Home/APRA CPS 230 and AI agents
Australia

APRA, ASIC and AI agents

Neither APRA nor ASIC has issued an AI-specific rulebook, and both have said the existing ones already apply. That makes the obligations live now rather than pending - and both regulators have named third-party dependency management as the weak point.

Scope of this page

This is a practitioner's orientation, not legal or compliance advice, and it is not a claim of certification. Obligations depend on your entity class and circumstances — read it with your risk and legal functions, against the current text of the standards themselves.

The APRA position, in short

Rather than write a new prudential standard for artificial intelligence, APRA has signalled that the existing suite already covers AI-related conduct: CPS 230 on operational risk management, CPS 234 on information security, CPS 220 on risk management and CPS 510 on governance.

That is a more demanding position than a new standard would have been, not a lighter one. A new standard arrives with a transition period. Applying existing standards means the obligations already attach to whatever you deploy this quarter.

APRA's 2026 industry letter on artificial intelligence drew on a targeted review which found governance, risk management, assurance and operational resilience practices were not keeping pace with AI deployment. The letter specifically flagged manipulation or misuse of autonomous AI agents, alongside prompt injection, data leakage and insecure integrations as common attack pathways.

CPS 230: operational risk and service providers

CPS 230 requires regulated entities to manage operational risk, maintain critical operations through disruption, and manage the risks arising from service providers. Agents transacting with external parties engage all three:

  • Operational risk. An agent acting on your behalf with an unverified counterparty is an operational exposure whose likelihood and impact you are expected to have assessed.
  • Critical operations. Where an agent-mediated exchange sits inside a critical operation, tolerance levels and the ability to continue through disruption apply to it.
  • Service provider management. The one most often missed. Material arrangements must be identified, assessed and contractually addressed — and an external MCP endpoint your agents depend on is an arrangement, whether or not anyone signed a services agreement for it.
The dated obligation

Contracts with material service providers, AI vendors included, are expected to be brought into line with CPS 230 at next renewal and no later than 1 July 2026. If agent-mediated dependencies are not yet in your service provider register, that is the first gap to close — you cannot contract for what you have not enumerated.

CPS 234: information security

CPS 234 requires information security capability commensurate with the threat, clearly assigned roles, controls over information assets, and systematic testing of control effectiveness. Deploying an autonomous agent with known vulnerabilities and no enterprise security model onto systems that process customer financial data sits in direct tension with it.

The agent-specific difficulty is that CPS 234 assumes you can enumerate your information assets and who has access to them. Agents undermine both assumptions when they are provisioned outside governance, share service accounts, or inherit a human's full permission set because that was the only credential available. Those failure modes are set out in agent-to-agent authentication.

ASIC REP 798: the vendor-management finding

APRA is not the only Australian regulator to have looked at this. ASIC's REP 798, Beware the gap: Governance arrangements in the face of AI innovation, reviewed AI use across 23 AFS and credit licensees covering 624 use cases in retail banking, credit, general and life insurance, and financial advice.

Its central finding was a gap rather than a breach: licensees are adopting AI faster than they are updating the risk and compliance frameworks around it. ASIC's position mirrors APRA's — existing obligations already apply, and licensees must satisfy themselves about them before deploying, not after.

The finding that matters here

Two weaknesses recurred across the review: nearly half of licensees had no fairness or bias policy for algorithmic systems, and many had inadequate third-party vendor management. The second is precisely the exposure an agent creates when it starts calling an external endpoint nobody assessed — the dependency is real, material, and typically undocumented.

Read alongside CPS 230's service provider requirements, the two regulators are pointing at the same control from different directions: know who you depend on, assess it, and be able to evidence both.

Where agents create the exposure

ExposureStandard engagedTypical gap
Unverified counterparty endpointCPS 230, CPS 234Trust decision made by whoever added the configuration
Undocumented external dependencyCPS 230Never entered in the service provider register
Over-privileged agent credentialsCPS 234Agent inherits a human's full access
No attribution for agent actionsCPS 230, CPS 510Shared service accounts
No independent record of exchangeCPS 230Application logs only
No ability to sever quicklyCPS 230Revocation requires counterparty cooperation

Mapping controls to evidence

Supervisors and internal audit ask for evidence of control effectiveness, not descriptions of intent. What MCPLayer supplies at the organisational boundary maps onto that request as follows:

Control expectationEvidence available
Counterparty identity is establishedEntity, domain and licence verification behind every attestation, re-checked per exchange
Access is proportionate to purposeDeclared data class, direction, purpose and scope, enforced inline rather than reviewed afterwards
Actions attributable to an accountable partyBoth attested organisations and the specific agent recorded against every exchange
Control effectiveness is testableReplayable ledger showing which policy permitted each exchange
Dependencies can be severedInstant, network-wide revocation of any party or any scope
Data handling is containedBoundary minimisation, and zero-retention for nominated data classes

To be precise about what this is: MCPLayer supplies control evidence at the boundary between organisations. It does not make an entity compliant, and no platform can — compliance is a property of your governance, of which this is one input.

A practical sequence

  1. Enumerate. List every external endpoint your agents already reach. Most organisations find more than the register shows.
  2. Classify. For each, identify the data class and whether the arrangement is material under CPS 230.
  3. Establish identity. Determine how you currently know each counterparty is who it claims to be. Where the answer is “a colleague configured it”, that is the finding.
  4. Close the contract gap. Material arrangements need CPS 230-aligned terms by 1 July 2026 at the latest.
  5. Fix evidence before scale. Attribution and record-keeping are far cheaper to build in before an agent programme scales than to retrofit afterwards.
Is there a specific APRA standard for AI?

No, and APRA has signalled it does not intend to write one. Its position is that CPS 230, CPS 234, CPS 220 and CPS 510 already reach AI-related conduct, which means obligations apply to systems in production now rather than after a transition period.

Does an external MCP endpoint count as a service provider?

Where your agents depend on it as part of a business operation, it is an arrangement to be assessed for materiality under CPS 230 — regardless of whether procurement was ever involved. Take advice on your circumstances; the practical risk is that these dependencies were never registered because they were created as configuration rather than contract.

Is data held in Australia?

Australian regions first, with per-organisation key management and rotation. Full detail on the security posture page, which is written for vendor risk questionnaires.

Does using MCPLayer make us CPS 230 compliant?

No. Compliance is a property of your governance and no vendor can confer it. What MCPLayer supplies is control evidence at the boundary between your organisation and others — verified counterparty identity, enforced policy, attribution and a replayable record — which is the part that is hardest to produce for yourself.

Founding cohort

Built for the questionnaires Australian regulators actually send.

Founding members across banking, insurance and government shape the control and evidence schema directly.

Apply for the founding cohort