Superannuation trustees are among the APRA-regulated entities facing sharper scrutiny over artificial intelligence after the prudential regulator warned governance, cyber controls and assurance frameworks are failing to keep pace with adoption across financial services.
A sector-wide letter issued to all APRA-regulated entities drew on a targeted engagement with selected large banks, insurers and superannuation trustees in late 2025, with the regulator identifying uneven maturity across governance, risk management and operational resilience as AI use accelerates.
APRA said assurance practices were also lagging the scale, speed and complexity of deployment.
That message carries particular significance for super funds because trustees are already operating under intense regulatory focus on governance, operational resilience and third-party risk. APRA made clear AI will be treated through the same prudential lens as any other material non-financial risk, with failures to adequately identify, manage or control exposures potentially leading to stronger supervisory action or enforcement.
“AI presents [a] great opportunity for productivity and efficiency, and failing to embrace AI may put businesses at a strategic disadvantage,” APRA said. “AI also has the potential to create new risks and escalate existing challenges.”
While the warning spans superannuation, banking and insurance, APRA’s findings suggest trustees should be paying close attention as funds continue to expand their use of digital tools across member servicing, operational efficiency and outsourced technology environments.
The regulator did not single out individual sectors, but its review included superannuation trustees alongside some of the largest institutions in the system.
Boards emerged as an early area of concern. APRA said many boards showed strong interest in AI’s strategic upside, particularly around productivity, efficiency and customer experience, but warned technical literacy was often still developing, limiting boards’ ability to provide effective challenge and oversight.
The regulator also pointed to an overreliance on vendor presentations and summaries without enough examination of risks such as unpredictable model behaviour and impacts on critical operations.
Trustees and other regulated entities were told boards should maintain sufficient understanding of AI to set strategic direction and ensure AI strategies are aligned with risk appetite and tolerance settings, supported by effective monitoring and reporting, including over third-party dependencies.
The broader review showed AI adoption is already moving beyond internal experimentation into more operationally significant and customer-facing uses across financial services.
APRA said entities were trialling or introducing AI in software engineering, claims triage, loan application processing, fraud and scam disruption, customer interaction and insight generation.
That evolution is likely to be relevant for super funds even where use cases remain less visible than in banking or insurance, particularly as trustees increasingly rely on administrators, service providers and digital platforms that may embed AI capabilities deeper into day-to-day operations.
APRA’s warning on supplier dependencies and governance maturity therefore extends beyond direct in-house AI deployment.
“APRA observed a tendency to treat AI risk as ‘just another technology’,” the regulator said. “This misses key differences such as the distinct characteristics of predictive systems, adaptive behaviour in models, ethical considerations such as inherent bias, and privacy and data risks.”
According to APRA, that mindset has contributed to gaps across the AI lifecycle, including weak controls over post-deployment monitoring, model behaviour monitoring, change management and decommissioning.
The regulator said entities should establish formal governance frameworks, clear ownership and accountability from design through to deployment and retirement, inventories of AI tools and use cases, and human oversight for high-risk decisions.
Cyber security was another major theme, with APRA warning AI is materially reshaping the threat landscape by creating more attack pathways and enabling faster, more coordinated attacks.
The regulator highlighted prompt injection, data leakage, insecure integrations, exploit injection and misuse of autonomous AI agents among the common risks emerging across regulated industries.
The regulator also said some entities’ identity and access management controls had not yet adapted to non-human actors such as AI agents, while AI-assisted software development was placing strain on traditional change and release controls.
Patching, configuration management and broader remediation efforts were not always keeping pace with the faster-moving threat environment.
Another concern was the use of enterprise AI tools by staff outside approved control frameworks. APRA said many entities were still relying too heavily on policy settings or detective measures after the fact, rather than enforceable technical restrictions and preventative controls.
Supplier concentration and opacity also featured prominently in the regulator’s findings. APRA said some entities were heavily dependent on a single provider for multiple AI use cases without robust contingency planning or tested exit and substitution strategies, while contractual arrangements often lagged practice and provided limited protections around audit rights, model updates, incident notification and changes to data handling.
That warning may resonate strongly in superannuation, where trustees remain heavily reliant on administrators, custodians, platforms and other external providers.
APRA said entities should be able to map the full AI supply chain, including material third-party and fourth-party dependencies, and actively manage concentration risk where common platforms or providers are involved.
Traditional assurance methods were also described as increasingly inadequate. APRA said point-in-time and sample-based approaches were poorly suited to probabilistic models that can learn, drift or degrade over time, while internal audit and risk functions often lacked the specialist skills and tools needed to independently assess AI systems, particularly where agentic behaviour or AI-assisted code generation was involved.
The regulator said second-line risk and internal audit teams would need stronger technical capability and tooling, while monitoring should be continuous and proportionate to the criticality of each use case, including consideration of model purpose, limitations, explainability and potential customer impacts.
Although APRA said its prudential framework remains technology and vendor agnostic, it made clear AI adoption will remain an active supervisory priority as it finalises its forward plan for prudential reviews, thematic activities and supplier engagement.
“Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, we will take stronger supervisory action and, where appropriate, pursue enforcement.”





