Agentic AI is already querying member records, triaging hardship applications, and drafting correspondence inside Australian superannuation funds, but most deployments cannot say who set the agent in motion or whether its access matched what was authorised. APRA named this gap directly in its 30 April 2026 Letter to Industry, and new Privacy Act disclosure rules land on 10 December 2026. This guide sets out the specific architecture failure behind the gap and the federated identity gateway pattern that closes it, using established identity principles rather than new technology.
Full guide delivered to your inbox
Covers the architecture of the identity gap, from the MCP server call into the registry or core platform, through to the specific APRA and Privacy Act obligations that apply from 30 April and 10 December 2026, and the federated identity gateway pattern that restores a traceable link between every AI agent action and the person who authorised it. Closes with a six-action checklist to run before your next AI deployment.
Includes the two request-flow diagrams showing where identity drops out and how a gateway restores it, the specific APRA and Privacy Act obligations superannuation funds face from April and December 2026, and a six-action pre-deployment checklist.
No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.
Read enough? The guide is one form away.
Get the guideIn its 30 April 2026 Letter to Industry on Artificial Intelligence, APRA found that identity and access management capabilities across the banks, insurers, and superannuation trustees it reviewed have not adjusted to non-human actors such as AI agents. It also flagged that security testing does not yet cover AI attack surfaces and that attack pathways now include the manipulation of autonomous agents.
From 10 December 2026, new provisions (APP 1.7 to 1.9) require organisations to state in their privacy policy the kinds of personal information used by, and the kinds of decisions materially shaped by, a computer program. The threshold covers anything substantially and directly related to a decision that could significantly affect someone's rights or interests, which includes an AI agent triaging hardship applications or scoring a group insurance claim.
It is a gateway placed between the MCP server and the core platform that checks, before any data returns, that the person behind a request was allowed to ask for it and that the agent making the request is the one they authorised. A human authenticates as normal, and when their action triggers an agent, that agent inherits a scoped, time-limited credential carrying the human's identity context, checked against policy at every request.
The Financial Accountability Regime, in force for superannuation trustees since 15 March 2025, requires named accountable persons to hold senior executive responsibility for defined areas of the business. If an accountable person cannot show that an AI agent's action traces back to an authorising human, the evidence chain their accountability rests on has a hole in it, which is why agent identity is foundational to FAR compliance rather than a separate project.
Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.