Green-toned graphic illustrating AI risk management in financial services, with a hand selecting 'Reduce' among risk strategies including accept, avoid, transfer, mitigate, and control.

AI risks and the end of the warning phase

July 14, 20264 min read

AI risks and the end of the warning phase

For the past couple of years, financial services regulators have largely held a warning posture on artificial intelligence. They flagged the risks, ran surveys, opened consultations, and asked firms to pay attention. Over the past two months, that posture has changed. Across three jurisdictions, the message has hardened from "be aware" to "act now, and be ready to show us that you have."

It is worth looking at what has actually been said, because read together these interventions describe a single, coherent expectation.

In Australia, two regulators moved within weeks of each other. The Australian Prudential Regulation Authority (APRA) wrote to industry on AI on 30 April, with a consistent finding: adoption is outpacing the controls designed to govern it. The Australian Securities and Investments Commission (ASIC) followed on 8 May with an open letter to licensees, framing frontier AI as a material shift in the cyber threat environment and reminding firms that cyber resilience is a core licensing obligation, not an IT issue. ASIC did not stop at sentiment. It instructed boards to table the letter at their highest governance committees, turning a warning into a governance artefact that will sit on the record the next time the regulator engages.

The harder edge is enforcement. ASIC's letter followed a $2.5 million penalty against FIIG Securities for cyber failures under its licence obligations, the first civil penalty of its kind. The direction of travel is unambiguous: inaction is now the exposure.

What the regulators are not demanding is perfection. ASIC's own instruction was to act now and act with discipline, rather than wait for certainty. Speaking at the AFIA Risk Summit, APRA's Therese McCarthy Hockey urged firms to fight fire with fire, using AI to find and patch weaknesses faster than attackers can exploit them, while cautioning that access to frontier models is not the same as resilience. The fundamentals still carry the weight: governance, controls, testing, and contingency planning.

This is not only an Australian story. In the United Kingdom, the Financial Conduct Authority (FCA) has been equally clear that it expects firms to govern AI through frameworks already in place, principally the Consumer Duty and the Senior Managers and Certification Regime (SMCR), which makes a named senior manager personally accountable for consumer harm or bias produced by a model. As FCA executive director David Geale put it, individuals are on the hook, delegating a decision to an algorithm does not transfer the liability. However, just last week, in speeches from both the FCA and the Bank of England, there is a clear emphasis on the speed of change and that they will be agile and move as stewards, to keep pace. We may not see formal rule change due to this pace, but we could see changing regulatory expectations and interventions on a much shorter time horizon. The publication of the Mills Report last week reinforces that evidence of accountability and oversight is going to be critical, and soon.

In the European Union, the form differs but the direction does not. The high-risk provisions of the EU AI Act, which capture financial services uses such as credit scoring, were this year deferred to December 2027. The extension is real, but so is the work it presupposes: technical documentation, human oversight, and rigorous bias testing before deployment. The regulators have been explicit that the additional time is for doing the work, not for deferring it.

Place these side by side and the common thread is clear. None of these regulators is writing new rules for AI. All of them are saying that the existing rules already apply, that the expectation is now, and that the burden of proof sits with the firm. The era in which "we are still forming our view" was an acceptable answer is closing.

For those of us in compliance, risk, cyber, audit, and governance, that reframes the task. The reasonable position is not to have every answer. It is to be visibly moving: to reassess cyber and AI plans against the current threat environment, to know which assets and decisions matter most, to evidence rather than assert that controls are working, and to put the questions the regulators are now asking in front of the board before they are asked of us. A considered best guess, documented and revisited, is defensible. Standing still is not.

The warning phase is over. The question each of us might sit with is a simpler one: if a regulator asked tomorrow what we have actually done, would we have an answer, or only an intention?

Back to Blog