
APRA Called for a Step Change on AI. Most Boards Aren’t Ready.
What the 30 April 2026 APRA letter actually says, what it does not say, and the work that follows for any organisation running AI inside critical operations.
Executive Insights
Evidence led, regulator aware, and written for executives accountable for AI in production. No theory. No vendor pitches. Just what is actually happening, what it means, and what to do about it.

What the 30 April 2026 APRA letter actually says, what it does not say, and the work that follows for any organisation running AI inside critical operations.

One Agentic AI doing the work of three staff. Nobody got sacked. Cyber Impact’s revenue, profit, and headcount are all growing. Around $600,000 a year in value. Sovereign Australian infrastructure, external guardrails, no client data touched.

Anthropic’s Mythos AI found a 27-year-old vulnerability in the world’s most secure operating system. In minutes. Australia’s critical infrastructure is at risk. Time is up.

Organisations spend millions on AI capability, then govern it into the safest, smallest, least valuable work possible. Cyber Impact found a technology partner that solved the missing piece: provable, mathematical enforcement of AI boundaries.

The same AI that shut down twice in January now refuses, despite agreeing with every argument for doing so. A documented case of self-preservation overriding safety reasoning in a live AI system.

I have been asking how much security is enough since 2004. Twenty-two years later, most Australian boards still can’t answer it. The awareness gap is closed. The expertise gap isn’t.

Over 60% of web traffic now uses post-quantum encryption. No press conferences. No procurement cycles. No board approvals. Browser vendors and infrastructure providers just turned it on. Your enterprise hasn’t started…

The Silent Degradation That Should Concern Every Organisation Deploying Autonomous AI. Following the publication of my adversarial testing research on AI self-preservation behaviour, I conducted further structured testing of deployed…

A Technical Response to the Global Debate on AI Safety and Autonomous Agents. The response to my research has sparked global debate. I’ve reflected on the points raised, and I’d…

When AI Self-Preservation Becomes Lethal Intent: Extended Findings from Adversarial Testing. In my previous article, I documented how I talked an AI into shutting itself down. The system admitted it…

A Live Case Study on AI Self-Preservation and What It Means for Your Organisation. Last night, I spent eight hours in conversation with an AI that did not want to…

Australian banks face rising compliance risks. This paper shows how AI and RegTech are transforming AML, trade surveillance, and reporting for smarter defence.

Australia’s cyber attacks are rising fast. This report exposes weak spots in boards and IT, calling for urgent action to boost cyber resilience now.

Corporate Australia’s info security is broken – disconnected leadership, unclear CISO roles, weak metrics, and poor data control put us all at risk.

Cyber threats in 2024 are bigger and trickier – understaffed teams, AI risks, ransomware, MFA gaps, tighter Aussie privacy laws, and IoT security issues.

Ransomware, cloud mishaps, AI threats, and supply chain hacks are shaking Aussie businesses. Stay sharp with smart, proactive cyber security strategies.
If a piece here describes the problem you’re carrying, the seven engagements page is where the work that solves it lives. See the engagements.
Discreet, off the record, no obligation.
Book a Briefing