I read APRA’s letter on AI in April from two positions: as someone who has spent years building and managing enterprise technology systems, and as a board director who now governs them. From both sides, the same gap is visible.

APRA’s letter names two minimum expectations for boards: sufficient literacy to set strategic direction on AI, and the capacity to provide effective challenge and oversight. Both, in APRA’s assessment, are currently missing from most boardrooms, not because boards are uninterested, but because they are applying existing risk frameworks, assurance methods and vendor management practices to an entirely new technology surface.

Among APRA’s findings, one is a direct root cause: “a tendency to treat AI risk as just another technology.” Understanding why that tendency is natural, and why it fails, is the starting point for governance that actually works.

The framework mismatch

Traditional technology governance rests on assumptions so embedded they’ve become invisible: systems are deterministic, behaviour is predictable, outputs are consistent, and a point-in-time review tells you something meaningful about how a system performs. You approve it, deploy it, audit it periodically. The framework works because the technology it was designed for is stable.

AI breaks every one of those assumptions.

Generative AI produces probabilistic outputs. The same prompt, run twice, may produce different results. The model can be confidently wrong, and it doesn’t know what it doesn’t know. APRA observed this: “point-in-time and sample-based assurance methods” are ill-suited to “probabilistic models that learn, adapt and degrade over time.”

Agentic AI acts. It doesn’t always wait for a human to review an output and decide what to do with it. It initiates actions, executes sequences, makes downstream commitments. The governance question is no longer “did the human use the tool correctly?” It is: what can this system initiate without human approval, who authorised that scope, and what catches an out-of-bounds action before harm occurs? APRA found that identity and access management across Australia’s largest regulated entities “has not yet adjusted to non-human actors such as AI agents.”

These tools are starting to be deployed at scale across the enterprise. Well-intentioned, enthusiastic, technically-untrained staff are using them, often outside approved frameworks, without understanding what probabilistic means in practice or what operational reach they’ve just handed an agent. APRA found this too: shadow AI use, weak preventative controls, organisations relying on policy and after-the-fact detection rather than technical enforcement. A 2026 survey of 108 enterprises found that 88% had experienced agent security incidents, and 82% had trusted their policies before those incidents occurred, a pattern APRA’s own observations echo across Australian regulated entities.

Three vectors, not one

The conversation about AI risk often settles on the external threat: even unsophisticated actors can use AI to launch a very sophisticated attack. That risk is real, documented by APRA and regulators globally, and demands a response. But it is one of three vectors operating simultaneously. The other two get less attention.

The first vector is internal. No attacker required. An employee with access to a probabilistic, autonomous system uses it in a consequential process. The output is confident. The action is initiated. The error propagates before anyone notices. Multiply that across an organisation of thousands and the result is operational chaos that no single person caused and no single governance control catches.

The second vector is external. AI-augmented attacks are shortening the kill chain (the sequence of steps from initial access to a successful attack) and enabling prompt injection (manipulating an AI system by embedding malicious instructions in its inputs). As APRA noted in its engagement with the Council of Financial Regulators, frontier AI models are creating threat categories that existing cyber defences weren’t designed for.

The third is systemic. Neither of the above actors needs to be present. The AI system itself, probabilistic, adaptive, and sitting on a supply chain no organisation fully controls, produces emergent behaviour at scale. APRA documented this specifically: entities heavily dependent on single providers, limited evidence of audit rights or model-update notification in contracts, upstream dependencies on foundation models and training data that are opaque even to the vendors. A foundation model update propagates through your systems. Nobody notified you. The model’s behaviour changed. Your governance instruments, designed for a stable and deterministic system, have no mechanism to catch it.

All three vectors operate simultaneously and interact. A technically-untrained employee makes a decision based on a confident AI output that was already shaped by silent model drift from a foundation model update the vendor didn’t surface. Governance that addresses any one of these while the others run unchecked is not governance. It is the appearance of it.

What this requires in practice

I’ve spent over 25 years building and directly managing enterprise technology systems: the transformation programmes, the teams, the delivery reality that rarely matches what appears in the board paper. I’ve also spent over a decade in boardrooms, not as an advisor but as a director, consuming those reports to inform how I make very consequential governance decisions. That changes how I read APRA’s letter.

The questions I ask as a committee chair are informed by having been the person who had to answer them. And the questions that reveal whether an organisation’s AI governance is real or gestural are not technical. They are structural.

Three things a governance framework needs to demonstrate: executives need to build them, boards need to verify they exist.

Visibility over what is actually running. Not what the policy covers, but what is deployed, including tools operating outside approved frameworks. APRA found shadow AI across Australia’s largest institutions. You cannot govern what you cannot see - an extension to you cannot manage what you cannot measure.

An accountability structure designed for autonomous systems. Who is responsible for an agent’s output? What oversight mechanism exists at the point of action, not after the fact? Treating agents as tools that execute human decisions, rather than systems that initiate actions with real consequences, leaves an accountability gap existing structures cannot close.

Supply chain transparency to the model layer. Who are the third and fourth-party dependencies beneath the tools you’ve approved? What changes to those systems trigger notification? What is your substitution plan if a critical provider changes its model or fails? These aren’t new AI governance obligations. They are existing CPS 230 requirements for operational risk management and service provider management, binding since July 2025, that most entities have not extended to their AI vendors and foundation model providers. APRA found the gap. The non-compliance is current, not pending.

If your governance framework can demonstrate all three, you are ahead of most. If it can’t, the exposure is not hypothetical and it is not future-dated.

CPS 230 has been in force since July 2025. The AI letter arrived in April 2026. Privacy Act amendments take effect in December 2026. Three instruments, converging at the same point: how organisations govern AI systems, their supply chains, and the people using them. Entities waiting for a single definitive AI governance framework to arrive are already behind on obligations that exist today.

APRA will not be the last regulator to name this. Prudential regulators move in concert; the standard established in one regulatory environment travels. Executives and directors in any complex, regulated organisation - not just those supervised by APRA - should read this letter as a directional signal for what is coming.

APRA has left the definition of adequate governance to each organisation. The boards and executive teams that treat that ambiguity as an invitation to define their own minimum will not have defined a minimum. They will have defined a liability.