APRA CPS 234 for AI systems and agents
CPS 234 Information Security has applied since 1 July 2019. AI systems hold sensitive data, and agents reach tools and systems through identities and keys, so they fall squarely within its scope.
| CPS 234 asks you to | What that means for AI | In Cogna8 |
|---|---|---|
| Keep information security capability in line with threats | Track threats specific to AI, such as prompt injection and data leakage | Threats catalogued against OWASP and MITRE ATLAS per system |
| Classify information assets, including third-party ones | Know what data each AI system and vendor model touches | Data sensitivity recorded in each risk assessment |
| Implement and test controls | Least privilege for agents, and tests that prove it | Tool and MCP permissions, enforced at the gate and tested |
| Notify APRA of material incidents within 72 hours | AI incidents need the same clock as any other | Incident register with notification dates |
24 controls in the registry. This page is general information, not legal advice.
Let's connect
Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.