APRA CPS 234
Information security applied to AI systems and agents.
CPS 234 has applied since 1 July 2019. AI systems hold sensitive data, and agents reach tools and systems through identities and keys, so they are squarely in scope.
| CPS 234 asks you to | For AI | In Cogna8 |
|---|---|---|
| Keep capability in line with threats | Track AI-specific threats such as prompt injection | Threats catalogued per system |
| Classify information assets | Know what data each system and vendor model touches | Data sensitivity in each assessment |
| Implement and test controls | Least privilege for agents, and tests that prove it | Tool and MCP permissions, enforced at the gate |
| Notify APRA of material incidents within 72 hours | AI incidents follow the same clock | Incident register with notification dates |
This page is general information, not legal advice.
Last reviewed October 2026Suggest a change