Superannuation · Identity
Guide

Your AI agents can access your members' records. Can you prove they should?

Agentic AI is already querying member records, triaging hardship applications, and drafting correspondence inside Australian superannuation funds, but most deployments cannot say who set the agent in motion or whether its access matched what was authorised. APRA named this gap directly in its 30 April 2026 Letter to Industry, and new Privacy Act disclosure rules land on 10 December 2026. This guide sets out the specific architecture failure behind the gap and the federated identity gateway pattern that closes it, using established identity principles rather than new technology.

SuperannuationIdentityAgentic AIAPRAPrivacy Act
Inside the guide
  1. 01You have deployed AI into your fund. Can you tell your board it is secure?
  2. 02Does your core platform know who let your AI agents in?
  3. 03What does the Privacy Act require when an agent, not a person, accesses member data?
  4. 04Why does the regulatory landscape make this harder, not easier?
  5. 05What does correctly architected agent identity look like?
  6. 06What it looks like when you have closed the gap

Full guide delivered to your inbox

What the guide covers

A federated identity gateway that closes the AI agent identity gap before your next APRA review.

Covers the architecture of the identity gap, from the MCP server call into the registry or core platform, through to the specific APRA and Privacy Act obligations that apply from 30 April and 10 December 2026, and the federated identity gateway pattern that restores a traceable link between every AI agent action and the person who authorised it. Closes with a six-action checklist to run before your next AI deployment.

What's inside

Includes the two request-flow diagrams showing where identity drops out and how a gateway restores it, the specific APRA and Privacy Act obligations superannuation funds face from April and December 2026, and a six-action pre-deployment checklist.

Get the full guide
Delivered to your inbox. Name and email only.

No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.

~20,000
Member accounts affected in the April 2025 credential-stuffing attacks across five Australian super funds, taking around $500,000 from members.
Source: National Cyber Security Coordinator, April 2025
109:1
The machine-to-human identity ratio inside the enterprise, up 32% in twelve months.
Source: Palo Alto Networks, 2026 Identity Security Landscape report
10 Dec 2026
The date new Privacy Act rules require organisations to disclose where a computer program materially assists a decision about someone's rights or interests.
Source: Privacy and Other Legislation Amendment Act 2024

Martin Barnier

Principal Consultant · Lumaris Consulting

Martin Barnier is Principal Consultant at Lumaris, an Australian-owned, vendor-neutral advisory firm specialising in AI, data, cyber security, cloud, and critical infrastructure. He is a security architect and technologist who works across all five domains, where most risk sits in the connections between them, not inside any one. Martin has over a decade of experience architecting security and technology across government, defence, national security, and health. Before Lumaris, he directed a large multidisciplinary practice at a Defence Prime delivering architecture, identity, cloud, and engineering capability for clients bound by APRA, Essential Eight, PSPF, and SOCI Act obligations. At Accenture, he was Lead Enterprise Security Architect for the Department of Health and Aged Care's Aged Care Transformation Program and Vaccines Response, and Lead Enterprise Architect for the National Security Portfolio and Department of Defence. Bachelor of Engineering (Robotics and Mechatronics), Swinburne University of Technology. TOGAF Practitioner, SABSA. Certified across AWS, Azure, and GCP. PRINCE2, Agile Scrum Master, SANS Cyber Incident Response Management.

View LinkedIn profile
Before you download

Questions about this guide

In its 30 April 2026 Letter to Industry on Artificial Intelligence, APRA found that identity and access management capabilities across the banks, insurers, and superannuation trustees it reviewed have not adjusted to non-human actors such as AI agents. It also flagged that security testing does not yet cover AI attack surfaces and that attack pathways now include the manipulation of autonomous agents.

From 10 December 2026, new provisions (APP 1.7 to 1.9) require organisations to state in their privacy policy the kinds of personal information used by, and the kinds of decisions materially shaped by, a computer program. The threshold covers anything substantially and directly related to a decision that could significantly affect someone's rights or interests, which includes an AI agent triaging hardship applications or scoring a group insurance claim.

It is a gateway placed between the MCP server and the core platform that checks, before any data returns, that the person behind a request was allowed to ask for it and that the agent making the request is the one they authorised. A human authenticates as normal, and when their action triggers an agent, that agent inherits a scoped, time-limited credential carrying the human's identity context, checked against policy at every request.

The Financial Accountability Regime, in force for superannuation trustees since 15 March 2025, requires named accountable persons to hold senior executive responsibility for defined areas of the business. If an accountable person cannot show that an AI agent's action traces back to an authorising human, the evidence chain their accountability rests on has a hole in it, which is why agent identity is foundational to FAR compliance rather than a separate project.

Let us talk

If the guide surfaces something you want to work through, that is a good place to start.

Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.