Learning Objectives:
-
Understand how artificial intelligence is fundamentally transforming the cyber threat landscape.
-
Identify the key ways AI is being used by attackers to enhance and automate attacks.
-
Analyse the compression of timelines for vulnerability discovery and exploitation.
-
Recognise the strategic implications of AI-enabled threats for central bank cybersecurity governance.
1.1 The AI-Driven Threat Landscape
Artificial intelligence is fundamentally reshaping the cyber threat landscape, enabling attackers to identify vulnerabilities, automate attacks, and scale cyber intrusions more rapidly . Frontier AI models are increasing the severity, scale, and sophistication of cyber threats, requiring financial institutions and regulators to strengthen their collective response . The MAS managing director has warned that frontier AI models can find and exploit system vulnerabilities, significantly compressing the timelines for patching, testing, and remediation . These developments have been described as a “long-term structural shift in the threat landscape,” requiring banks to revisit strategic ICT decisions, resource allocation, and risk tolerance frameworks .
The AI threat landscape is characterised by three key dynamics:
Accelerated Vulnerability Discovery: Frontline AI models reveal more vulnerability findings and shorten discovery-to-exploit timelines, compressing the window for defensive action .
Reduced Attack Costs: AI tools reduce the cost and skill barrier for sophisticated attacks, enabling a broader range of threat actors to conduct operations.
Increased Attack Scale: AI enables attacks to be automated and scaled, increasing the volume and velocity of attacks.
1.2 AI-Assisted Cloud Intrusions
AI-assisted cloud intrusions are a growing threat category . Attackers are using AI to identify and exploit misconfigurations, vulnerabilities, and weak access controls in cloud environments. This creates new challenges for financial institutions that are increasingly dependent on cloud services, core banking vendors, and outsourced AI systems .
The main attack pattern involves malicious AI-themed extensions, infostealers abusing AI ecosystems, autonomous vulnerability discovery, and AI agent exposure in enterprise environments . These attacks can spread rapidly, as demonstrated by the South Korea Qilin ransomware campaign, which compromised a managed service provider and spread to 32 financial institutions, resulting in the theft of more than 2 terabytes of data .
1.3 AI-Powered Phishing at Scale
AI-enabled phishing is a significant threat to financial institutions. Generative AI tools have made it cheaper and faster to produce convincing scam content, from fake audio clips impersonating executives to fabricated identity documents . The MAS has noted that AI-enabled scams can be more personalised and persuasive “at scale” . The combination of AI-powered phishing and automated attacks increases the risk of successful credential theft and account takeover.
The ECB’s July 2026 mandate requires eurozone banks to have plans in place by 31 October to address AI-enabled cyber threats capable of disrupting financial services . The ECB noted that AI is discovering and exploiting vulnerabilities in unprecedented ways and is also greatly improving the phishing attack success rate. Combining these two capabilities greatly increases the risk of successful AI attacks and compresses the time between a stolen credential and a live breach .
1.4 Defensive Responses to AI-Enabled Threats
Financial institutions must accelerate their defensive responses to AI-enabled threats. The ECB expects banks to focus on three priority areas in the short term: accelerating vulnerability and patch management at scale; strengthening monitoring, detection, and AI-enabled defensive capabilities; and verifying that third-party risk management is fit for purpose given the critical role of ICT service providers in supply chains . Over the longer term, structural measures should include reinforcing defence-in-depth and modernising infrastructure, in particular by replacing or updating legacy technologies, and improving operational resilience through crisis management, recovery mechanisms, and information-sharing arrangements .
The MAS has introduced requirements for key financial institutions to conduct AI-assisted “red teaming” on critical internet-facing systems, using advanced AI models to identify potential attack paths . The central bank will also issue supervisory expectations for key financial institutions to develop and submit comprehensive assessments and action plans to strengthen defence against AI-enabled cyber threats .