- A BIS paper warns that AI is shortening the time banks have to repair software vulnerabilities.
- The authors say routine patching schedules are increasingly insufficient.
- Supervisors are urging faster fixes and better preparation to contain breaches and restore services.
Advanced AI is leaving banks less time to fix software flaws before attackers exploit them, according to a Financial Stability Institute paper published Wednesday. The report argues that institutions must speed up both software repairs and the decisions needed to authorize them.
“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes.”
The paper cites a U.K. Financial Conduct Authority review finding that vulnerability discovery is outpacing firms’ ability to respond. Separate guidance from the U.K.’s Cross Market Operational Resilience Group anticipates repair timelines shrinking from weeks to hours.
BaFin in Germany has called for quicker patching, while the Hong Kong Monetary Authority has urged stronger breach response and recovery. “…the [European Central Bank’s] cyber resilience stress testing programme…emphasise[s] institutions’ ability…to continue delivering critical services throughout severe operational disruptions,” the report said.
The warning follows an August call for stronger cyber defenses backed by OpenAI, Anthropic, and over 100 other organizations. The BIS paper examines the Hugging Face intrusion involving OpenAI models as preliminary evidence of real-world attacks.
“The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own,” the authors wrote. “The significance…lies in combining a capable model with a surrounding software system that enables it to plan, use tools and act autonomously.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
