The International Monetary Fund has published an assessment of how artificial intelligence is reshaping cyber risk in the financial sector. It finds that the main financial stability threat is not new forms of attack, but AI’s capacity to accelerate vulnerability discovery and exploitation across shared software, cloud services and other common infrastructure. This could produce simultaneous disruptions across institutions and jurisdictions, while machine-speed attacks compress the time available for detection, containment and recovery. The note identifies structural vulnerabilities arising from AI’s dual-use and increasingly autonomous capabilities, concentration among technology providers, gaps in third-party and operational resilience oversight, uneven defensive capacity in emerging market and developing economies, and frontier models outpacing existing evaluation tools. It recommends seven actions for national authorities: updating systemic cyber surveillance, strengthening oversight of cloud and AI providers, improving cross-sector coordination, expanding cyber simulations to cover macro-financial effects, standardizing incident reporting, advancing international AI governance and building supervisory capacity to monitor frontier AI. Institutions should also deploy controls that limit the spread of breaches, strengthen response and recovery, and pair machine-speed defenses with human oversight and public-private collaboration.
2026-06-30International Monetary Fund
International Monetary Fund identifies systemic AI cyber risks and sets out seven resilience actions
The International Monetary Fund warns that AI could turn vulnerabilities in shared financial technologies and critical service providers into rapid, correlated disruptions. It recommends seven resilience actions covering surveillance, third-party oversight, cross-sector exercises, incident reporting, international coordination and frontier AI monitoring. Financial institutions should prioritize containment, recovery and machine-speed defenses.