Learning Objectives:

  • Understand the regulatory and supervisory expectations for AI governance in financial institutions.

  • Identify the key areas of AI risk requiring board and senior management attention.

  • Explain the role of red teaming and other testing approaches.

  • Recognise the relationship between AI governance and broader risk management frameworks.

7.1 Supervisory Expectations for AI Governance

Regulators are increasingly issuing supervisory expectations for AI governance in financial institutions. The MAS has introduced a requirement for key financial institutions to conduct AI-assisted “red teaming” on critical internet-facing systems . The central bank will also issue supervisory expectations for key financial institutions to develop and submit comprehensive assessments and action plans to strengthen defence against AI-enabled cyber threats .

These expectations will address financial institutions’ ability to:

  • Detect and patch vulnerabilities at scale

  • Test system changes before implementation

  • Back up, restore, and recover critical systems and services when disruptions occur 

The European Supervisory Authorities (ESAs) have stated that AI defensive tooling becomes part of the regulated estate itself and must comply with subsequent regulatory requirements such as the EU AI Act and model-risk obligations . This reflects the growing integration of AI governance into the broader regulatory framework.

7.2 Key Areas of AI Risk

The MAS has identified AI-driven cyber threats as a serious near-term risk to the financial sector . The ECB’s July 2026 mandate requires eurozone banks to have plans in place by 31 October to address AI-enabled cyber threats capable of disrupting financial services .

Key Areas of AI Risk:

Vulnerability Discovery: Frontier AI models can find and exploit system vulnerabilities, significantly compressing the timelines for patching, testing, and remediation .

Phishing and Social Engineering: AI-enabled phishing can be more personalised and persuasive “at scale,” increasing the likelihood of successful attacks .

Deepfakes and Synthetic Media: AI-generated content can be used to impersonate individuals, eroding traditional verification controls .

Autonomous Attacks: AI can be used to automate attacks, increasing the speed and scale of cyber intrusions .

AI Risk Integration: The MAS has proposed that the board or a committee delegated by it will be responsible to ensure that AI risks, where material, are explicitly addressed within the financial institution’s risk appetite framework .

7.3 Red Teaming and Testing

Red teaming is an essential tool for testing defences against AI-enabled threats. The MAS has introduced a requirement for key financial institutions to conduct AI-assisted “red teaming” on critical internet-facing systems, meaning they need to use advanced AI models to identify potential attack paths .

The task force, jointly established by the MAS and the Association of Banks in Singapore, will facilitate industry sharing of AI cybersecurity use cases and experience, as well as boost cyber defence knowledge . It will also strengthen the cybersecurity posture of financial institutions .

7.4 Governance Frameworks

The ECB’s July 2026 mandate explicitly places responsibility for responding to this evolving environment primarily with banks’ management board under general prudential requirements and requirements under DORA . Banks are expected to revisit strategic ICT decisions, resource allocation, and risk tolerance frameworks where necessary .

The ECB’s priorities include:

  • Accelerating vulnerability and patch management at scale

  • Strengthening monitoring, detection, and AI-enabled defensive capabilities

  • Ensuring effective third-party ICT risk management

  • Enhancing incident response and crisis managementÂ