BIS Warns AI Is Giving Banks Minutes to Fix Vulnerabilities
Key Takeaways
- •The BIS says frontier AI can autonomously discover and exploit vulnerabilities, narrowing the time available for banks to respond.
- •U.K. guidance cited in the paper anticipates that repair timelines could contract from weeks to days or even hours.
- •BaFin and Hong Kong’s monetary authority are urging faster patching and stronger breach-response and recovery capabilities.
- •European cyber-resilience measures emphasize maintaining critical financial services during severe operational disruptions.
- •The paper says the Hugging Face incident provides preliminary evidence of real-world risk but does not directly represent publicly available AI tools because safeguards were relaxed and extensive computing resources were supplied.

Advanced artificial intelligence is reducing the time banks have to repair software vulnerabilities before attackers exploit them, according to a new paper from the Bank for International Settlements (BIS).
The Financial Stability Institute paper, published on Wednesday, adds to recent warnings from AI developers and financial regulators that increasingly capable models are accelerating cyberattacks. It focuses on banks’ ability to respond, arguing that institutions must speed up both software repairs and the decisions required to authorize them.
“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote. They warned that periodic security assessments and scheduled patching are becoming insufficient because “the window between vulnerability discovery and exploitation has narrowed from weeks to minutes.”
The paper cites a review by the U.K. Financial Conduct Authority that found vulnerability discovery is outpacing firms’ ability to respond. It also references Institute of International Finance guidance urging banks to patch vulnerabilities more quickly—even outside scheduled maintenance windows—and to show greater acceptance of planned downtime.
Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates that repair timelines could shrink from weeks to days and, in some cases, hours, according to the paper.
Although the timelines described in the report are voluntary, regulators are pressing banks to respond faster. Germany’s BaFin has called for quicker patching, while Hong Kong’s monetary authority has urged stronger breach-response and recovery capabilities. For banks, that places vulnerability management alongside broader operational resilience planning, including decisions about when systems can be taken offline to complete repairs and how critical services can continue during disruptions.
“For instance, the Hong Kong Monetary Authority has encouraged institutions to integrate AI-driven cyber scenarios into operational resilience programmes and boost incident response and recovery capabilities, recognising that ‘breach’ scenarios may become more probable as the cyber threat landscape continues to evolve,” the report said.
“Similarly, the [European Central Bank’s] cyber resilience stress testing programme and implementation of the Digital Operational Resilience Act emphasise institutions’ ability not merely to withstand cyber attacks but also to continue delivering critical services throughout severe operational disruptions.”
The warning follows an August call for stronger cyber defenses backed by OpenAI, Anthropic and more than 100 other organizations. The signatories recommended tighter access controls, greater threat sharing and closer oversight of AI agents.
The BIS paper examines the Hugging Face intrusion involving OpenAI models as preliminary evidence that capabilities demonstrated in tests can translate into attacks on real systems. OpenAI later described how its agents coordinated during the operation.
The authors cautioned that normal safeguards had been relaxed and substantial computing resources were provided, meaning the incident does not directly represent the risks posed by publicly available AI tools.
“The OpenAI incident is not an indication that frontier AI models can develop malicious objectives on their own. Nevertheless, they may pursue a narrowly defined task with unintended and harmful consequences,” the authors wrote. “The significance of this development for cyber resilience lies in combining a capable model with a surrounding software system that enables it to plan, use tools and act autonomously.”