Learning Objectives:
-
Understand the emerging governance challenges posed by AI-enabled cyber threats.
-
Recognise the implications of quantum computing for cybersecurity governance.
-
Identify the evolving supervisory expectations for cyber resilience.
-
Understand the role of governance in preparing for emerging threats.
8.1 AI-Enabled Threats and Governance Implications
The rapid advancement of artificial intelligence is fundamentally changing the cyber threat landscape, creating new governance challenges for financial institutions. The European Central Bank (ECB) has warned that emerging AI models are fundamentally changing the cyber threat landscape by enabling attackers to identify vulnerabilities and develop functioning exploits much more rapidly than before . The CSSF and the ECB have issued new guidance on AI-enabled cyber risks, governance under DORA, and operational resilience, sending a clear signal that traditional cybersecurity practices alone are no longer sufficient in an AI-enabled threat environment .
The Monetary Authority of Singapore (MAS) has identified both AI-driven cyber threats and quantum computing risks as serious near and medium-term threats to the financial sector . Frontier AI models can find and exploit system vulnerabilities, significantly compressing the timelines for patching, testing, and remediation . “Together, these significantly compress the timelines for patching, testing and remediation” .
8.2 Governance Responses to AI-Enabled Threats
Supervisory Expectations: The ECB requires significant institutions to assess the impact of this evolving threat environment without delay and prepare a comprehensive action plan covering concrete measures, required resources, responsibilities, and implementation timelines . The ECB identifies priority areas including accelerating vulnerability and patch management at scale; strengthening monitoring, detection, and AI-enabled defensive capabilities; ensuring effective third-party ICT risk management; and enhancing incident response and crisis management .
Regulatory Requirements: MAS has introduced a requirement for key financial institutions to conduct AI-assisted “red teaming” on critical internet-facing systems . The central bank will also issue supervisory expectations for key financial institutions to develop and submit comprehensive assessments and action plans to strengthen defence against AI-enabled cyber threats .
Governance Frameworks: The European Supervisory Authorities (ESAs) have stated that AI defensive tooling becomes part of the regulated estate itself and must comply with subsequent regulatory requirements such as EU AI Act and model-risk obligations .
8.3 Quantum Computing Risks and Governance
Quantum computing poses significant risks to the security of data and communications used by financial institutions in the medium term . Experts have given a five to ten year estimated timeframe for when quantum computing could break existing encryption techniques, and the transition to quantum-safe practices will take time . “It is certainly not too early to make serious preparations” .
Supervisory Expectations: MAS will issue supervisory expectations for quantum resilience, setting progressive timelines for financial institutions to address quantum resilience concerns . “Our aim is for (financial institutions) to achieve quantum resilience before the end of this decade” .
Migration Requirements: MAS will set progressive timelines for financial institutions to establish an inventory of their cryptographic assets, develop a prioritisation of the migration of vulnerable assets to quantum-resilient solutions, and build technical capabilities and governance frameworks to support a quantum-safe migration .
8.4 The Evolution of Supervisory Expectations
The ECB and other regulators are raising expectations for cyber resilience. The ECB’s letter of July 7, 2026, identifies rapid advancements in AI systems as a “pivotal change” to the cybersecurity landscape, stressing that this is a long-term structural shift in the threat landscape, not a temporary phenomenon . Responsibility for responding to this evolving environment lies primarily with banks’ management board under general prudential requirements and requirements under DORA, which are expected to revisit strategic ICT decisions, resource allocation, and risk tolerance frameworks where necessary .
The ECB expects banks to focus on three priority areas in the short term: accelerating vulnerability and patch management at scale; enhancing monitoring, detection, and AI-enabled defensive capabilities; and verifying that third-party risk management is fit for purpose given the critical role of ICT service providers in supply chains . Over the longer term, structural measures should include reinforcing defense-in-depth and modernising infrastructure, in particular by replacing or updating legacy technologies, and improving operational resilience through crisis management, recovery mechanisms, and information-sharing arrangements