APRA CPS 234 for AI systems and agents

CPS 234 Information Security has applied since 1 July 2019. AI systems hold sensitive data, and agents reach tools and systems through identities and keys, so they fall squarely within its scope.

CPS 234 asks you toWhat that means for AIIn Cogna8
Keep information security capability in line with threatsTrack threats specific to AI, such as prompt injection and data leakageThreats catalogued against OWASP and MITRE ATLAS per system
Classify information assets, including third-party onesKnow what data each AI system and vendor model touchesData sensitivity recorded in each risk assessment
Implement and test controlsLeast privilege for agents, and tests that prove itTool and MCP permissions, enforced at the gate and tested
Notify APRA of material incidents within 72 hoursAI incidents need the same clock as any otherIncident register with notification dates

24 controls in the registry. This page is general information, not legal advice.

Let's connect

Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.