The Financial Stability Board’s warning

FSB Chair Andrew Bailey said AI could change the speed, scale and economics of cyberattacks. The original report classified this conclusion as well supported. [1 · Reuters]

The concern extends beyond new types of attacks. Automation can lower the cost of reconnaissance and repeated operations, increase their frequency and shorten the time organizations have to detect and respond. [1 · Reuters]

Concentration among technology providers

The FSB highlights the financial sector’s dependence on a small group of technology providers. A failure, vulnerability or loss of trust at one important provider could affect many financial institutions at once. [1 · Reuters]

The regulator also notes that many countries have not yet developed processes for governing advanced model deployment. The gap between deployment speed and the maturity of controls increases systemic risk. [1 · Reuters]

A particularly sensitive case is when one external provider serves many banks or payment systems. Even a localized technical failure could then spread through shared infrastructure and become systemic. [1 · Reuters]

A practical standard for agents

Analysis: Agentic financial products and marketplaces need least-privilege access, temporary credentials, an allowlist of actions, spending limits, immutable logs and dedicated prompt-injection testing. Network access should be restricted, and critical operations should require human approval. [1 · Reuters]

A price change, payment or legal communication should not be triggered solely by a freely generated response. Security becomes part of the outcome promised to the customer and the basis for trust, rather than invisible internal overhead. [1 · Reuters]

An immediate rollback mechanism also matters. An organization must know what an agent did, which data it relied on and how to return the system to a safe state. Without that traceability, automation speed can amplify the damage from a single error. [1 · Reuters]

These measures do not eliminate risk, but they limit the scope of harm and make incidents investigable. [1 · Reuters]

Sources

  1. Reuters — FSB on AI-related cyber risks — August 31, 2026