1300 002 001
Follow Us  —Lk. /Ig.

Insights · 18 Aug 2026 · 2 min read

What should we be asking about AI and cybersecurity?

New ASD and AICD guidance sets out the key questions and priorities boards need to govern frontier AI cyber threats. Symsafe breaks down what it means for SMB and enterprise IT security planning.

Managing AI threats with governance frameworks for company boards

What the ASD and AICD’s new frontier AI guidance means for your board

Boards are used to hearing that cyber risk is increasing. What this provides is a structured way to act on it.

In August 2026, the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) released joint guidance titled Frontier AI Cyber Threat Considerations for Boards of Directors. Rather than another warning about AI enabled threats, the report gives boards a governance framework: a set of questions to ask, and a staged set of priorities to oversee.

For SMB and enterprise leaders alike, the structure is worth understanding, because it is likely to shape how directors are expected to demonstrate oversight going forward.

Four threshold questions for the boardroom

The guidance opens with questions boards should be putting to management directly, covering exposure to AI enabled attacks, whether minor system weaknesses could combine into a major incident, control over cyber security fundamentals, and whether the business could keep operating through a serious incident. These are not technical questions. They are governance questions, designed to test whether risk assessments and continuity plans still hold up against attacks that move at machine speed.

A roadmap across four horizons

The report then sets out priorities across four time horizons, moving from immediate to long term:

  • Immediate: securing attack surfaces and reducing known software vulnerabilities.
  • Short term: replacing legacy systems, reinforcing identity and access management, and testing incident response plans.
  • Medium term: adopting AI for cyber defence in a controlled, human supervised way.
  • Long term: modernising systems using secure by design principles from the ground up.

Why the structure matters more than the content

The real value for boards is not in any single recommendation. It is in the discipline of the framework itself: a recurring set of questions, mapped against a phased plan, with regular reporting and assurance back to the board.

Treated this way, frontier AI risk becomes something boards can govern continuously, rather than react to after the fact.

Turning guidance into a plan

Reading the guidance is the easy part. Mapping it against your own systems, vendors, and legacy technology, and building a realistic remediation timeline, takes expertise most SMB and enterprise IT teams are stretched to provide alone.

Symsafe works alongside boards and management teams to translate frameworks like this into a practical, resourced plan, and to report on progress in language directors can act on.

If your board is starting this conversation, we are glad to help you work through where you currently stand.

Contact us

1300 002 001 | [email protected]

Frontier AI Cyber Threat Considerations for Boards of Directors