For years, professional firms have been told to take “reasonable steps.” In the world of AI and cyber security, what was considered "reasonable steps" yesterday is not considered reasonable anymore.
In May 2026, ASIC and the Australian Cyber Security Centre (ACSC) warned that advanced AI models are changing the cyber threat landscape. This is not another technology trend. It is a step change.
Cyber criminals can now identify vulnerabilities and automate attacks at a scale never seen before.
What used to take days or weeks can now be done in minutes.
And this is only the beginning.
ASIC has strongly signalled to AFSLs that the threat environment has fundamentally changed. More importantly, this is not a one-off event. It is "the start of a wave that will continue" as AI becomes more capable and more accessible.
The question for directors and business owners is simple:
Have your cyber controls evolved at the same speed as the threats?
The five AI risks advice firms need to understand
1. AI-powered impersonation and phishing
Cyber criminals can now create highly personalised phishing emails, clone voices and generate deepfake videos using information gathered from LinkedIn, websites and social media.
The risk: Your team may unknowingly provide login credentials, transfer money or disclose sensitive client information to a criminal pretending to be someone they trust.
2. Data leakage through AI
Staff are increasingly uploading information into AI tools to save time and improve productivity.
The risk: Client information, personal data and confidential business information may leave the organisation without anyone realising it.
3. Agentic AI and prompt injection
The next generation of AI can access systems, read emails, search documents and take actions on behalf of users. Attackers are already experimenting with prompt injection attacks that attempt to manipulate AI agents into ignoring their original instructions.
The risk: Your trusted AI assistant could effectively become a spy within your business, exposing sensitive information or taking actions that benefit an attacker.
4. AI-accelerated cyber attacks
AI allows attackers to automate reconnaissance, identify vulnerabilities and launch attacks faster than ever before.
The risk: Organisations have less time to detect, respond and recover before damage occurs.
5. Governance failure
Many firms still treat cyber security as an IT issue. Regulators do not.
The risk: Following an incident, regulators will assess not only the breach itself, but the decisions, governance, controls and behaviours that existed beforehand.
What is really at risk?
Most firms think the biggest risk is a cyber incident.
It isn’t.
The biggest risk is losing the trust that took years to build.
When client information is exposed, the first conversation is not with ASIC. The first conversation is with your clients.
What will you say to them when you have to explain that their information was compromised because your controls did not keep pace with the changing threat environment?
Only after that comes the regulator.
Client trust, reputation and relationships are often far harder to recover than systems and data.
What should advice firms do?
Review the recent guidance from ASIC and the ACSC. Assess whether your current cyber program reflects the new threat environment and regulatory expectations.
Review your cyber risks. Review your controls. Review how AI is being used within your business. Train your people. Test your response plans. Ask for help, don't assume your IT firm has it covered. Know what you have and what else you need.
Most importantly, recognise that this is not the peak of the AI wave.
It is the beginning.
The firms that struggle over the next few years will not necessarily be the firms with the worst technology.
They will be the firms that assume yesterday’s controls are still enough to manage tomorrow’s threats.
Fraser is Founder of The Cyber Collective