Skip to main content

What the BIS just told banks about frontier AI - and what it means for your crisis plan

There is a comfortable version of the frontier AI story and an uncomfortable one. The comfortable version says the threat is novel, so you need novel defences. The uncomfortable version is the one the Bank for International Settlements actually published.

In September 2026, the BIS Financial Stability Institute released Occasional Paper No 28 - When machines attack: frontier AI cyber threats and policy responses in the financial sector. Its central finding is not that everything has changed. It is that almost nothing has changed about what you need to do - and everything has changed about how fast you need to do it.

Frontier AI, the paper concludes, does not call for a fundamental change to the prudential framework. It calls for a significant acceleration in the execution of cyber resilience practices firms already have. Governance, patching, detection, response, recovery. The same list. Less time.

That is a harder message than the one being sold at most vendor stands, and it is worth taking seriously.

What actually changed


Three findings in the paper are worth carrying into a board discussion. All three come from sources that can be independently checked, which matters, because this field is thick with unverifiable numbers.

Unpatched software is now the leading way in. Verizon's 2026 Data Breach Investigations Report found that, for the first time, exploitation of vulnerabilities overtook credential abuse as the most common initial access vector for breaches -  31% against 13%. The same report found only 26% of the critical vulnerabilities designated by the US Cybersecurity and Infrastructure Security Agency were fully remediated during 2025, down from 38% the year before.

Read those two together. The route attackers most favour is the one defenders are getting worse at closing.

The capability curve is compounding. The UK AI Security Institute estimates that the length of cyber task a frontier model can complete reliably is now doubling roughly every 4.7 months. Its previous estimate was around eight months. The doubling time itself is shortening.

That figure deserves more attention than any single scary anecdote, because it is what makes planning horizons unstable. A control set that is adequate today, assessed annually, is being assessed against a threat that has doubled in capability twice between reviews.

Exploitation is the step change, not discovery. Earlier models could already find vulnerabilities. What the ExploitGym benchmark showed is that the newest models are markedly better at turning a vulnerability into a working exploit - the best-performing model produced working exploits for 157 of 898 real-world instances, around 17%. Not a majority. But a long way from zero, and the trend line is the point.

The practical consequence is the one the paper keeps returning to: the interval between a vulnerability becoming known and it being exploited is compressing. The Cross Market Operational Resilience Group, the UK's joint public-private resilience body, anticipates remediation timelines falling from weeks to days, and in some cases to hours.

What regulators are asking for


The striking thing about the paper's survey of financial authorities is how little disagreement there is.

  • The Bank of England, FCA and HM Treasury issued a joint statement on frontier AI and cyber resilience in May 2026.

  • The FCA followed with findings from a multi-firm review, noting that vulnerability discovery is accelerating faster than firms' ability to respond.

  • The ECB wrote to bank CEOs directly.

  • Germany's BaFin created a new supervisory division to run shorter, faster "IT spotlight" inspections and called for accelerated patching.

  • The HKMA told banks to review their defences on the assumption that attacks now arrive at machine speed, and to strengthen incident response and recovery specifically.

  • Japan's FSA and the Bank of Japan issued a joint request on short-term measures.

  • APRA and ASIC ran industry roundtables and published a board preparedness checklist.

Different jurisdictions, near-identical instruction: assume breach is more likely, and compress the time between detection, decision and recovery.

Note where the emphasis has moved. Not to prevention. Authorities are consistent that preventive fundamentals - patch management, zero trust, identity and access management, secure development - remain correct and unchanged. The shift is towards the assumption that some of it will fail anyway, and that what distinguishes a resilient firm is how quickly it contains, communicates and restores.

The paper is blunt on one related point: firms that have underinvested in cyber fundamentals should not expect AI-enabled defence to substitute for them.

The part most firms will underweight


The paper's most under-discussed argument is about dependency, not attack.

Financial institutions now depend on a small number of cloud providers, software vendors and AI developers. Australia's APRA characterises frontier AI as simultaneously creating cyber risk, third-party risk, concentration risk and sovereign access risk — that last one meaning a regulatory decision taken in another country can impair your critical business processes without any attacker being involved.

This is not hypothetical. The paper's own timeline records a US export control directive on 12 June 2026 that cut off non-US access to two frontier models, reversed on 1 July. Nineteen days, no breach, no attacker, and a capability withdrawn from every affected firm simultaneously.

The resilience question that follows is uncomfortable and specific: when a shared provider fails, how many of your critical services fail with it - and does your ability to coordinate a response depend on the same provider?


Five questions for your next resilience review


  1. What is our actual median time from disclosure to patch on internet-facing systems, measured rather than targeted?

  2. Who is authorised to approve emergency patching outside the maintenance window, and can they be reached in twenty minutes?

  3. If our primary collaboration and email environment is compromised or deliberately isolated, where does the crisis team meet?

  4. Which of our critical services share a single underlying provider, and have we tested that assumption rather than assumed diversity?

  5. Can we produce a defensible, timestamped record of who decided what and when, after the fact, to a supervisor?

Question three is the one that catches people. A great many crisis plans are documented inside the environment they are designed to recover.

Where YUDU Sentinel fits


We build out-of-band crisis communications, so our interest here is not neutral and we will not pretend otherwise. But two points from this paper map directly onto why Sentinel is architected as it is.

Every Sentinel client runs a fully independent single-tenant instance with its own operating system, hosted separately from Microsoft 365 and Azure. There is no shared platform whose compromise cascades across clients — the isolation is at instance level, not merely at data level. When the concern is concentration risk, that architecture is the answer to the question rather than an added instance of it.

And because Sentinel holds a complete, tamper-evident and exportable audit trail, the record of decisions taken under pressure survives the incident that produced them. SMS alerting reaches contacts without requiring an app on their device, which matters when the estate you are trying to reach is the estate you have just isolated.

The BIS paper does not recommend out-of-band communications by name. That inference is ours. But when every authority surveyed is asking firms to compress response and recovery timelines, and when the working assumption is that the primary environment may be unavailable, the conclusion is not a long walk.


Source: Crisanto, J C, A Currat and J Yong (2026), "When machines attack: frontier AI cyber threats and policy responses in the financial sector", BIS Financial Stability Institute Occasional Paper No 28, September 2026. Available at www.bis.org.

YUDU Sentinel won the 2025 BCI European Award for Best Resilience Platform.

Richard Stephenson
Written byRichard Stephenson
16 Sep 2026
Richard is the CEO of crisis management software provider YUDU Sentinel. Richard has run public listed companies, mid-market private equity investments and tech start-ups. His professional skills include digital strategy, crisis management, risk and digital document publishing.