Introduction
Artificial intelligence (AI) has become one of the defining technologies of this generation.1 Hardly a day passes without another announcement of a breakthrough model or a disrupting new business application, a news report of a model escaping its sandbox environment and attacking live systems or alarming statements by qualified experts on the adverse implications that AI could have on the economic system or society at large.
In the financial sector, banks are at present deploying AI to detect fraud, assess creditworthiness, automate compliance, improve customer service and strengthen risk management. Supervisors themselves are increasingly using AI to process supervisory data, identify emerging risks and allocate scarce resources more efficiently.
Across the broader economy, AI is also reshaping firms, labour markets and industries. The economic benefits of AI will not be evenly distributed. Industries involved in developing AI, and those able to harness it to complement human capabilities, could thrive. Industries built around routine information-processing tasks that AI can increasingly perform at near zero marginal cost are likely to struggle.
This illustrates that AI is changing not only how banks operate, but also the environment in which they operate. A changing economic environment affects banks’ customers, which ultimately affects banks’ business.
This means that supervisory thinking around AI should balance a narrow technology governance perspective with a broader resilience perspective.
Let me go through each perspective in turn.
The narrow technology governance perspective
Most central bank and supervisory speeches on AI tend to follow a similar structure. They describe AI’s transformative potential. They acknowledge the risks. They stress the importance of governance, accountability, transparency and human oversight. And they conclude by calling for international cooperation.
Yet supervision cannot simply adopt a defensive approach and inadvertently become an obstacle to innovation. The objective has never been to eliminate risk. Rather, it is to ensure that innovation takes place with appropriate safeguards.
This is particularly relevant as supervisors reconsider existing frameworks that were developed long before modern AI existed.
Model risk management (MRM) is a good example. Many supervisory expectations around MRM were designed around relatively transparent statistical models. The limited explainability of large language models and other advanced AI models challenges some of these expectations, particularly those relating to governance, model validation and independent review. It is therefore imperative that MRM guidance be revisited and adjusted to reflect the complexities of AI models. For example, there may be a need to recognise trade-offs between model explainability and performance, provided that risks are properly assessed and effectively managed (Pérez-Cruz et al (2025)). Indeed, good supervision has always required balance. The same principle applies today.
The broader resilience perspective
Beyond the safe and responsible use of AI by banks, supervisors should also consider the eventual impact on banks’ operations, assets, liabilities and business models arising from the widespread use of AI outside the financial sector. This has resilience implications on two fronts: operational and strategic.
Operational resilience: when time becomes the scarce resource
Supervisory concern about AI-enabled cyber attacks on banks and disruptions to AI services is not new. AI can strengthen cyber criminals’ arsenal through scalable phishing, vulnerability discovery, social engineering and other techniques. Disruptions to AI services that support banks’ operations could also occur, either because of a cyber attack or a non-malicious incident at the AI provider. Both can create operational resilience issues for individual banks and, more broadly, for the financial system.
What has changed recently is the rise of frontier AI models. Increasing evidence suggests that these models have substantially narrowed the window between the discovery of cyber vulnerabilities and their exploitation by cyber criminals, while enabling cyber-attacks to be conducted with greater autonomy, sophistication and scale.
The same models can, of course, help strengthen banks’ cyber defences through more effective anomaly detection and security monitoring, faster incident analysis and automated response. However, faster discovery and exploitation of vulnerabilities by cyber criminals also mean that banks have significantly less time to implement defensive measures and respond to cyber incidents.
This is a cause for concern for financial supervisors, and many have issued policy statements or responses to address these issues.
The statements and responses by authorities – as examined in a recent Financial Stability Institute paper – reinforce established cyber risk management and operational resilience principles, while highlighting the need to adapt to the challenges posed by frontier AI models.
As successful breaches become more likely despite stronger preventive measures, supervisory attention is shifting from cyber defence towards reassessing whether existing operational resilience practices are sufficiently robust to safeguard business continuity.
