Summary

  • A report from the Bank for International Settlements highlights that AI is reducing the time banks have to address software vulnerabilities.
  • The authors assert that traditional patching timelines are increasingly inadequate.
  • Regulatory bodies are advocating for quicker fixes and better readiness to manage breaches and restore operations.

The Bank for International Settlements (BIS) has issued a warning indicating that the rise of advanced AI technologies is significantly compressing the timeframe banks have to rectify software vulnerabilities before they can be exploited by cybercriminals.

In a paper released on Wednesday by the Financial Stability Institute, the authors underscore the urgency for banks to hasten both their software updates and the decision-making processes involved in these repairs. This report adds to previous alerts from AI developers and financial regulators about the increasing speed of cyberattacks fueled by more sophisticated AI models.

Myriad: What will be crude oil's next move? Make your prediction here.

The report states, "The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation." The authors caution that standard security assessments and routine patching are proving to be inadequate, noting that the time frame for identifying vulnerabilities to their exploitation has shrunk from weeks to mere minutes.

It references findings from a review by the U.K. Financial Conduct Authority, which suggests that the pace of vulnerability identification is outstripping firms' capacity to respond. Additionally, guidance from the Institute of International Finance advocates for accelerated patching efforts, even outside predetermined maintenance periods, and a greater willingness to accept planned downtimes.

According to the paper, separate guidance from the U.K.'s Cross Market Operational Resilience Group anticipates that the time required for repairs could dwindle from weeks to just days or even hours.

While these proposed timelines are advisory, regulators are pressing banks for more rapid responses. For example, Germany’s BaFin has called for expedited patching protocols, and the monetary authority in Hong Kong has emphasized the need for stronger responses to breaches and recovery processes.

The report mentions that the Hong Kong Monetary Authority has recommended that institutions incorporate AI-driven cybersecurity scenarios into their operational resilience strategies and enhance their incident response and recovery capabilities, acknowledging that breaches are likely to become more frequent as the cyber threat landscape evolves. It also notes that the European Central Bank's cyber resilience stress testing and the Digital Operational Resilience Act highlight the necessity for institutions to not only withstand cyber attacks but also to maintain critical services during serious operational disruptions.

The warnings in the BIS report follow an August call for enhanced cyber defenses supported by OpenAI, Anthropic, and over 100 other organizations. The signatories advocated for stricter access controls, improved threat sharing, and increased oversight of AI systems.

The paper discusses the Hugging Face breach involving OpenAI models as initial evidence that capabilities shown in testing can lead to actual attacks on systems. OpenAI later described how its agents worked together during the incident.

While the authors point out that typical safeguards were bypassed and significant computational resources were utilized, they clarify that this incident does not directly reflect the risks associated with publicly accessible AI tools. They assert, "The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own. Nevertheless, they may pursue a narrowly defined task with unintended and harmful consequences." They emphasize that the critical factor for cyber resilience is the combination of a capable model with a software system that allows it to plan, utilize tools, and operate autonomously.

Daily Debrief Newsletter

Stay updated daily with the latest news stories, original features, podcasts, videos, and more.