Shadow AI use without enforceable technical controls
APRA's 30 April 2026 letter found entities relying primarily on policy direction or after-the-fact detective measures rather than preventative technical restrictions. Identity and access management capabilities have not yet adapted to non-human actors such as AI agents.
- Shadow AI tools ingesting client data, pre-earnings information, and board materials
- Model drift, bias, and lifecycle oversight gaps undiscovered in most entities
- Concentration risk in single AI providers without tested exit and substitution strategies