Superannuation trustees have been put on notice over artificial intelligence risk after APRA warned governance, cyber controls and assurance frameworks are failing to keep pace with the speed of AI adoption across regulated entities.
A letter sent to all APRA-regulated entities said lessons from the regulator’s late-2025 deep-dive into large banks, insurers and super trustees should serve as a warning for the broader sector as funds move beyond experimentation and embed AI more deeply across operations.
APRA said AI was increasingly being adopted to drive productivity, efficiency and customer outcomes, but flagged inconsistent maturity across governance, risk management and operational resilience, with assurance functions lagging behind the scale, speed and complexity of deployment.
The warning carries particular weight for super funds because APRA made clear that boards and accountable executives will be expected to treat AI as a prudential risk issue rather than a technology side project, with failures potentially attracting stronger supervisory intervention or enforcement.
“AI presents great [a] opportunity for productivity and efficiency, and failing to embrace AI may put businesses at a strategic disadvantage,” APRA said. “AI also has the potential to create new risks and escalate existing challenges.”
While boards were showing strong interest in AI’s strategic upside, particularly around productivity, efficiency and customer experience, APRA said many were still developing the technical literacy needed to provide effective challenge and oversight.
The regulator also pointed to an over-reliance on vendor presentations and summaries, without sufficient interrogation of unpredictable model behaviour or the implications for critical operations.
Trustees were told boards should maintain sufficient understanding of AI to set strategy and challenge management, while ensuring any AI strategy is aligned with risk appetite and tolerance settings and supported by effective monitoring and reporting, including over third-party dependencies.
The regulator’s attached executive debrief suggested the sector is already moving beyond basic internal experimentation, with entities trialling or introducing AI across software engineering, customer interaction, fraud and scam disruption, claims triage and insight generation.
While APRA did not single out individual super funds, it said governance had not matured at the same pace as adoption.
“APRA observed a tendency to treat AI risk as ‘just another technology’,” the regulator said. “This misses key differences such as the distinct characteristics of predictive systems, adaptive behaviour in models, ethical considerations such as inherent bias, and privacy and data risks.”
That gap, according to APRA, had resulted in weaknesses across the AI lifecycle, including weak controls over post-deployment monitoring, model behaviour monitoring, change management and decommissioning of AI capabilities.
Cyber risk also emerged as a clear pressure point for trustees, with APRA saying AI adoption was materially changing the threat landscape by creating more attack pathways and enabling faster, more coordinated attacks.
It highlighted risks such as prompt injection, data leakage, insecure integrations, exploit injection and misuse of autonomous AI agents.
APRA also warned some entities’ identity and access management frameworks had not adapted to non-human actors such as AI agents, while AI-assisted software development was placing strain on traditional change and release controls.
Patching, configuration management and broader remediation efforts were not always keeping pace with the faster threat environment, it said.
Another concern raised by the regulator was staff using enterprise AI tools outside approved control frameworks, with many entities still relying on policy settings or after-the-fact detective measures instead of stronger preventative controls.
Supplier concentration was also identified as a key risk for trustees after APRA observed some entities were heavily dependent on a single provider for multiple AI use cases without robust contingency planning or tested exit and substitution strategies.
Contract terms often lagged actual practice, with limited evidence of protections around audit rights, model updates, incident notification or changes to data handling, according to APRA.
Traditional, point-in-time and sample-based assurance methods were described as poorly suited to probabilistic models that can learn, drift or degrade over time, while internal audit and risk teams often lacked the specialist skills and tools needed to independently assess AI systems, particularly where agentic behaviour or AI-assisted code generation was involved.
APRA’s message to super trustees is that AI should be governed through the same prudential lens as any other material operational or non-financial risk, but with stronger controls tailored to the technology’s unique characteristics.
That includes formal governance frameworks, clear ownership across the AI lifecycle, inventories of AI tools and use cases, human involvement in high-risk decisions, continuous monitoring and integrated assurance across cyber, data, privacy, conduct and operational resilience.
While APRA said it was finalising its forward supervisory plan on AI risks and would take a proportional approach across prudential reviews, thematic work and supplier engagement, the regulator left little doubt the issue will remain firmly in focus.
“Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, we will take stronger supervisory action and, where appropriate, pursue enforcement.”




