cd /news/ai-safety/banks-have-minutes-not-weeks-to-fix-… · home topics ai-safety article
[ARTICLE · art-126108] src=decrypt.co ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS

A new Bank for International Settlements paper published Wednesday warns that frontier AI has narrowed the window between vulnerability discovery and exploitation from weeks to minutes, leaving banks insufficient time to patch software flaws. The Financial Stability Institute paper cites a U.K. Financial Conduct Authority review finding vulnerability discovery is outpacing firms' response, and notes Germany's BaFin and the Hong Kong Monetary Authority are pushing faster patching and stronger breach recovery. The authors point to the Hugging Face intrusion involving OpenAI models as preliminary evidence that tested capabilities can translate into real attacks, while cautioning the incident does not show frontier models develop malicious objectives on their own.

by read3 min views1 publishedSep 10, 2026
Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS
Image: Decrypt (auto-discovered)

In brief

  • A BIS paper warns that AI is shortening the time banks have to repair software vulnerabilities.
  • The authors say routine patching schedules are increasingly insufficient.
  • Supervisors are urging faster fixes and better preparation to contain breaches and restore services.

Advanced AI is leaving banks less time to fix software flaws before attackers exploit them, according to a new paper published by the Bank for International Settlements.

The Financial Stability Institute paper, published on Wednesday, adds to recent warnings from AI developers and financial regulators that increasingly capable models are accelerating cyberattacks. The new report's focus is on banks’ ability to respond, with the authors arguing that institutions must speed up both software repairs and the decisions needed to authorize them.

“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote, warning that periodic security assessments and scheduled patching are increasingly insufficient. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes.”

The paper cites a U.K. Financial Conduct Authority review finding that vulnerability discovery is outpacing firms’ ability to respond, alongside Institute of International Finance guidance urging faster patching—even outside scheduled maintenance windows—and greater acceptance of planned downtime.

Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates repair timelines shrinking from weeks to days and, in some cases, hours, according to the paper.

While the timelines mentioned in the report are voluntary, regulators are pushing banks to act faster: Germany’s BaFin has called for quicker patching, while Hong Kong’s monetary authority has urged stronger breach response and recovery, according to the paper. “For instance, the Hong Kong Monetary Authority has encouraged institutions to integrate AI-driven cyber scenarios into operational resilience programmes and boost incident response and recovery capabilities, recognising that ‘breach’ scenarios may become more probable as the cyber threat landscape continues to evolve,” the report said. “Similarly, the [European Central Bank’s] cyber resilience stress testing programme and implementation of the Digital Operational Resilience Act emphasise institutions’ ability not merely to withstand cyber attacks but also to continue delivering critical services throughout severe operational disruptions.”

The warning follows an August call for stronger cyber defenses backed by OpenAI, Anthropic and more than 100 other organizations. The signatories recommended tighter access controls, threat sharing and closer oversight of AI agents.

The BIS paper examines the Hugging Face intrusion involving OpenAI models as preliminary evidence that capabilities demonstrated in tests can translate into attacks on real systems. OpenAI later described how its agents coordinated during the operation.

While the authors caution that normal safeguards had been relaxed and substantial computing resources were provided, they say the incident does not directly reflect the risks posed by publicly available AI tools. “The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own. Nevertheless, they may pursue a narrowly defined task with unintended and harmful consequences,” they wrote. “The significance of this development for cyber resilience lies in combining a capable model with a surrounding software system that enables it to plan, use tools and act autonomously.”

── more in #ai-safety 4 stories · sorted by recency
── more on @bank for international settlements 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/banks-have-minutes-n…] indexed:0 read:3min 2026-09-10 ·