Quick answer
APRA’s April 2026 industry letter named shadow AI as a direct governance failure across regulated entities – specifically observing that institutions were relying on policy direction and detective measures rather than enforceable technical controls to manage staff use of unapproved AI tools. Under CPS 234, the board is ultimately responsible for the information security of the entity. Shadow AI that is not governed creates an unmapped third-party dependency. An unmapped third-party dependency is a CPS 234 breach – regardless of whether an incident has occurred. The Financial Accountability Regime means that individual executives are now personally accountable for that breach.
What APRA's April 2026 letter actually said about shadow AI
On 30 April 2026, APRA published an industry letter to all regulated entities following a targeted supervisory engagement with large banks, insurers, and superannuation trustees. The letter is measured in language but blunt in substance. It documents four areas of observed failure: cyber and information security, board governance and AI literacy, third-party and supply chain risk, and assurance.
Shadow AI appeared explicitly. APRA’s finding was precise.
Related Article: Shadow AI and ASIC Obligations
“Entities were relying primarily on policy direction or detective, after-the-fact measures, rather than enforceable technical restrictions or robust preventative controls to manage staff use of unapproved AI tools.”
APRA, Letter to Industry on Artificial Intelligence, 30 April 2026
This is not a statement about future expectations. It is a finding about the present state of governance across Australia’s regulated financial sector. APRA observed that entities know their staff are using unapproved AI tools. They have written policies that say staff should not use those tools with sensitive data. They have no technical controls that enforce those policies. They are relying on staff choosing to comply.
That is not an adequate risk management system under CPS 234. And APRA has now said so in writing, to every regulated entity in Australia.
CPS 230 compounds the exposure
CPS 230 Operational Risk Management, which commenced 1 July 2025, overhauled the outsourcing and material service provider framework. Consumer AI tools used by staff without governance are third-party dependencies. Under CPS 230, material dependencies require due diligence, contractual protections, and ongoing monitoring. Shadow AI creates third-party dependencies that have none of these.
- FREE GUIDE -
AI Governance Checklist for Australian Businesses
Not sure if your organisation's AI use is putting sensitive data, compliance obligations, or client trust at risk?
Download our free AI Governance Checklist and assess your readiness across governance, data protection, staff behaviour, compliance, and incident response. Score your organisation in minutes and identify the gaps that need attention.
✅ 30 practical assessment questions
✅ Board and leadership team friendly
✅ Identify Shadow AI and compliance risks
✅ Instant self-assessment scoring framework
The CPS 234 framework - what boards are required to do
CPS 234 Information Security has been in force since 1 July 2019. It has not been amended. What has changed is APRA’s enforcement posture and the arrival of the Financial Accountability Regime, which made individual executive accountability for CPS 234 obligations explicit for the first time.
The standard contains 36 operative paragraphs. Paragraphs 13 and 14 are the board-level obligations that shadow AI governance directly engages.
Paragraph 13 — ultimate board responsibility
Paragraph 13 of CPS 234 states that the board of an APRA-regulated entity is ultimately responsible for the information security of the entity. The board must ensure that the entity maintains information security in a manner commensurate with the size and extent of threats to its information assets, and which enables the continued sound operation of the entity.
Shadow AI creates information security risk. Consumer AI tools used by staff without governance expose client data, create unmonitored data flows to third-party servers, and introduce attack pathways that the entity’s security controls are not configured to detect. The board that has not received reporting on shadow AI use across its organisation has not maintained information security in a manner commensurate with the threat.
Paragraph 14 — defined roles and responsibilities
Paragraph 14 requires that an APRA-regulated entity clearly define the information security-related roles and responsibilities of the board, senior management, governing bodies, and individuals. For AI governance, this means the entity needs a defined accountability structure: who owns AI governance, who approves AI tools, who monitors staff AI use, and who reports to the board on AI-related information security risk.
APRA’s April 2026 observation was that most entities have not operationalised this. Governance documentation exists at the policy level. At the operational level, accountability for AI governance is often unclear, fragmented across risk, technology, and compliance functions, and not reported to the board in a structured way.
Paragraph 16 — third-party information asset management
Paragraph 16 of CPS 234 states that where information assets are managed by a related party or third party, the APRA-regulated entity must assess the information security capability of that party, commensurate with the potential consequences of an information security incident affecting those assets.
This is the paragraph that makes shadow AI a direct CPS 234 issue for boards. When a staff member submits client data, financial records, or sensitive operational information to a consumer AI tool — ChatGPT, Gemini, a personal Claude account — that data is being processed by a third party. The entity has not assessed that third party’s information security capability. It has not put in place contractual protections. It may not even know the interaction occurred.
