Learning Objectives:

  • Understand the evolving regulatory and supervisory responses to emerging technology risks.

  • Analyse the specific supervisory expectations for quantum resilience.

  • Recognise the role of international coordination in addressing technology risks.

  • Identify the future direction of technology risk regulation.

8.1 Evolving Supervisory Expectations

Regulators are rapidly evolving their supervisory expectations in response to emerging technology risks. The MAS will issue a set of “supervisory expectations” for quantum resilience, setting out progressive timelines for financial institutions to address quantum resilience concerns . The aim is for financial institutions to achieve quantum resilience before the end of this decade .

The MAS will set progressive timelines for financial institutions to:

  • Establish an inventory of their cryptographic assets 

  • Develop a prioritisation of the migration of vulnerable assets to quantum-resilient solutions 

  • Build technical capabilities and governance frameworks to support a quantum-safe migration 

8.2 The Convergence of AI and Quantum Computing

While the quantum threat to encryption is serious by itself, an increasingly urgent concern is its convergence with advances in AI . Individually, each technology poses distinct risks to cybersecurity; together, they threaten to create a compounding effect that could overwhelm current defences far more quickly than either could alone .

Threat actors are using machine learning models to automate vulnerability discovery in software code, identifying weaknesses far more rapidly than manual methods allow . AI-driven tools can also craft highly convincing phishing emails and deepfake audio or video for impersonation attacks, reducing the skill barrier for sophisticated social engineering campaigns . The timeframe in which current defences become inadequate may be shorter than quantum computing progress alone would suggest .

8.3 International Coordination

International coordination is essential for addressing technology risks that transcend national boundaries. The MAS and the Bank of Thailand have forged a cybersecurity partnership through a Memorandum of Understanding that establishes a framework for the central banks to run joint cross-border cybersecurity and crisis management exercises, exchange regulatory and incident updates and threat intelligence affecting the financial sector, and share research and policy insights to deepen technical collaboration .

The BIS Innovation Hub’s Project Leap also demonstrates the importance of international collaboration, involving central banks from France, Germany, and Italy, as well as private sector partners . The World Economic Forum has noted that this collaborative initiative underscores the commitment of central banks to proactively safeguarding the integrity and resilience of financial infrastructures .

8.4 The Future Direction of Technology Risk Regulation

The future direction of technology risk regulation is likely to include:

Stronger Governance Requirements: Increased focus on AI governance and accountability.

More Testing Requirements: Regular red teaming and vulnerability assessments.

Quantum Resilience Requirements: Progressive timelines for quantum-safe migration.

AI-Specific Requirements: Supervisory expectations for AI-enabled cyber threats, including vulnerability management, testing, and recovery.

Cross-Sectoral Coordination: Enhanced coordination between financial, technology, and national security regulators.

Regulatory bodies worldwide are developing new compliance frameworks that will require quantum-safe cryptography . Given the long-term sensitivity of financial data and the complexity of IT systems, a transition phase should be initiated well in advance so that quantum-resistant encryption schemes can be implemented