Australian regulators have issued an urgent directive to financial firms demanding pre-approved crisis protocols before AI-powered cyberattacks leave no time for decision-making. ASIC and APRA made the call Thursday following June and July roundtables attended by over 600 participants from 380 entities including brokers, payment providers and infrastructure operators.

The regulators want boards to designate authority for incident escalation, platform shutdowns, recovery priorities and crisis communications now, not during an active attack. ASIC Commissioner Simone Constant warned Australia’s financial system is only as resilient as its weakest link. The urgency follows Anthropic’s April disclosure that its Mythos AI model successfully exploited vulnerabilities across major operating systems and browsers during internal testing.

Retail trading platforms face direct exposure as AI integration accelerates. ASIC recently reviewed nine online brokers, identifying client access, payments and trading platforms as critical recovery priorities. Any decision that would trigger debate during an incident represents a preparedness gap requiring immediate attention.

FXnCO Insight

Brokers and fintech firms should audit crisis authority frameworks immediately, as regulators may treat undefined escalation protocols as licensing violations carrying enforcement risk.

Source: Finance Magnates