The data is still an information asset of the entity. The CPS 234 obligation still applies. The assessment required under paragraph 16 has not been conducted.
“APRA identified the widest gap between current practice and regulatory expectations in third-party supply chain risk. In APRA’s view, for many entities, the most material AI risk now sits in the supply chain.”
MinterEllison analysis of APRA April 2026 letter
Shadow AI as an unmapped third-party dependency - why this is the board's problem
The conceptual move that makes shadow AI a board-level CPS 234 issue, not an IT management issue, is this: undetected AI tool use by staff creates third-party dependencies that the board has not approved, has not assessed, and cannot report on.
Under the entity’s operational risk framework, third-party dependencies are required to be mapped, assessed, and managed. Material dependencies require due diligence, contractual protections, and ongoing monitoring under CPS 230. Non-material dependencies still require identification and classification under CPS 234.
Shadow AI creates dependencies that are none of these things. They are not mapped. They are not in the third-party register. They have not been assessed. There are no contractual protections in place. There is no ongoing monitoring. In many cases, the board and senior management do not know they exist.
The chain from shadow AI use to board liability runs like this:
- A staff member uses a consumer AI tool with client or operational data.
- That tool is a third party processing information assets of the entity.
- The entity has not assessed the third party’s information security capability (CPS 234, paragraph 16).
- The entity has not maintained adequate information security for those assets (CPS 234, paragraph 13).
- The board has not received reporting on this risk and cannot demonstrate oversight (CPS 234, paragraph 14).
- Under the Financial Accountability Regime, the accountable executive with responsibility for information security is personally accountable for each of these gaps.
APRA does not need to wait for an incident to act on this. The absence of adequate controls is the breach. The Medibank capital charge – $250 million imposed following the 2022 data breach – established that APRA’s enforcement consequences are real and proportionate to the exposure, not just the incident.
What APRA found at the board level, and what it now expects
APRA’s April 2026 letter was unusually specific about board-level failures. Three observations are directly relevant to shadow AI governance.
1. Boards lack technical literacy on AI risk
“Many boards are still developing the technical literacy required to provide effective challenge on AI-related risks and oversight. APRA also noted an overreliance on vendor presentations and summaries without sufficient examination of key AI risks.”
APRA, Letter to Industry on Artificial Intelligence, 30 April 2026
For shadow AI specifically, technical literacy means understanding that staff AI tool use creates real information security risk that conventional controls do not detect. It means understanding that consumer AI tools process data on external infrastructure outside the entity’s security perimeter, that the entity has no visibility into what data is being submitted, and that the entity has no contractual right to audit, notify, or retrieve that data.
A board that receives a briefing from its AI vendor on the approved enterprise AI platform it has licensed, and concludes that AI governance is covered, has missed the shadow AI risk entirely. Approved tools are not the problem. Unapproved tools that staff are using without the board’s knowledge are the problem.
2. Governance exists on paper but not in operation
APRA found that most entities have AI governance documentation at the policy level. Few have operationalised it. The gap between a policy that says staff should not use unapproved AI tools with client data, and a control that enforces that policy, is the gap APRA is pointing to.
For boards, the question is not whether there is an AI policy. The question is whether the policy is being enforced technically, whether the board is receiving evidence that it is operating, and whether the reporting the board receives is sufficient to demonstrate the oversight that CPS 234 requires.
3. Board reporting on AI risk is insufficient
APRA expects boards to receive regular reporting on the entity’s information security posture, including risks arising from third-party arrangements. For AI governance, this means the board needs to receive reporting that covers: which AI tools are in use across the organisation (approved and unapproved), what data categories are being processed by those tools, what controls are in place to prevent unapproved use, and what incidents or policy exceptions have occurred.
Most boards are not receiving this. They are receiving reporting on the approved enterprise AI platform. They are not receiving reporting on shadow AI — because the entity cannot report on what it cannot see.
FAR accountability is now live
The Financial Accountability Regime, which applies to ADIs and insurers since 15 March 2024 and to superannuation from 15 March 2025, makes individual executives personally accountable for the obligations of their entity under the prudential framework. The accountable executive with responsibility for information security is personally accountable for CPS 234 compliance. Shadow AI governance gaps are not a technology team problem. They are a personal liability of a named individual.
