The Bank for International Settlements published a bulletin assessing how frontier artificial intelligence models are changing cyber risk for the financial system. It concludes that these tools can both strengthen cyber defence and materially increase the speed, scale and complexity of attacks, with the balance potentially tilting toward attackers because defence remains structurally more costly. For banks, payment systems and other financial market infrastructures, the concern is that stronger offensive capabilities could turn software vulnerabilities and supplier dependencies into wider financial stability risks. The bulletin says the medium-term effect on systemic cyber risk will depend on who can access the most advanced models, the compute power available to run them and the incentives facing attackers and defenders. It points to evidence that frontier models such as Mythos and GPT-5.5 can identify vulnerabilities, develop exploits and in some cases complete full network takeovers in simulated environments, while attack costs are falling from about USD 5,000 to USD 10,000 for a full attack chain on Mythos to as little as USD 50 to USD 100 on cheaper models. It also highlights signs of a faster vulnerability cycle, including a jump in Firefox security bug fixes after Mythos and an increase in critical common vulnerabilities and exposures reported after 1 April 2026, while noting these data should be interpreted cautiously. On policy, the bulletin argues for rapid use of frontier AI in defensive tasks such as reviewing code bases and fixing vulnerabilities, alongside stronger domestic and cross-border coordination. It points to cooperation among financial firms, central banks, supervisors, national security agencies and critical suppliers, and says existing operational resilience and cyber resilience frameworks should be adapted to cover AI-enabled attack paths, third-party risk and faster patching and information-sharing arrangements.