Supervisory authorities are pushing for reductions in the time required to contain incidents and for stronger capabilities to maintain critical services and restore normal operations. This entails strengthening incident response playbooks, conducting increasingly realistic cyber exercises, improving crisis management arrangements and ensuring that critical third-party providers remain capable of supporting recovery under stressed conditions (Crisanto et al (2026)).
Strategic resilience: the slow-burning challenge
The second resilience implication evolves more slowly, which perhaps explains why it receives less attention.
The wider use of AI can drive changes across the economy. It can affect individuals whose employment prospects may be disrupted by AI. It can also affect entire industries, particularly those that cannot easily adapt to the new technological environment.
It is therefore important for supervisors to ensure that banks’ risk management policies fully factor in the potential disruptive impact of AI on their investments. In a way, this is already captured – but in very broad terms – in the Basel Core Principles, which state that banks’ credit risk management process should consider forward-looking information (BCBS (2024)).
Beyond the impact on their credit portfolios, structural changes in the economy can test banks’ strategic resilience. Indeed, a bank that is well capitalised and financially sound today may still become vulnerable if it is unable to evolve or adapt to economic changes brought about by AI.
Supervisors therefore need to make forward-looking assessments of the resilience and adaptability of banks’ business models in the light of the increasing use of AI across the economy. Where these assessments identify potential vulnerabilities, they could provide grounds for supervisory intervention.
Therefore, supervisory perspectives need to broaden. It is no longer sufficient for prudential supervision to focus largely on risks arising from decisions made within banks. Increasingly, supervisors must also understand risks to financial safety, soundness and stability arising from technological change across the wider economy.
This does not mean supervisors should become industrial policymakers or technology forecasters. It simply recognises that banks cannot be separated from the economies they finance. If AI transforms the economy, prudential supervision must understand those transformations.
Conclusion
To summarise: supervision in the age of AI is not simply about supervising banks’ use of AI. It is also about supervising the resilience of banks and the financial system in an AI-shaped economy: operational resilience, because technology compresses the time available to respond to disruptions; and strategic resilience, because technology reshapes industries, borrowers and business models over time.
Of course, core prudential concerns remain relevant. Likewise, traditional prudential tools – such as the emphasis on capital, liquidity and other hard financial metrics – remain indispensable.
In the face of AI developments, however, they may no longer be sufficient on their own. Some emerging risks cannot be fully captured through capital ratios or static assessments of financial risks. Instead, supervisors may increasingly need to rely on a broader set of instruments for supervisory diagnosis and intervention.
Business model analysis, strategic reviews, scenario analysis, horizon scanning and cross-sectoral intelligence – these tools help supervisors understand not only whether institutions are resilient today, but also whether they are preparing for tomorrow by addressing risks that are building on the horizon. Moreover, to address banks’ strategic vulnerabilities, qualitative supervisory measures are likely to be more effective than simple capital add-ons (Balan et al (2025)).
Importantly, this evolution places greater emphasis on supervisory judgment. AI creates strategic challenges which may significantly diverge across firms. Therefore, supervisory assessment and action can hardly be codified ex ante. Yet the exercise of judgment should be properly framed in a robust supervisory framework that ensures sufficient transparency, consistency across firms and stability over time.
References
Balan, M, F Restoy, R Zamil (2025): “Act early or pay later: the role of qualitative measures in effective supervisory frameworks”, FSI Insights on Policy Implementation, no 66.
Basel Committee on Banking Supervision (BCBS) (2024): Core principles for effective banking supervision.
Crisanto, J C, A Currat and J Yong (2026): “When machines attack: policy responses to financial institution’s frontier AI cyber threats”, FSI Occasional Paper, no 28.
Pérez-Cruz, F, J Prenio, F Restoy and J Yong (2025): “Managing explanations: how regulators can address AI explainability”, FSI Occasional Paper, no 24.
1 Footnote
| 1 | I’m grateful to Jermy Prenio for his support in the preparation of these remarks. The views expressed here are my own and not necessarily those of the BIS or its member institutions. |