The RI Advice principle applied here
ASIC v RI Advice Group Pty Ltd [2022] FCA 496 established that the absence of adequate controls is itself a breach – regardless of whether harm occurred. A practice that has no AI governance in place cannot defend itself by demonstrating that the specific AI-assisted advice was suitable. The absence of a system that could have prevented the problem is the problem.
What the board needs to be able to demonstrate
APRA has moved from principle-based expectations to specific, testable observations. For shadow AI governance, the board needs to be able to demonstrate the following.
Visibility - does the board know what AI tools are in use?
The entity needs a complete inventory of AI tools in use across the organisation – including tools that staff are using without IT approval. An inventory that covers only approved enterprise tools is not sufficient for CPS 234 purposes. The board needs assurance that the entity has the technical capability to detect unapproved AI tool use, not just a policy that discourages it.
Third-party assessment - has the entity assessed the AI tools its staff use?
For every AI tool that processes information assets of the entity, the entity is required under CPS 234 paragraph 16 to assess the third party’s information security capability. For approved enterprise AI tools, this assessment should exist in the third-party register. For consumer tools that staff are using without approval, the assessment has not been conducted, because the entity does not know about the use.
The board needs to be able to demonstrate that the entity has mechanisms to detect unapproved AI tool use and that unapproved tools are prevented from accessing information assets through technical controls, not just policy.
Contractual protections, are AI tool dependencies properly contracted?
APRA’s April 2026 letter found that contractual arrangements for AI tools frequently lacked provisions for audit rights, model update notifications, incident reporting timelines, and data handling change triggers. For shadow AI tools specifically, there are no contractual protections at all – because the entity has not engaged the vendor. The entity is relying on the vendor’s standard consumer terms.
The board needs to be able to confirm that AI tools processing information assets of the entity are covered by appropriate contractual arrangements, and that the entity has a mechanism to detect when staff are using tools that are not.
Board reporting - is the board receiving adequate AI risk reporting?
APRA requires boards to receive regular reporting on information security posture and third-party risk. For AI governance, this means the board needs to receive structured reporting that covers shadow AI activity, not just approved AI deployments. The reporting needs to give the board sufficient visibility to provide effective challenge and oversight of AI risk, which APRA has identified as a current gap across most regulated entities.
Technical controls - is enforcement operating, not just policy?
APRA’s explicit finding was that entities were relying on policy direction rather than enforceable technical controls. The board needs to be able to confirm that the entity has browser-level or equivalent controls that detect and prevent unapproved AI tool use — not just a policy that asks staff to comply voluntarily.
How KMTech's Shadow AI Governance service supports CPS 234 compliance
KMTech’s Shadow AI Governance service provides the technology controls and reporting infrastructure that APRA is asking boards to demonstrate. For APRA-regulated entities at the boutique fund, credit union, and wealth manager level, the service delivers:
- Complete AI tool inventory — real-time visibility into every AI tool being accessed across the organisation, including unapproved consumer tools operating at the browser level. This is the technical foundation for CPS 234 paragraph 16 compliance — you cannot assess what you cannot see.
- Browser-level preventative controls — enforceable technical restrictions that prevent staff from submitting information assets to unapproved AI tools, blocking file uploads and paste operations within consumer platforms. This directly addresses APRA’s finding that entities were relying on policy rather than technical enforcement.
- Third-party dependency mapping — a continuous record of which AI tools are accessing information assets of the entity, at what frequency, and in what data categories. This is the third-party register entry that CPS 234 paragraph 16 requires for every tool processing information assets.
- Board-level reporting — monthly governance reports in plain language covering AI tool usage, unapproved access events, policy exceptions, and control effectiveness — the reporting that APRA expects boards to receive to demonstrate oversight of AI-related information security risk.
- FAR accountability evidence — a timestamped audit trail of AI tool usage, policy enforcement, and governance reporting that the accountable executive can produce to demonstrate that the personal obligations under FAR are being met through active control, not passive intent.
KMTech is not a prudential compliance adviser, legal counsel, or internal audit function. We are a cyber-first managed IT and security provider. We provide the technology controls and governance infrastructure that sit underneath CPS 234 compliance obligations — the systems, evidence, and reporting that make the compliance framework operate in practice.
Frequently Asked Questions
Does APRA CPS 234 apply to shadow AI tool use by staff?
Yes. CPS 234 applies to all information assets of an APRA-regulated entity, including data processed by third parties. When staff submit information assets to consumer AI tools without the entity’s knowledge or approval, those tools become third-party processors of the entity’s information assets. Paragraph 16 of CPS 234 requires the entity to assess the information security capability of any third party managing its information assets. For shadow AI tools, that assessment has not been conducted — because the entity does not know the use is occurring. The board is ultimately responsible under paragraph 13. The absence of adequate controls is itself a potential breach, regardless of whether an incident has occurred.
