APRA and ASIC expect entities to act now and provide evidence that decision-making, escalation pathways, assurance, recovery and governance processes can operate at the pace of emerging frontier AI threats. Defensive AI may support threat intelligence, vulnerability detection and incident response, but the regulators stressed that it cannot replace sound cyber fundamentals or each entity’s individual accountability, even as industry-wide information sharing and coordinated preparedness become more important.