Frontier AI Is Compressing Incident Response Time. Boards Need Decisions Made Before the Crisis

Key takeaways

  • Australian regulators are warning that organisations need to move beyond awareness of frontier AI risk and demonstrate that their governance and response arrangements can work under pressure.
  • The central issue is speed. AI-assisted attacks can reduce the time available to investigate, escalate, contain and recover.
  • New Zealand professional services firms should pre-decide critical authorities, escalation thresholds, recovery priorities and supplier dependencies before an incident occurs.

Frontier AI is changing cyber risk in a way that has direct implications for governance. On 27 August 2026, APRA and ASIC published findings from industry roundtables involving more than 600 participants from over 380 organisations, with a clear message that awareness of AI-related cyber risk is no longer enough.

The more important issue is whether governance, resilience and incident response arrangements can still work when the time available to make decisions is compressed. For New Zealand professional services firms, that is a practical lesson even where Australian regulatory requirements do not apply.

The problem is increasingly about speed

AI can help malicious actors accelerate reconnaissance, vulnerability discovery, phishing, malware development and other parts of the attack lifecycle. The effect is not necessarily to create entirely new forms of attack, but to increase the speed and scale at which existing techniques can be used.

That matters because many incident response processes assume there will be time to investigate, brief management, seek legal advice, contact suppliers and then escalate significant decisions. In a faster-moving incident, several of those steps may need to happen at the same time.

The governance question therefore becomes less about whether an organisation has an incident response plan and more about whether the right people can make important decisions quickly enough.

Some decisions should be made before the incident

One of the strongest themes from the APRA and ASIC roundtables was the need to clarify important governance decisions in advance. Participants identified areas such as risk appetite, escalation authority, supplier reliance, recovery priorities, communications and resilience investment as matters that should not be left until a crisis is already underway.

An incident response plan may identify who should be contacted, but that does not always establish who has authority to make difficult decisions. Who can shut down a critical system if continued operation may expose more client information? Who can authorise emergency expenditure or disconnect a compromised cloud service? At what point must the board become involved?

If those questions are being debated for the first time during an incident, the organisation is already losing time. Pre-agreed decision rights can make the response faster and reduce confusion when information is incomplete.

Cyber fundamentals become more important, not less

The regulators did not suggest that organisations should solve frontier AI risk by simply deploying more AI. The roundtables instead reinforced familiar controls such as asset visibility, patching, strong identity and access management, monitoring, reliable backups, tested recovery arrangements and management of legacy systems.

AI changes the environment in which those controls operate rather than making them obsolete. A vulnerability that once presented a manageable remediation window may become more urgent if attackers can identify and exploit it faster, while weak privileged-access controls become more consequential if an attacker can move through the environment more quickly after initial compromise.

For boards and executives, the focus should therefore be on whether critical controls work reliably and quickly in practice. Documented policies matter, but operational performance matters more.

Defensive AI needs governance too

Organisations are also exploring AI for threat intelligence, vulnerability detection, code review and incident response. The roundtables identified growing interest in these use cases, while also noting that governed, measurable and scalable defensive AI capability remains relatively immature.

This creates a second governance issue. An AI security tool may accelerate investigation or identify patterns that human analysts could miss, but if its output influences important security decisions, the organisation needs to understand its reliability, limitations and appropriate level of human oversight.

The same governance principles that apply to other consequential AI systems therefore apply here as well. Defensive AI should have clear accountability, secure configuration, testing, monitoring and defined limits on what it may do autonomously.

Supplier concentration is becoming a resilience issue

The roundtables also highlighted reliance on common cloud providers, SaaS platforms, managed service providers, AI model providers, open-source components, telecommunications and other shared infrastructure. That concentration can create resilience problems because a disruption affecting one widely used provider may affect many organisations at the same time.

This is particularly relevant for professional services firms that depend on a relatively small number of platforms for email, identity, document management, cloud infrastructure and increasingly AI. Supplier assurance should therefore extend beyond security questionnaires and procurement checks.

Firms should understand which providers support critical operations, where multiple important services depend on the same underlying infrastructure and what realistic alternatives exist if a provider becomes unavailable. The key question is not only whether a supplier is secure, but whether the organisation can continue operating if that supplier fails.

New Zealand is facing the same direction of travel

The Australian findings align with warnings already issued by New Zealand’s National Cyber Security Centre and its Five Eyes partners about frontier AI and cyber preparedness. Across those developments, the direction is consistent: AI can reduce barriers for attackers and accelerate activities that previously required more time or specialist capability.

For New Zealand firms, this does not mean assuming every future incident will be AI-driven. It means testing whether existing governance and response arrangements are still appropriate if the available decision-making window becomes materially shorter.

That is fundamentally a resilience issue. The organisation needs to know whether decision-makers, suppliers and response teams can operate effectively when the pace of the incident increases.

What this means for your organisation

Pre-decide critical authorities. Identify who can authorise system shutdowns, isolation, external assistance, emergency expenditure and other significant response actions.

Review escalation thresholds. Ensure serious incidents can reach senior decision-makers quickly without unnecessary approval layers.

Set recovery priorities. Agree which systems and services must be restored first and confirm that technology teams and key suppliers understand those priorities.

Map critical suppliers. Identify providers supporting essential operations and look for common dependencies across cloud, SaaS, managed services and AI.

Test decisions under pressure. Use tabletop exercises and simulations that deliberately compress timelines and require executives to make decisions with incomplete information.

Govern defensive AI. Where AI is used in cyber security or incident response, define its authority, test its reliability and retain meaningful human oversight.

The governance issue is preparedness

Frontier AI does not require organisations to discard their existing cyber governance arrangements. It does require them to test whether those arrangements are fast enough for the environment that is emerging.

For boards and executives, one of the most useful questions is simple: which decisions would we struggle to make quickly if a major incident started today? Those are the decisions worth working through before the pressure arrives.

Sources

About the author

Campbell McKenzie is a Director at Incident Response Solutions, a New Zealand firm experienced in cyber incident response, digital forensics, investigations and technology risk. Through KiwiGen.AI, Campbell helps professional services firms adopt generative AI safely, with practical governance and controls.