A New Class of Threat
Top financial regulators are sounding the alarm. In an August 2026 letter to G20 finance ministers, the chair of the Financial Stability Board (FSB) identified AI-driven cyber risk as the most immediate threat to the global financial system. This isn't
just about hackers having better tools; it's a fundamental change in the economics of cybercrime. AI models can now plan and execute attacks without a human operator at every step, removing the labor costs that once limited the scope of an attack. The International Monetary Fund (IMF) has echoed these concerns, warning that AI is already fueling attacks against financial firms and that extreme cyber-incidents could trigger funding strains and disrupt entire markets.
Hyper-Personalised and Deceptive Scams
One of the most immediate challenges comes from generative AI. This technology makes it shockingly easy to create highly convincing phishing emails, fake invoices, and social engineering scripts in multiple languages. This lowers the barrier for entry, allowing less-skilled criminals to launch sophisticated attacks. The threat goes beyond text. AI-powered voice cloning can replicate the voice of a CEO or family member with terrifying accuracy from just a few seconds of audio. Scammers use these 'deepfake' voices to authorize fraudulent wire transfers or trick employees into revealing sensitive information. In one reported incident, a firm lost $25 million due to deepfake deception. This weaponizes trust in a way that traditional scams could not.
Automated Attacks on a Massive Scale
Beyond convincing scams, AI gives attackers the ability to automate their work at an unprecedented scale. AI can continuously scan bank networks, payment processors, and fintech APIs for vulnerabilities much faster than human teams ever could. Once a weakness is found, an AI can deploy malware or manipulate transactions automatically. This ability to discover and exploit vulnerabilities at machine speed is a core concern for regulators. The financial system relies on shared digital infrastructure, including cloud services and payment networks. An AI-driven attack that finds a single weakness in a widely used piece of software could cause a ripple effect, disrupting numerous institutions at once and turning a single hack into a systemic crisis.
The Defender's Arms Race
Of course, financial institutions are not standing still. They are also using AI to defend themselves, deploying tools to detect threats, prevent fraud, and identify system weaknesses. The problem is that when attackers operate at machine speed, defenders must do the same. This has created an AI arms race. While AI will likely strengthen cyber resilience in the long run, many experts believe that in the short to medium term, it gives the advantage to attackers. The speed of AI development is so rapid that it challenges existing regulatory frameworks, forcing institutions to constantly adapt just to keep pace. This highlights the need for robust resilience standards and close collaboration between the public and private sectors to share threat intelligence.













