Cybersecurity will dominate the boardroom when Commonwealth Bank signs off its full-year results in two weeks, and it will do the same at its major rivals. Directors at Australia’s largest financial institutions now treat the risk of AI-assisted criminals breaching core systems as a primary threat, not a secondary operational issue.
What once sat alongside other technology risks is fast becoming the central challenge shaping board agendas for the year ahead.
Directors are reacting to rapid advances in artificial intelligence, including Anthropic’s Mythos system, which has already uncovered decades-old software vulnerabilities at speed. Rival AI models with comparable power are close behind, forcing banks to revisit long-standing incident response frameworks they had assumed were robust.
For years, those frameworks required senior executives to personally authorise the shutdown of any compromised system, even in urgent scenarios. That authorisation step often introduced delays of up to a day, particularly when executives were travelling or required extended briefings before signing off on drastic action.
Boards now face the reality that yesterday’s governance logic can leave today’s systems dangerously exposed when attacks can propagate in minutes. Legacy playbooks were built around careful escalation, detailed deliberation and clear personal accountability for decisions to pull systems offline.
AI-driven threats change that calculation, because vulnerabilities can be identified and exploited faster than traditional approval chains can react. Financial institutions are being pushed to balance tighter response times with the oversight regulators still expect, reconsidering who holds the power to hit the kill switch when something looks wrong.