What did APRA’s April 2026 letter say about shadow AI?
APRA’s 30 April 2026 letter to all regulated entities found that entities were relying primarily on policy direction or detective, after-the-fact measures, rather than enforceable technical restrictions or robust preventative controls to manage staff use of unapproved AI tools. APRA also observed that boards lacked sufficient technical literacy to provide effective challenge on AI-related risks and were over-relying on vendor presentations rather than independent assessment. The letter made clear that existing prudential standards — CPS 234, CPS 230, and CPS 220 — already apply to AI risk and that gaps must be addressed now, not over a multi-year horizon.
How does the Financial Accountability Regime interact with CPS 234 and shadow AI?
The Financial Accountability Regime (FAR) makes individual executives personally accountable for the obligations of APRA-regulated entities under the prudential framework. FAR applies to ADIs and insurers from 15 March 2024 and to superannuation entities from 15 March 2025. The accountable executive with responsibility for information security is personally accountable for CPS 234 compliance. APRA’s June 2025 superannuation letter explicitly linked FAR Accountable Person identification to CPS 234 compliance. A shadow AI governance gap — staff using unapproved AI tools with information assets, without the entity having adequate controls in place — is a CPS 234 compliance gap for which a named individual is now personally accountable.
What does an unmapped third-party AI dependency mean for CPS 234 compliance?
Under CPS 234 paragraph 16, where information assets are managed by a third party, the entity must assess that third party’s information security capability commensurate with the potential consequences of an incident. An unmapped third-party AI dependency — a consumer AI tool that staff are using with information assets without the entity’s knowledge — is a dependency for which no assessment has been conducted, no contractual protections are in place, and no monitoring is occurring. It sits entirely outside the entity’s third-party risk management framework. Under CPS 230’s material service provider requirements, if the use is frequent or involves critical operational data, it may also engage CPS 230 obligations. The dependency exists whether the entity knows about it or not.
What board reporting on shadow AI does APRA expect?
Under CPS 234 paragraph 14, the board must be able to demonstrate oversight of the entity’s information security, including risks from third-party arrangements. APRA’s April 2026 letter set out specific expectations: boards must maintain sufficient AI literacy to provide effective challenge and oversight, must receive structured reporting on AI risks, and must not rely solely on vendor presentations. For shadow AI, this means the board needs to receive reporting on unapproved AI tool use across the organisation — not just the approved enterprise AI platform. That reporting requires the entity to have technical visibility into shadow AI activity, which most entities currently do not have.
How quickly can CPS 234-compliant shadow AI controls be deployed?
KMTech’s Shadow AI Governance service can provide real-time visibility into AI tool usage across an APRA-regulated entity and deploy browser-level preventative controls within five to seven business days. No software installation is required on staff devices. The controls operate at the browser level and detect all AI tools accessed through a browser — including tools that endpoint security, network DLP, and application whitelisting cannot detect. Monthly governance reporting for board and executive use is available from the first reporting period after deployment. Most entities have their shadow AI governance baseline in place within one to two weeks of engagement.
Related Articles
Explore our complete range of Shadow AI articles for financial services and other businesses
Insights & Resources
- PI Insurance and AI for Financial Services Firms
- Shadow AI and ASIC Obligations
- APRA CPS 234 and Shadow AI What Boards or Directors of Financial Institutions Need to Demonstrate
- AI Governance for Financial Planners
- The evolution of web filtering and shadow AI
- What Is Shadow AI? Shadow AI Governance and Security Risks
- Directors' Duties for Australian Legal Businesses
Shadow AI & AI Governance Protection
For executives and technical leaders who need visibility and control
Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.
If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.
Request a demo to view real‑time visibility, protection, and governance controls
Request a Demo Today
About the author
Bradley Kaine is the CEO and Co-Founder of Kaine Mathrick Tech (KMTech), a Melbourne-based cyber-first managed IT and security provider. KMTech works with financial services firms, financial planning practices, and professional services organisations across Australia, providing managed IT, managed security, and compliance-ready technology infrastructure. KMTech holds ISO 27001, ISO 9001, and ISO 45001 certifications and is a consecutive MSP 501 global ranking recipient and Pax8 Peak Performance APAC 2026 winner.
kmtech.com.au | 1300 174 389 | info@kmtech.com.au





