A Financial Stability Institute occasional paper published by the Bank for International Settlements assesses how frontier artificial intelligence is reshaping cyber risk in finance. These models can autonomously discover vulnerabilities, develop exploits and conduct complex attacks, reducing the time, expertise and resources required. The paper finds that financial authorities are generally responding by intensifying existing cyber risk management and operational resilience frameworks rather than creating separate AI-specific cyber regimes. Supervisory responses increasingly emphasize faster board and management decision-making, accelerated patching, realistic incident testing and stronger response and recovery capabilities. Institutions may also need controls tailored to autonomous AI, including model inventories and activity logs, restricted access to tools and data, human approval for high-impact actions and mechanisms to halt agents. The paper highlights heightened concentration and sovereign access risks from reliance on common cloud, software and frontier AI providers, supporting closer mapping and testing of critical dependencies, credible continuity and exit arrangements, and faster information-sharing across firms, authorities and technology providers.
2026-09-09Bank for International Settlements
Bank for International Settlements assesses frontier AI cyber threats and finds authorities reinforcing existing resilience frameworks
A Bank for International Settlements paper finds that frontier AI is accelerating cyber attacks by automating vulnerability discovery, exploitation and complex operations. Financial authorities are mainly reinforcing existing operational resilience frameworks, with greater emphasis on faster patching, stronger governance, recovery capabilities and oversight of critical third-party dependencies.