Indonesian Political, Business & Finance News

New Catastrophe Hits Banks, Government Gives Four-Month Deadline

| Source: CNBC Translated from Indonesian | Finance
New Catastrophe Hits Banks, Government Gives Four-Month Deadline
Image: CNBC

A new catastrophe is hitting the European banking industry. Banking supervisory authorities have warned that the latest generation of artificial intelligence, or ‘frontier AI’, could trigger systemic cyber risks for the financial sector. As a result, approximately 110 banks reportedly have only until the end of October 2026, or about four months, to prepare an action plan to face this threat. A Financial Times report on 7 July 2026 stated that European banking supervisors have sent letters to 110 banks asking them to prepare a comprehensive action plan regarding AI-driven cyber threats. The requested plan must include controls, resources, the division of roles and responsibilities, and an implementation schedule for dealing with AI-based cyber attacks. This move marks a change in the regulator’s approach to AI. If previously the main focus was on the governance of AI use, attention has now shifted to cyber resilience as part of financial system stability. The warning is also in line with the view of the European Systemic Risk Board (ESRB). In a document released on 2 July 2026, the institution stated that the latest capabilities of frontier AI have created a structural increase in systemic cyber risk in the European Union’s financial system. According to the ESRB, advanced AI models are capable of accelerating the process of searching for security gaps, combining various vulnerabilities, and reverse engineering security updates. These capabilities are considered able to help cyber criminals launch attacks more quickly and effectively. In agreement, European Central Bank (ECB) Supervisory Board member Claudia Buch, in a speech on 3 June, revealed that more than 85% of large banks under ECB supervision are already using AI in their operations. However, she also warned that advanced AI models can cut the cost and time needed to find, combine, and exploit software vulnerabilities. This condition means banks must be able to increase their speed of response to evolving threats. For the banking industry, the biggest challenge is not just regulating the use of AI, but proving that the process of handling security vulnerabilities can run as fast as the AI capabilities utilised by attackers. This means banks need to accelerate the process of closing security gaps (patching), have a clearer map of dependencies on systems and third-party providers, and prepare incident handling simulations assuming that attackers are also utilising AI. This change also pushes the AI issue closer to aspects of security engineering, digital asset inventory, system dependency management, and oversight at the board of directors level. The deadline for submitting the action plans at the end of October will be an indicator of whether regulators will apply uniform control standards for all banks or provide specific improvement measures for institutions deemed to still have weaknesses. This approach also has the potential to become a reference for other tightly regulated sectors in classifying cyber risks due to frontier AI as part of future operational resilience testing.

View JSON | Print