Featured answer: Frontier AI changes bank cyber risk primarily by increasing attack speed, scale and adaptability while also introducing new internal attack surfaces. Banks should combine threat intelligence with service-level scenarios, control-performance metrics, recovery testing, loss-distribution uncertainty and governance that treats cyber events as capital, liquidity and customer-impact problems.
Artificial intelligence does not make every cyber threat new. Phishing, vulnerability exploitation, ransomware, credential theft and third-party compromise remain central. What changes is the economics of attack: language generation can personalise lures, automation can accelerate reconnaissance, and code assistance can help adversaries adapt known techniques. At the same time, banks create new exposures through AI interfaces, retrieval systems, plugins, excessive permissions and uncontrolled data use.
Key takeaways
- Separate evidence on observed threats from speculative frontier-AI scenarios.
- Model cyber loss as a multi-stage event with operational, conduct, liquidity and reputational consequences.
- Use KRIs that measure exposure and control performance, not activity counts.
- Test restoration and data integrity under simultaneous third-party and communication stress.
- Link scenario severity to service criticality and management decision points.
The 2025 threat evidence
ENISA's 2025 threat landscape identifies vulnerability exploitation as an important initial-access route and describes AI as a defining element of the threat environment. Its finance-sector landscape, published in February 2025, provides sector-specific context. These sources support heightened attention but do not justify treating every reported global percentage as directly representative of one bank. Internal exposure, controls and adversary profile remain decisive.
From threat event to bank loss
A cyber scenario should specify the full transmission chain: initial access, privilege escalation, lateral movement, service or data compromise, detection, containment, restoration and secondary impacts. Financial loss can include incident response, fraud, customer remediation, legal cost, regulatory consequences, lost income and longer-term franchise effects. A data-integrity event may be more dangerous than an outage because incorrect balances or risk data can persist after systems appear available.
Expected cyber loss can be represented as E[L] = Σ p(s) × E[L | s] across scenario states s. The formula is simple; estimating probabilities is not. Sparse internal events, changing controls and intelligent adversaries make historical frequency unstable. Risk managers should therefore present ranges, scenario weights and sensitivity rather than a falsely precise single figure.
AI-enabled external attacks
AI can improve language, translation and personalisation in social engineering and may help attackers generate variants that evade simple signature controls. Deepfake audio or video can strengthen payment fraud and executive impersonation. Defensive implications include stronger transaction verification, out-of-band confirmation, behavioural monitoring and staff exercises that do not rely on spotting poor grammar.
For vulnerability exploitation, the critical metric is often exposure time. Measure the interval between public disclosure, asset identification, mitigation and verified closure. Internet-facing critical assets and exploitable identity systems should receive risk-based priority rather than queue order.
Internal AI attack surfaces
Banks should threat-model prompt injection, unsafe tool use, data exfiltration through retrieval, model-supply-chain compromise and excessive agent permissions. An assistant that can read email, search files and initiate workflows combines several trusted channels. Least privilege, segmented credentials, allow-listed actions and immutable logs are essential when AI can use tools.
Shadow AI is an operational and data risk. Blocking public tools may reduce one exposure while driving work into less visible channels. A better framework offers approved services, classifies permitted data, monitors use and creates a rapid review path for legitimate cases.
Cyber stress testing
Scenarios should be severe but plausible and linked to critical functions. A useful test might combine ransomware at a major service provider, compromised privileged credentials, customer misinformation and a market-stress day. The bank should quantify unavailable services, transaction backlog, intraday liquidity, customer remediation, recovery time and the possibility that restored data cannot be trusted.
Reverse stress testing begins from failure: for example, the point at which payments remain outside tolerance, liquidity resources become operationally inaccessible or data integrity prevents reliable regulatory reporting. Teams then identify combinations of attack, control failure and recovery delay that could produce that state.
Capital and insurance
Operational-risk capital should reflect severe cyber scenarios and uncertainty. Insurance recoveries should be modelled net of limits, exclusions, deductibles, payment delay and insurer counterparty risk. A policy can reduce loss severity but cannot restore a service or prevent customer harm.
Regulatory perspective
DORA is binding EU law for covered entities and establishes requirements for ICT risk, incidents, testing and third-party risk. The FSB's cyber response toolkit and 2025 FIRE report are international guidance and coordination frameworks, not directly applicable legislation. Banks should label each source accurately and map it to their legal entities and jurisdictions.
What CROs should do now
- Build cyber scenarios around critical business services and data integrity.
- Measure patch latency and exposed-asset inventory completeness.
- Threat-model every material AI application and tool permission.
- Test decision-making and recovery under provider outage and misinformation.
- Quantify capital and insurance with explicit uncertainty and recovery timing.
- Report residual risk in business terms to the board.
Conclusion
Frontier AI is an accelerator and an attack surface, not a reason to abandon disciplined cyber-risk management. Banks need evidence-based threat assessment, realistic service scenarios, tested recovery and transparent loss uncertainty. The objective is not to predict the next technique; it is to remain capable when techniques, providers and conditions change.
References
- ENISA, Threat Landscape 2025, 1 October 2025
- ENISA, Finance Sector Threat Landscape, 21 February 2025
- Financial Stability Board, FIRE Final Report, 15 April 2025
- European Union, Regulation (EU) 2022/2554 (DORA)
Frequently Asked Questions
How does frontier AI change bank cyber risk?
AI can increase the speed, scale and personalisation of social engineering, lower the cost of reconnaissance and code adaptation, and expand risk from poorly controlled internal AI tools.
Should cyber risk be modelled as an operational-risk scenario?
Yes, but scenarios should include service interruption, data integrity, legal and conduct impacts, liquidity effects, third-party dependencies and recovery uncertainty rather than only direct financial loss.
Can cyber insurance replace cyber capital and controls?
No. Coverage is subject to limits, exclusions, deductibles, aggregation and claims uncertainty. It is a risk-transfer layer, not a substitute for prevention, resilience or capital assessment.
What should a cyber KRI measure?
Useful KRIs measure exposure and control performance, such as internet-facing critical assets, patch latency, privileged-access exceptions, tested recovery time, backup integrity and third-party concentration.