The Bank for International Settlements has released a paper arguing that advanced AI is shrinking the window of time banks have to address software vulnerabilities before attackers move in to take advantage of them.
A report from the Financial Stability Institute, released on Wednesday, warns that the time between finding a weakness and someone taking advantage of it has shrunk from weeks down to minutes. The authors make the case that regular patching schedules and periodic security reviews are no longer adequate.
The Shrinking Repair Window
According to the authors, the biggest change caused by frontier AI is that machines can now find and take advantage of security weaknesses on their own. They note that the time it takes for a flaw to be found and then used against a system has shrunk dramatically, going from weeks down to mere minutes.
The research references a U.K. Financial Conduct Authority examination that found that the pace of vulnerability detection has surpassed what firms can manage. It also notes guidance from the Institute of International Finance that calls for quicker remediation—going beyond routine maintenance schedules—and more willingness to accept planned service interruptions.
A separate voluntary guidance document from the U.K.’s Cross Market Operational Resilience Group projects that repair timelines could drop from weeks down to days, and in certain instances, just hours, as outlined in the report.
Regulators Push for Speed
Regulators are urging banks to move more quickly, even though the deadlines in the report are voluntary. Germany’s BaFin has pressed for faster fixes, and Hong Kong’s monetary authority has pushed for a stronger response and recovery after breaches, as the paper reports.
The report notes that the Hong Kong Monetary Authority has pushed financial institutions to add AI-driven cyber scenarios to their operational resilience plans and improve their ability to respond to and recover from incidents. The authority recognises that “breach” scenarios could become more likely as the cyber threat landscape keeps changing.
The European Central Bank’s cyber resilience stress testing programme and the implementation of the Digital Operational Resilience Act both focus on how institutions can keep going through serious operational problems while still withstanding cyber attacks.
The warning comes after an August appeal for better cyber protection that was supported by OpenAI, Anthropic and over 100 other organizations. Those backing the call suggested stricter access controls, increased threat sharing and greater monitoring of AI agents.
The Hugging Face Case
A study from the BIS looks at the Hugging Face breach tied to OpenAI models as early proof that abilities shown in testing can turn into real-world attacks on systems. OpenAI later explained how its agents worked together during the event.
The researchers note that significant computing resources were made available and standard precautions were loosened, but they argue that the event does not directly reveal the dangers of AI systems that are openly accessible to the public.
They wrote that the OpenAI incident does not prove that frontier AI models can develop malicious objectives on their own. But they may carry out a narrowly defined task with unintended and harmful results. The importance of this development for cyber resilience comes from joining a capable model with a surrounding software system that lets it plan, use tools, and act independently.
What This Means for Banks
The main point of the paper is that banks can no longer approach cyber defense as something done at set intervals. Instead, the authors say that institutions need to move faster on fixing software and on making the calls that give permission for those fixes.
| Timeline | Old Expectation | New Reality |
|---|---|---|
| Vulnerability to exploitation | Weeks | Minutes |
| Repair timelines | Weeks | Days to hours |
| Security assessments | Periodic | Increasingly insufficient |
The result is quicker approval chains and increased scheduled maintenance windows. According to the paper’s authors, managers are pushing for improved planning to limit the damage from breaches and get services back up after an attack succeeds.
Financial regulators and AI developers alike have issued a rising chorus of caution about how more powerful models are turbocharging cyberattacks. The report contributes to that accumulation of concern. For banks, the bottom line is plain: the old schedule no longer holds up.
What remains to be seen is if organizations can restore their response speeds before adversaries compel them to act.
Source: decrypt.co
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

