Top international financial officials, including representatives from the IMF, Bank of England, and European Central Bank, have issued stark warnings about the growing risks posed by advanced AI models to the cyber defenses of the global banking system. This alert comes after Anthropic, an AI company, demonstrated its "Mythos Preview" model's ability to quickly identify thousands of high-severity vulnerabilities across major operating systems and web browsers, raising concerns about the potential for these capabilities to fall into malicious hands and destabilize financial stability.
The swift evolution of AI technology is enabling cybercriminals to conduct more sophisticated and rapid attacks. These AI-driven attacks can operate at speeds, scales, and costs far beyond what skilled human practitioners could achieve. Financial services companies are already experiencing increased vulnerabilities, with 76% of organizations reporting a security incident involving AI applications or models in the past two years, and the finance and insurance sectors collectively accounting for 27% of all cyber incidents in 2025.
Regulators emphasize the need for financial firms to bolster their cyber resilience by adopting effective protective, detective, and response capabilities. This includes deploying automated and AI-enabled defenses to match the speed of AI-driven attacks, effectively managing third-party risks associated with AI, and ensuring senior management has a strong understanding of these emerging threats. Banks like JPMorgan Chase, Lloyds Banking Group, and Santander are enhancing their systems; for instance, Lloyds has developed a "Global Correlation Engine" to identify threats.
While AI presents new challenges, it also offers tools for defense. Financial institutions are exploring AI-powered solutions to improve their cybersecurity. However, the rapidly decreasing time it takes to find and exploit vulnerabilities, as highlighted by JPMorgan's CISO Patrick Opet, underscores the urgency for robust and continuous investment in cybersecurity measures, including appropriate insurance coverage to mitigate risks.
The international community, including the Bank of England, FCA, and HM Treasury in the UK, plans to continuously monitor AI developments and engage with the industry to address these evolving threats. The concern is not just about direct attacks but also the potential for broader market disruptions, funding strains, and systemic failures if these AI-driven cyber risks are not managed effectively through enhanced supervision and global coordination.