Australian regulators told financial firms today (Thursday) to set crisis authority and recovery priorities before a frontier AI-enabled cyberattack compresses decision time. The call followed nine roundtables with more than 600 attendees from over 380 entities.
The warning reaches retail trading. The Australian Securities and Investments Commission (ASIC) addressed all licensees and market participants in May.
A separate ASIC review recently covered nine online brokers. Client access, payments and trading platforms can all become recovery priorities.
The Australian Prudential Regulation Authority (APRA) and ASIC held the meetings in June and July. Participants included market infrastructure operators, intermediaries, payment providers, financial services firms and technology suppliers.
The regulators published no firm-level responses or incident statistics. The findings are not a measure of sector-wide compliance.
Boards Told to Decide Before an Incident
The regulators want boards to settle who can escalate an incident, order a shutdown, set recovery priorities and approve communications before a crisis starts.
Risk appetite, reliance on suppliers and resilience spending also belong in those pre-agreed decisions, according to the information paper.
Evidence of preparedness could include clear decision-making authority, tested escalation paths and crisis exercises. ASIC and APRA said a firm should treat any decision that would be debated for the first time during an incident as a priority gap.
"Australia's financial system is only as resilient as its weakest link," ASIC Commissioner Simone Constant said.
- ASIC Sets Q4 Consultation on CFD Leverage Rules Ahead of 2027 Expiry
- Court Appoints Provisional Liquidators to 12 Companies After A$182 Million Raise
- ASIC Removes Over 19,400 Scams as AI Deepfakes Target Investors
Technical controls remain part of the test. Firms were told to map critical assets, patch vulnerabilities, restrict privileged access and test backups against faster attack timelines.
ASIC's May letter also said cyber resilience is a licensing obligation, not simply an information technology issue.
Roundtable participants said Anthropic's publication about its Mythos model increased board engagement.
Anthropic reported in April that Mythos Preview could find and exploit vulnerabilities across major operating systems and browsers. The results came from the model developer's own testing.
AI Has Reached Live Trading Accounts
The board questions have a direct application in retail trading as AI moves closer to accounts and execution. Capital.com connected AI agents to its MENA trading service in June, with two confirmations required before an agent can place a trade.
Interactive Brokers later opened its account connector to outside tools using the Model Context Protocol. The AI can read account information and draft instructions, but the client must convert each instruction into an order.
The connection now also reaches a broker's internal systems. Your Bourse opened its Trade Server to AI assistants this month.
Authorized staff can query exposure and initiate hedges or position closures. Actions affecting positions or funds require human confirmation.
Those deployments use different permission models. They still require brokers to decide what happens if an AI tool, identity control or connected provider behaves unexpectedly while client accounts or open positions are affected.
Shared Providers Can Spread an Outage
ASIC and APRA identified cloud services, software providers, AI model companies, open-source components, payment infrastructure and telecommunications as common dependencies. A failure at one provider could interrupt several financial firms and markets at the same time.
Provider concentration is already visible outside Australia. A recent FM Intelligence review of European securities firms found that 41% of 397 respondents answering a hosting question relied on a single commercial provider.
Other regulators have raised the same operational issue. France's AMF put AI-enabled threats and third-party oversight into its 2026 cyber work while applying the European Union's Digital Operational Resilience Act.
Participants showed interest in defensive AI for threat intelligence, vulnerability detection, code review and incident response. The Australian report said governed, measurable and scalable capability remains limited and cannot replace basic cyber controls.
The joint paper sets no new rule or compliance deadline. It asks firms to produce evidence that governance, escalation and recovery processes work under shorter incident timelines, and ASIC and APRA said the issue will remain a heightened supervisory focus.