ASD Has Handed Australian and New Zealand Boards 16 Questions on Frontier AI

insicon_cyber1 pts0 comments

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

Search

Contact Insicon Cyber

Toggle Menu

Search

Toggle Menu

Contact Insicon Cyber

Linkedin

Cyber Advisory Services

AI Security & Governance

Board Cyber Advisory

AI Security Governance Advisory

Cyber Security Risk Assessment

Tabletop and Cyber Simulation Exercises

Managed Services

Managed Security Services

Security Operations Centre (SOC)

Managed Compliance Services

Managed Autonomous Red Teaming

Managed Detection and Response (MDR)

Managed Security Information and Event Management (SIEM)

Managed IT Services

Compliance & Certification

Information Security Compliance (ISO 27001)

AI Compliance (ISO 42001)

Quality Assurance Compliance (ISO 9001)

Essential Eight (E8)

ISO 14001 & ISO 45001 Compliance

Technology Acquisition & Application

Technology Acquisition & Application

Technology Partners

Industries

Aged Care

Online Retails and SaaS

Finance and Lending

Roles

Testing 1

Sub Nav 1

Sub Nav 2

Testing 2

Testing 3

Needs

Testing 1

Sub Nav 1

Sub Nav 2

Testing 2

Testing 3

5 min read

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

Insicon Cyber

Updated on August 6, 2026

Cyber Security

Governance

AI

Insicon Cyber

ISO 42001

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

10:16

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company Directors with it.

The earlier ASD material, published on 9 April 2026 and updated on 30 April, spoke to accountable authorities, chief security officers and technical teams. Useful, but not the room where cyber risk is accepted or declined. The new publication, Frontier AI cyber threat considerations for boards of directors, is written for directors and senior leaders, and it is co-authored with the AICD. That co-authorship is the signal. This is not a technical advisory a director can delegate. It is a governance document, and it lands sixteen threshold questions squarely on the board table.

Most directors across Australia and New Zealand cannot yet answer them with evidence. That is the point of the exercise.

What ASD is telling the board

The regulator's framing is precise and it is worth reading slowly. Frontier AI models can identify vulnerabilities and rapidly weaponise them, chain together multiple low-severity vulnerabilities into high-impact compromises, and perform malicious cyber activities with little to no human oversight. The last of those three is the one that should hold a director's attention. Agentic activity, at machine speed, with no human in the loop.

ASD is blunt about what this does to a board's existing assumptions. These developments may rapidly invalidate an organisation's current risk tolerance. The risk appetite the board signed off last year was calibrated for a slower, human-led threat. It may no longer hold. ASD warns that vulnerability discovery and exploitation timelines are collapsing from days to hours, while the skill and knowledge barrier for malicious actors drops at the same time. Attackers who previously lacked the capability now have it.

There is a second dimension the earlier advisory underplayed and this one puts front and centre. Cyber supply chain risk, and specifically foreign ownership, control or influence over the AI vendors an organisation depends on. ASD asks boards whether they are relying on vendors and service providers without sufficient governance, including an understanding of who ultimately owns and controls them. For organisations across both countries that have adopted AI tooling quickly over the past two years, this is an uncomfortable question, because most cannot answer it.

The sixteen questions, and why they are hard

ASD groups its threshold questions around exposure, supply chain, fundamentals, and resilience. A director does not need all sixteen memorised. They need to notice the ones management will struggle to answer honestly.

On exposure,

ASD asks what assumptions underpin the current risk assessment, and how frontier AI might invalidate them. It asks which parts of the business would be most exposed if a frontier AI model were used to identify and exploit weaknesses across the organisation. These are not questions a maturity score answers. They require the organisation to reason about itself as an attacker would.

On the supply chain

ASD asks whether the board has visibility of the security posture of third and fourth-party suppliers. Fourth-party. Not just the vendor, but the vendor's vendor. Few organisations in Australia or New Zealand can produce that map today.

On fundamentals

ASD asks whether the organisation adheres to a recognised cyber security framework, what legacy technology risk it...

cyber security frontier questions directors risk

Related Articles