Skip to main content

When machines attack: frontier AI cyber threats and policy responses in the financial sector

Type
Publication
Series
FSI Occasional Papers 28
Date Published
09 September 2026
Sources
FSI
Topics
Insurance Banking Operational resilience
JEL Classification

Frontier artificial intelligence (AI) models are a game changer in the cyber threat landscape. Unlike earlier generations of AI models, they can autonomously identify critical vulnerabilities, develop effective exploits and conduct increasingly complex multi-step cyber operations, thus reducing the expertise, time and resources needed to carry out sophisticated attacks. At the same time, these capabilities offer significant defensive opportunities, including faster vulnerability discovery, threat detection and incident response. 

The risks for financial institutions arise from compressed cyber remediation windows, higher likelihood of breach and amplified third‑party dependencies. By collapsing the window from discovery to exploitation and automating exploit chaining, frontier models materially increase the likelihood of breach, with unpatched software becoming the leading initial access vector in many incidents. Reliance on common cloud, software and frontier AI providers introduces concentration and sovereign access risks, whereby a single provider’s disruption or policy decision can cascade across firms and jurisdictions. 

Financial authorities are converging on a pragmatic response. Rather than introducing new AI-specific cyber regimes, they are reinforcing existing cyber risk management and operational resilience frameworks while adapting supervisory expectations to the new cyber threat environment. Policy responses increasingly emphasise governance capable of supporting timely decision-making, accelerated patching and enhanced response and recovery capabilities. Frontier AI therefore does not fundamentally change the foundations of cyber resilience, but it significantly increases the speed and intensity with which established practices need to be executed. 


The views expressed in this publication are those of the authors and do not necessarily reflect the views of the BIS, its member central banks or the Basel-based standard-setting bodies.