The Financial Sector is entering a new era of cyber risk shaped by rapid advances in frontier artificial intelligence (AI). The Prudential Authority (PA) recently warned that advances in AI are accelerating the speed, scale, and sophistication of attacks across the financial sector. This means that traditional cybersecurity approaches based on periodic patching, manual reviews, and delayed response cycles are no longer sufficient. In light of the awareness issued by the PA, FSPs must also prepare for a threat environment where attackers can exploit vulnerabilities at an accelerated speed.
The PA highlights that frontier AI technologies are capable of autonomously identifying software vulnerabilities, generating exploits, and coordinating attacks faster than ever before. Institutions that rely on outdated systems, third-party service providers, or fragmented technology environments may be particularly vulnerable.
To prepare effectively, there should be a focus on cyber resilience through continuous monitoring and automated threat detection. Rather than focusing only on the volume of cyber risks, institutions should prioritise vulnerabilities based on exploitability and potential impact. Continuous validation of applications, third-party integrations, cloud environments, and privileged access accounts is becoming essential. Cybersecurity tools enhanced with AI can help institutions detect anomalies, contain threats, and respond more rapidly to incidents.
Governance and leadership oversight are equally critical. The PA makes it clear that AI-accelerated cyber risk is now a board and senior management responsibility. The Financial Sector should ensure that cyber risk management is embedded into enterprise risk frameworks and that decision-making authority during cyber incidents is clearly defined. Boards should regularly review risk appetite, incident response readiness, and operational resilience capabilities against increasingly compressed attack timelines.
There should also be a focus on secure and responsible AI adoption within their own organisations. As AI tools become integrated into operations and software development, institutions must implement governance mechanisms to monitor AI usage, detect unsafe behaviour, and ensure compliance with regulatory standards. Staff training and cyber awareness programmes should evolve to address AI-driven threats such as advanced phishing, automated fraud, and social engineering attacks.
Importantly, the PA emphasises that strong cybersecurity hygiene remains the foundation of resilience. Maintaining visibility across systems, enforcing identity and access controls, applying timely patches, and testing recovery procedures are still critical controls. Closely aligning with the Joint Cybersecurity and Cyber Resilience Standard will be a better position to be in to withstand AI-accelerated threats while maintaining operational continuity and stakeholder confidence.
