APRA CPS 234

Information security applied to AI systems and agents.

CPS 234 has applied since 1 July 2019. AI systems hold sensitive data, and agents reach tools and systems through identities and keys, so they are squarely in scope.

CPS 234 asks you toFor AIIn Cogna8
Keep capability in line with threatsTrack AI-specific threats such as prompt injectionThreats catalogued per system
Classify information assetsKnow what data each system and vendor model touchesData sensitivity in each assessment
Implement and test controlsLeast privilege for agents, and tests that prove itTool and MCP permissions, enforced at the gate
Notify APRA of material incidents within 72 hoursAI incidents follow the same clockIncident register with notification dates

This page is general information, not legal advice.

Last reviewed October 2026Suggest a change