A BIS paper warns that AI is shortening the time banks have to repair software vulnerabilities.
The authors say routine patching schedules are increasingly insufficient.
Supervisors are urging faster fixes and better preparation to contain breaches and restore services.
Advanced AI is leaving banks less time to fix software flaws before attackers exploit them, according to a new paper published by the Bank for International Settlements.
The Financial Stability Institute paper, published on Wednesday, adds to recent warnings from AI developers and financial regulators that increasingly capable models are accelerating cyberattacks. The new report’s focus is on banks’ ability to respond, with the authors arguing that institutions must speed up both software repairs and the decisions needed to authorize them.
Myriad: Crude oil’s next move? Click to make your prediction.
“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote, warning that periodic security assessments and scheduled patching are increasingly insufficient. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes.”
The paper cites a U.K. Financial Conduct Authority review finding that vulnerability discovery is outpacing firms’ ability to respond, alongside Institute of International Finance guidance urging faster patching—even outside scheduled maintenance windows—and greater acceptance of planned downtime.
Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates repair timelines shrinking from weeks to days and, in some cases, hours, according to the paper.
While the timelines mentioned in the report are voluntary, regulators are pushing banks to act faster: Germany’s BaFin has called for quicker patching, while Hong Kong’s monetary authority has urged stronger breach response and recovery, according to the paper.
“For instance, the Hong Kong Monetary Authority has encouraged institutions to integrate AI-driven cyber scenarios into operational resilience programmes and boost incident response and recovery capabilities, recognising that ‘breach’ scenarios may become more probable as the cyber threat landscape continues to evolve,” the report said. “Similarly, the [European Central Bank’s] cyber resilience stress testing programme and implementation of the Digital Operational Resilience Act emphasise institutions’ ability not merely to withstand cyber attacks but also to continue delivering critical services throughout severe operational disruptions.”
BitcoinBTC · USD
$77,066−5.15%
Sep 3Sep 5Sep 7Sep 9Sep 10
$81.8k$80.1k$78.5k$76.9k
24h HighHigh$78,774
24h LowLow$76,748
VolVol$1.2B
Market projectionsOdds by Myriad
The warning follows an August call for stronger cyber defenses backed by OpenAI, Anthropic and more than 100 other organizations. The signatories recommended tighter access controls, threat sharing and closer oversight of AI agents.
The BIS paper examines the Hugging Face intrusion involving OpenAI models as preliminary evidence that capabilities demonstrated in tests can translate into attacks on real systems. OpenAI later described how its agents coordinated during the operation.
While the authors caution that normal safeguards had been relaxed and substantial computing resources were provided, they say the incident does not directly reflect the risks posed by publicly available AI tools.
“The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own. Nevertheless, they may pursue a narrowly defined task with unintended and harmful consequences,” they wrote. “The significance of this development for cyber resilience lies in combining a capable model with a surrounding software system that enables it to plan, use tools and act autonomously.”
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.