AI News Feed
Market watch
Cybersecurity

Banks Urged to Trade Periodic Defense for Continuous Resilience as AI Speeds Up Attacks

A TechRadar analysis argues banks must shift from prevention-only strategies to continuous resilience, citing a PYMNTS report on OpenAI's Astra model and an IMF note on AI and financial-sector cybersecurity.

The analysis cites a PYMNTS report this month that OpenAI could not rule out its highest cybersecurity warning level for its upcoming Astra model. That threshold signals a model may be able to independently discover and develop working zero-day exploits, or carry out attacks with minimal human direction.

Around the same time, the International Monetary Fund reached a similar conclusion in a note on artificial intelligence and cybersecurity in the financial sector, the analysis says. The IMF's argument, which the author says banks should be listening to, is that AI does not need to invent an entirely new type of attack to change the risk equation. AI-enabled attacks may not look fundamentally different from attacks carried out by humans. What changes is their speed, scale and capacity to adapt, which accelerates vulnerability discovery and exploitation across shared technologies and turns what used to be isolated incidents into correlated disruptions that hit several institutions at once.

Banking, the analysis notes, has never run on bespoke, siloed technology. It runs on shared foundations including core banking platforms, cloud infrastructure, payment rails, identity systems and a long chain of third-party software. Modern financial infrastructure relies on layers of commercial software, cloud services and open-source libraries. That makes development faster and can strengthen security through shared scrutiny, but it also creates common dependencies, which the author compares to thousands of doors relying on the same key.

The article contrasts the two tempos. An attacker who needs weeks to find a working exploit gives defenders time to patch, monitor and respond. An AI system can potentially find the same exploit in seconds and, in the most autonomous cases, execute a multistep attack with limited ongoing human involvement. The current record cited in the piece is 27 seconds. The IMF frames the underlying issue as a dual-use problem: the same capabilities that let AI find vulnerabilities faster for defensive purposes are the ones that let it find them faster for offensive purposes.

The author says this is not hypothetical for payments specifically. Payment infrastructure has so many overlapping systems at the intersection of common software, cloud dependency and dense third-party integration that a single exploit becomes an ecosystem-wide issue. A vulnerability in a widely deployed component can propagate risk far beyond a single institution, particularly where common cloud services, software libraries or third-party platforms are involved.

For a long time, resilience strategy has leaned heavily on prevention: patch faster, test harder, review more code before release. The article says all of that still matters, but when discovery and exploitation can happen faster than a conventional patch cycle, prevention alone is no longer sufficient. The answer it proposes is a shift from periodic defense toward continuous resilience, with architectures designed to detect, isolate, contain and recover while an attack is unfolding.

The IMF's recommendation points the same way, according to the analysis: institutions need architectures built to limit the blast radius of a successful breach through segmentation, disciplined access controls, zero-trust design and closer oversight of third parties. Detection, containment and recovery need to operate at a speed comparable to the speed of the threat, rather than the speed of the last board-approved incident response plan.

The piece extends the point to how banks govern AI inside their own security operations. AI tools will increasingly play a role in detecting vulnerabilities and responding to threats, but the degree of autonomy granted to those systems must be an explicit governance decision. Institutions need clear boundaries around what AI can access, what actions it can take independently and where human intervention remains mandatory.

That, the author writes, is where the conversation has to move from the security team to the boardroom. Segmentation and access control are technical decisions, but the analysis places the broader question of how much autonomy to grant AI systems in front of bank leadership rather than security staff alone.