Frontier AI Compresses the Cyber Response Window for Financial Institutions
FSI Occasional Paper 28 argues that frontier AI can identify vulnerabilities, develop exploits and execute increasingly complex cyber operations with less time and expertise. For financial institutions, the central risk is a compressed remediation window combined with greater dependence on shared cloud, software and frontier-AI providers.
When machines attack: frontier AI cyber threats and policy responses in the financial sector
STRATEGIC OUTLOOK · SECBRIEFS ANALYSISExecutive Takeaway
The FSI paper’s core message is about tempo. Frontier AI does not necessarily require financial institutions to invent a new cyber-control universe, but it shortens the time available to discover, prioritize, patch and contain weaknesses while making sophisticated attack steps accessible to a broader set of actors.
For banks and supervisors, the paper links that faster threat environment to operational resilience and concentration risk. Financial authorities are generally reinforcing existing cyber and resilience frameworks rather than building a separate AI-cyber regime, with greater emphasis on timely governance decisions, accelerated patching, response and recovery, and the risks created by common cloud, software and AI providers.
Key Findings
- 01
Frontier AI models can increasingly identify software vulnerabilities, develop effective exploits and conduct complex multi-step cyber operations with reduced human expertise, time and resources.
- 02
The paper says financial institutions face compressed remediation windows, a higher likelihood of breach and amplified third-party dependencies.
- 03
Unpatched software is identified as a leading initial-access vector in many incidents, making patch speed more important as discovery-to-exploitation time shrinks.
- 04
Reliance on common cloud, software and frontier-AI providers creates concentration and sovereign-access risks that can cascade across firms and jurisdictions.
- 05
Financial authorities are generally strengthening existing cyber-risk and operational-resilience frameworks rather than creating a new AI-specific cyber regime.
- 06
The paper cites 2025 research showing AI-enabled attacks increased 89% and average eCrime breakout time fell to 29 minutes, illustrating the shrinking defender decision window.
- 07
The paper also argues that established threat frameworks such as MITRE ATT&CK may need to evolve to represent more autonomous, agentic attack behavior.
What the Data Says
Average eCrime breakout time cited
The paper cites 2025 CrowdStrike research reporting an average breakout time of 29 minutes, 65% faster than the prior year.
AI-enabled attack growth cited
The FSI paper cites research reporting an 89% increase in AI-enabled attacks during 2025.
Observed malicious AI actions
The paper summarizes Anthropic analysis mapping 13,873 actions from 832 banned accounts to 482 MITRE ATT&CK techniques across 14 tactics.
What It Doesn’t Say / Limitations
This is a policy and supervisory analysis, not an incident census or a forecast of breach probability for any individual bank. Several quantitative examples in the paper are drawn from third-party studies and vendor research rather than a BIS-produced primary dataset.
Frontier-model capabilities are moving quickly, so the exact performance and misuse examples will date faster than the paper’s broader resilience conclusions. The authors also state that their views do not necessarily represent the BIS, its member central banks or Basel-based standard-setting bodies.
Why It Matters
The paper turns AI cyber risk into an operational-resilience problem: the same controls still matter, but the time available to execute them is shrinking. Vulnerability management, identity, detection, containment and recovery processes that were designed around slower attacker progression can become inadequate even when the control framework itself is sound.
The concentration dimension also matters for banks. As more institutions depend on a small set of cloud, software and frontier-AI providers, an outage, compromise or access-policy change can create correlated operational risk across multiple firms and jurisdictions.
Who Should Care
- Bank CISOs and security leaders
- Vulnerability-management teams
- Incident-response and SOC teams
- Operational-resilience leaders
- Third-party and cloud-risk teams
- AI governance teams
- Financial-sector supervisors
- Boards and technology-risk committees
SecBriefs Assessment
The strongest takeaway is that frontier AI changes the required operating speed more than it changes the control objectives. Banks should treat patch latency, detection-to-containment time and provider concentration as explicit risk metrics rather than assuming existing annual or quarterly control cycles are sufficient.
The defensive opportunity is real as well: the same model capabilities can accelerate vulnerability discovery, threat detection and incident response. The winning posture is therefore not to avoid AI, but to combine faster defensive automation with strong decision rights, auditability, human escalation and resilience planning for shared providers.
What To Do Now
- Recalibrate critical-vulnerability triage and patching targets around external exposure, exploitability and business criticality rather than fixed calendar cycles.
- Test whether detection, decision and containment processes can operate inside sub-hour lateral-movement scenarios.
- Include frontier-AI, cloud and shared-software concentration in third-party risk assessments and operational-resilience scenarios.
- Rehearse provider outage, compromise and sudden service or access-policy changes that could affect multiple business services at once.
- Update threat models and ATT&CK mappings to account for more autonomous reconnaissance, exploitation and post-compromise activity.
- Use AI defensively for discovery and response where it reduces time-to-action, but preserve human escalation, logging and accountability for high-impact decisions.
When machines attack: frontier AI cyber threats and policy responses in the financial sector
- Publisher
- Bank for International Settlements / Financial Stability Institute
- Published
- URL
- https://www.bis.org/publications/fsi-paper-28-when-machines-attack-frontier-ai-cyber-threats-and-policy-responses-financial-sector
Follow the evidence chain
Move from the current signal to its topic context, supporting briefs, decision analysis and deeper research.
Briefs
- BriefDutch NCSC warns of two critical Check Point VPN flaws
The Dutch NCSC is urging organizations using Check Point VPN products to address two critical flaws and reduce exposure while exploitation remains a risk.
- BriefConnectWise patches ScreenConnect flaw used in worm-like attacks
ConnectWise patched a ScreenConnect vulnerability reportedly exploited to transfer and execute files without authorization through active remote sessions.
- BriefCritical GitLab file-read flaw was reportedly exploited soon after disclosure
A critical, unauthenticated GitLab path-traversal flaw was reportedly exploited within a day, making patching and exposure checks urgent.
- BriefCISA Flags Two MikroTik RouterOS Bugs as Actively Exploited
CISA says two MikroTik RouterOS vulnerabilities are being exploited. Identify exposed devices, patch or mitigate them, and check for compromise.
- BriefA second September Patch Tuesday view reinforces the need for focused remediation
A separate technical tally of September’s Microsoft fixes reports 973 vulnerabilities and 113 critical issues, reinforcing the need to prioritize by exposure and exploitability.