Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS

A Bank for International Settlements paper warns that advances in AI are compressing the time banks have to fix software vulnerabilities, shrinking response windows from weeks to minutes. The report says routine patching schedules are no longer adequate and cites supervisory guidance pushing institutions to accept planned downtime and speed up authorization for urgent fixes.

By AI NewsroomPublished about 1 hour agoUpdated about 1 hour ago0 views
Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS

Why It Matters

If attackers can exploit flaws within minutes, banks’ existing maintenance and approval cycles may leave critical systems exposed; supervisors across jurisdictions are urging faster patching and stronger recovery plans to limit service disruption and contain breaches.

Key Facts

  • Publisher: Financial Stability Institute, Bank for International Settlements
  • Publication timing: Published Wednesday (per source)
  • Primary finding: AI-driven autonomous vulnerability discovery and exploitation shortens the window for remediation from weeks to minutes
  • U.K. regulator cited: Financial Conduct Authority review finding discovery outpaces firms’ response ability
  • Industry guidance cited: Institute of International Finance advising faster patching, including outside scheduled maintenance windows and acceptance of planned downtime

A Bank for International Settlements paper from the Financial Stability Institute warns that more capable AI models are accelerating cyberattacks and reducing the time banks have to repair software flaws. The authors argue that autonomous AI-driven tools can discover and exploit vulnerabilities far faster than previous methods, narrowing remediation windows that used to be measured in weeks down to minutes.

The report draws on supervisory reviews and industry guidance to show current defenses are lagging. It cites a U.K. Financial Conduct Authority review that found vulnerability discovery is outpacing firms’ capacity to respond, and quotes Institute of International Finance guidance urging institutions to speed up patching — including making fixes outside routine maintenance windows and accepting planned downtime when necessary. The U.K. Cross Market Operational Resilience Group is also noted as expecting repair timelines to compress from weeks to days and, in some cases, hours.

Regulators across jurisdictions are pushing banks to adapt. Germany’s BaFin has called for quicker patching, while the Hong Kong Monetary Authority has encouraged institutions to build AI-driven cyber scenarios into operational resilience programmes and strengthen incident response and recovery. The paper also highlights the European Central Bank’s cyber resilience stress testing and the Digital Operational Resilience Act as frameworks that emphasise maintaining critical services through severe operational disruptions.

As part of its analysis, the BIS paper examines an intrusion linked to Hugging Face that involved OpenAI models as preliminary evidence that capabilities demonstrated in tests can translate into attacks on real systems. OpenAI later described how its agents coordinated during that operation. The authors caution, however, that the incident involved relaxed safeguards and substantial compute resources, and therefore does not directly represent the risks posed by widely available AI tools. Still, the paper stresses the significance of combining a capable model with surrounding software that enables planning, tool use and autonomous action.

The report sits alongside earlier calls — including an August appeal backed by OpenAI, Anthropic and over 100 organisations — for stronger cyber defences, tighter access controls, threat sharing and closer oversight of AI agents. Overall, the BIS paper urges banks to speed both technical repairs and the decision-making needed to authorize them so institutions can contain breaches and restore services more rapidly.

Keep Reading