be in place before a crisis, not during one.
For insurance brokers, the governance gap in insurer counterparties is not an abstract concern. Insurers are using AI in claims triage, fraud detection, pricing, and customer service – all areas that directly affect broker clients. The Actuaries Institute report identifies claims processing as a core AI use case in financial services, noting that AI systems can produce differential outcomes across demographic groups, may disadvantage claimants experiencing financial hardship or with limited English proficiency, and are subject to manipulation through adversarial inputs. These failure modes sit directly within the scope of the General Insurance Code of Practice and the Life Insurance Code of Practice.
Brokers placing professional indemnity or management liability cover should note that APRA’s 2026 AI engagement identified third-party dependencies as a potential source of systemic risk, including where entities rely heavily on external AI providers. APRA also highlighted gaps between existing contractual arrangements and emerging AI practices, including the need to address issues such as oversight, model changes, and incident notification. The APRA-ASIC roundtable paper similarly warned that common dependencies on third parties can amplify the impact of an incident across multiple organisations.
For brokers whose own operations use AI tools – for client communication, document drafting, or compliance checking – the obligations exposed in the FIIG proceedings apply equally. ASIC has taken two cyber security enforcement actions against AFS licensees, with a third case involving Fortnum Private Wealth before the courts as of 2026. The first, against RI Advice, resulted in a 2022 Federal Court finding that the licensee had breached its obligations by failing to maintain adequate cyber-risk management systems. In February 2026, FIIG Securities became the second after the Federal Court ordered it to pay a $2.5 million penalty. ASIC’s proceedings against Fortnum Private Wealth, filed in 2025, remained before the courts.
The APRA-ASIC roundtable paper’s appendix sets out the board-level questions regulators expect entities to answer before an incident occurs. Three translate directly into broker renewal conversations with AFSL-holding clients. First: have key escalation, shutdown, recovery, and communications decisions been made ahead of an AI-related incident, and have they been tested? The roundtable paper states plainly that “if key decisions would be debated for the first time during an incident, this should be treated as a priority gap.”
Second: does the client know which AI providers and platforms support their critical operations, where common dependencies exist, and whether fallback arrangements work under compressed timeframes? Vendor concentration is a documented weakness across the sector. Third: is the client’s AI governance documentation – AI policy framework, risk register entries, board reporting – sufficient to meet the standard ASIC applied in FIIG and reiterated in the roundtable paper? The Actuaries Institute framework includes an AI system triage form and vendor due diligence checklist that map directly to these expectations.
ASIC commissioner Simone Constant stated at the roundtable release: “Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find. Australia’s financial system is only as resilient as its weakest link. Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans.” For brokers, those three renewal questions are how that statement becomes a client conversation.