What actually changed
The regulator did not write a new AI standard. It applied the one you already have.
There is no separate AI instrument coming, and waiting for one is the mistake. AI risk arrives through operational risk, information security, supplier management and board oversight — all of which are already prudential obligations with an existing supervisory apparatus behind them.
What the April letter added was a finding. APRA looked across a set of large banks, insurers and trustees and reported that governance and assurance were not keeping pace with adoption. It named board reliance on vendor presentations without examination of the underlying risks. It noted identity and access management built for human users and not yet adjusted for non-human ones. It asked for recognised control frameworks and integrated assurance rather than a policy document.
ASIC wrote eight days later, on different ground: cyber resilience against an AI-accelerated threat environment, a twelve-point action list, and an instruction that the letter be tabled at the ultimate board and risk committees. Two regulators, ten days apart, arriving at the same place from opposite directions — the board, and what it can actually evidence.
Read alongside CPS 230, that is a specific and uncomfortable question about every AI capability in the business: is it inside a critical operation, and if it is, can you evidence what happens when it degrades, who intervenes, and how quickly you would know.