Thought Leadership

AI in Financial Services: The Case Against (Part II)

August 31, 2026

The benefits of AI adoption offer Australian financial services firms efficiency and better risk management. However, the same AI tech is expanding the attack surface faster than many Australian financial services licensees can identify, let alone defend against.

In Part II of this two-part series, we explore the risks and safe adoption of AI tools in Australian financial services businesses. 

A Glance at the Cyber Threat Landscape 

ASIC has issued an urgent call for a cybersecurity uplift, warning that emerging AI models can expose vulnerabilities at increasing speed, scale and attack sophistication. 

Vulnerabilities that once took experts years to find are now much easier to identify with AI tools. What we once knew as a “12-month risk horizon” has now compressed. This lowers the barrier to entry for non-sophisticated bad actors.

ASIC has reinforced its stance through enforcement action, ordering one licensee to pay a significant penalty for cybersecurity failures. The practical takeaway is that cyber controls must address the end-to-end risk landscape of the financial services business. 

Why AI Threats Matter for Fund Managers and Licensees

Security risks like algorithmic bias and data leaks have the potential to directly expose financial services organisations to regulatory liability, reputational harm and operational roadblocks. Here’s what you need to know about managing those risks:

Responsibility Lands on Boards

Cyber resilience should be treated as a core licensing obligation, not an IT issue, and that starts at the board and executive level. Boards must test systems, address weaknesses early and act before vulnerabilities are exploited.

Preparedness and Impact Look Different Across Organisations

When it comes to AI adoption, security and compliance preparedness of Australian financial services organisations varies widely. Even regulators are falling behind the pace of AI adoption in the sector they supervise.

Treat Third-Party Risk Like In-House Risk

Financial services businesses rely on third-party vendors, so a vendor weakness can pose latent threats to a financial services firm that shares infrastructure with them. This is especially the case when:

  1. The vendor's services create a concentration, with many clients relying on the same provider.
  2. There’s systemic exposure, such as a failure that could proliferate across the sector, not just one business.

Ultimately, financial services businesses must manage third-party risk to remain compliant. 

What Good Practice Looks Like

Here are five practical steps to take that help ensure your financial services firm is prepared for the explicit risk of AI:

  1. Reassess your cyber plans for today's threat environment.
  2. Strengthen core controls, patch systems and minimise attack surfaces.
  3. Review user access regularly and monitor for “insider threats.”
  4. Be prepared to handle incidents by maintaining and exercising incident response plans, including business continuity planning.
  5. Use AI defensively, where appropriate. For example, vulnerability detection and securing software before release.

Managing AI Risk: Next Steps

For financial services businesses in Australia, AI adoption requires a dual lens. The first is taking advantage of genuine opportunity, while the second is implementing disciplined, well-governed cyber risk management.

It’s a good idea to benchmark your cyber governance and incident response readiness against ASIC's expectations.

To ensure your AI and cyber risk frameworks meet regulatory expectations and are appropriately documented for board and licensing purposes, reach out to PMC Legal today. 

DOWNLOAD FILE

Similar Articles