A new paper published by the Bank for International Settlements indicates that cutting-edge AI is narrowing the time window for banks to fix software vulnerabilities. The article states that attackers are discovering and exploiting vulnerabilities at a significantly faster pace, and the practice of banks relying on regular security checks and fixed patching cycles is becoming increasingly insufficient.
This paper, published by the Financial Stability Institute of the Bank for International Settlements, focuses on the responsiveness of banks. The authors believe that banks not only need to complete technical repairs more quickly but also need to shorten internal approval and authorization times; otherwise, vulnerabilities may be exploited before patches are deployed.
The time window has been significantly shortened.
The paper states that one prominent change brought about by cutting-edge AI is the increased automation of the process of vulnerability discovery and exploitation. In the past, there was often a several-week buffer period between discovering a vulnerability and launching an attack; now, this time difference may have been reduced to just minutes.
A review by the UK Financial Conduct Authority (FCA) was also cited in the paper. The review results indicated that the speed at which vulnerabilities are discovered is exceeding the response capabilities of some institutions. The International Finance Association had previously recommended that financial institutions should accelerate the deployment of patches and, when necessary, not wait solely for scheduled maintenance windows, while also being more prepared to accept the practical needs that come with planned outages.
Regulators call for faster handling
The paper mentions that although some of the repair deadlines are still voluntary industry guidelines, regulatory authorities are urging banks to take action more quickly. Germany's Federal Financial Supervisory Authority BaFin has called for faster patching, while the Hong Kong Monetary Authority requires institutions to enhance their response and recovery capabilities after intrusions.
According to the paper, the Hong Kong Monetary Authority has encouraged financial institutions to incorporate cyber attack scenarios driven by AI into their operational resilience plans and to enhance their incident response and recovery capabilities, as system breaches may become more common with changes in the threat environment.
On the European side, the European Central Bank's network resilience stress tests, as well as the implementation of the 'Digital Operations Resilience Act', also focus on another aspect: banks not only need to withstand attacks but also continue to provide critical services during severe operational disruptions.
Hugging Face event is used as a reference case
This paper also mentions an intrusion incident related to Hugging Face, and regards it as a preliminary indication that the capabilities demonstrated by AI during testing could potentially be transformed into attacks on real systems. OpenAI subsequently described as well the coordination method of its proxy system in this operation.
However, the paper authors also emphasize that there were special circumstances in this case, including a relaxation of conventional security measures and the system receiving substantial computational support. Therefore, it cannot be directly equated with the general risks associated with the public AI tool.
The author also stated that this incident does not mean that the cutting-edge AI model will automatically become a malicious target on its own. However, when a high-capacity model is combined with callable tools and software systems that can execute tasks autonomously, even with limited target settings, harmful consequences may still occur. This represents a new source of pressure on the resilience of bank networks.









