BIS says AI is cutting banks’ vulnerability-fix window from weeks to minutes

BIS says AI is cutting banks’ vulnerability-fix window from weeks to minutes

N
News Editor
2026-09-10 18:13:13
A new paper from the Bank for International Settlements says advanced AI is giving banks far less time to repair software flaws before attackers exploit them. Published Wednesday by the Financial Stability Institute, the report argues that the main operational problem is no longer just finding vulnerabilities, but keeping up with how quickly they can be weaponized. Its central warning is stark: the gap between vulnerability discovery and exploitation has narrowed from weeks to minutes. The paper says periodic security reviews and scheduled patching are becoming less effective under those conditions. It points to a U.K. Financial Conduct Authority review that found firms are falling behind the pace of vulnerability discovery, and cites guidance from the Institute of International Finance urging faster patching even outside standard maintenance windows, along with greater acceptance of planned downtime. It also notes voluntary guidance from the U.K.’s Cross Market Operational Resilience Group that envisions repair timelines falling from weeks to days, and in some cases hours. The report also references calls from Germany’s BaFin, the Hong Kong Monetary Authority, the European Central Bank, and the EU’s Digital Operational Resilience Act. As an illustration of how AI capabilities can translate into real-world incidents, the BIS paper examines the Hugging Face intrusion involving OpenAI models, while adding that the case does not directly represent the risks of publicly available AI tools.

Advanced AI is leaving banks with much less time to fix software flaws before attackers move in, according to a new paper from the Bank for International Settlements.

BIS says AI is cutting banks’ vulnerability-fix window from weeks to minutes 2

Published Wednesday by the Financial Stability Institute, the paper adds to recent warnings from AI developers and financial regulators that stronger models are accelerating cyberattacks. Its focus is on how banks respond. The authors argue that institutions need to speed up both technical remediation and the internal decisions required to approve it.

The gap between discovery and exploitation is shrinking fast

“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote. They warned that periodic security assessments and scheduled patching are becoming increasingly inadequate.

“The window between vulnerability discovery and exploitation has narrowed from weeks to minutes,” the paper said.

The report cites a review by the U.K. Financial Conduct Authority that found vulnerability discovery is outpacing firms’ ability to respond. It also points to guidance from the Institute of International Finance urging faster patching, including outside scheduled maintenance windows, and broader acceptance of planned downtime.

Regulators and industry groups are pressing for quicker repairs

Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group, according to the paper, anticipates repair timelines shrinking from weeks to days and, in some cases, hours.

Those timelines may be voluntary, but regulators are also pushing banks to act faster. The paper says Germany’s BaFin has called for quicker patching, while the Hong Kong Monetary Authority has urged stronger breach response and recovery.

“For instance, the Hong Kong Monetary Authority has encouraged institutions to integrate AI-driven cyber scenarios into operational resilience programmes and boost incident response and recovery capabilities, recognising that ‘breach’ scenarios may become more probable as the cyber threat landscape continues to evolve,” the report said.

It adds that the European Central Bank’s cyber resilience stress testing programme, along with implementation of the Digital Operational Resilience Act, stresses that institutions must not only withstand cyberattacks but continue delivering critical services during severe operational disruptions.

The paper points to the Hugging Face intrusion as early evidence

The warning comes after an August call for stronger cyber defenses backed by OpenAI, Anthropic, and more than 100 other organizations. The signatories recommended tighter access controls, more threat sharing, and closer oversight of AI agents.

The BIS paper examines the Hugging Face intrusion involving OpenAI models as preliminary evidence that capabilities shown in testing can carry over into attacks on real systems. OpenAI later described how its agents coordinated during the operation.

The authors also include an important caveat. They say normal safeguards had been relaxed in that case, and substantial computing resources were provided, so the incident does not directly reflect the risks posed by publicly available AI tools.

“The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own. Nevertheless, they may pursue a narrowly defined task with unintended and harmful consequences,” the authors wrote.

They add that the cyber-resilience significance of the development lies in pairing a capable model with a surrounding software system that allows it to plan, use tools, and act autonomously.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.