AI is testing cyber controls. Can you prove yours hold up?
AI is lowering the barrier to sophisticated attacks and shrinking the gap between a vulnerability...
Between 30 April and 22 June 2026, three separate regulatory bodies wrote to Australian organisations about the same issue. The Australian Prudential Regulation Authority (APRA), the Australian Securities and Investments Commission (ASIC), and the cybersecurity agencies of the Five Eyes alliance each warned that artificial intelligence (AI) is changing the pace and scale of cyber-attacks – and each put the responsibility for addressing it squarely on boards and executives.
None of them called for new technology. All three asked for the same thing: proof that existing controls are actually working.
For organisations building a case for ISO 27001, and increasingly asking about ISO 42001, this is about as clear a signal as regulators are likely to give.
APRA’s 30 April letter followed a targeted review of large banks, insurers and superannuation trustees. It found that AI governance, risk management and assurance practices haven’t kept pace with adoption, and called for a step-change – clear AI governance frameworks, defined accountability, AI inventories and risk classification, and stronger cyber and third-party controls.
ASIC’s 8 May open letter to AFS licensees and market participants took a similar line on cyber resilience more broadly. Its message: don’t wait for perfect clarity on the AI threat – act now, and act with discipline, on the fundamentals. It listed specific expectations, including reassessing cyber and incident response plans, reviewing user access and privileged accounts, patching promptly, and minimising attack surfaces. Critically, ASIC said governance shouldn’t rely on assurances alone – it should be backed by evidence: test results, audit findings, and independent validation.
The Five Eyes joint statement on 22 June, issued by the cyber security agencies of Australia, Canada, New Zealand, the UK and the US, reinforced the same points from an intelligence perspective. AI is lowering the barrier to sophisticated attacks and shrinking the gap between a vulnerability being discovered and being exploited. Their recommendations: treat cyber risk as a board and executive responsibility, prioritise foundational controls, strengthen identity and access management, and build resilience on the assumption that breaches will happen.
Read together, the letters converge on the same handful of fundamentals: access control, patching, incident response and third-party risk management. None of the regulators is asking organisations to reinvent their approach. They’re asking for consistent execution of well-established controls, supported by clear governance and evidence that those controls hold up under scrutiny – not just policies sitting in a folder.
They also agree on where accountability sits. All three name cyber and AI risk as a board and executive-level responsibility, not something to be delegated to IT and left there.
This is where a certified management system comes in. ISO 27001 exists to systemise the fundamentals these regulators are describing: risk assessment, access control, patching and vulnerability management, incident response, and supplier and third-party oversight, all built into a structured, independently audited system rather than a set of standalone policies.
The independent audit is the part that matters most here. Regulators are explicit that assurance built on self-reported policy isn’t enough – they want evidence the controls are tested and effective. A certified information security management system (ISMS) under ISO 27001 provides exactly that: a structured basis for demonstrating, with independent verification behind it, that fundamentals are in place and being reviewed on an ongoing cycle.
ISO 42001 sits alongside this as the emerging standard specifically for AI governance – the layer ISO 27001 doesn’t reach. It follows the same management system structure as ISO 27001, but addresses AI-specific concerns: governance and accountability for AI systems, risk management across the AI lifecycle, human oversight of AI-assisted decisions, and transparency. Given that all three regulators explicitly flagged AI governance as an emerging accountability gap, it’s a standard worth understanding now, even for organisations not yet ready to pursue it.
To be clear about the limits: certification to ISO 27001 or alignment with ISO 42001 doesn’t satisfy any of these regulators’ requirements on its own, and no certification body can claim otherwise. What it does is give an organisation a structured, independently assessed way to demonstrate the fundamentals regulators are asking about – proportionate governance, evidenced controls, and a system for showing that oversight is real rather than aspirational.
For boards asking “how do we know our controls actually work, and how do we show it”, that’s a meaningfully different starting point to a policy collecting dust in a draw.
Three regulators making the same point within eight weeks isn’t a coincidence – it’s a signal that this is now a standing expectation, not a one-off warning. For organisations reassessing where their information security and AI governance stand, an independent, accredited assessment against ISO 27001 is a practical place to begin.
Get in touch with us to talk through what that would look like for your organisation.