NewsLayer.com

Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS

The Bank for International Settlements says routine patching schedules are increasingly inadequate and cites guidance urging banks to accept planned downtime for urgent fixes.

Jason Nelson

Publisher Decrypt

Sep 10, 2026 at 6:13 PM UTC · 3 分钟阅读

Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS
Image via Decrypt
翻译中…

In brief

  • A BIS paper warns that AI is shortening the time banks have to repair software vulnerabilities.
  • The authors say routine patching schedules are increasingly insufficient.
  • Supervisors are urging faster fixes and better preparation to contain breaches and restore services.

Advanced AI is leaving banks less time to fix software flaws before attackers exploit them, according to a new paper published by the Bank for International Settlements.

The Financial Stability Institute paper, published on Wednesday, adds to recent warnings from AI developers and financial regulators that increasingly capable models are accelerating cyberattacks. The new report's focus is on banks’ ability to respond, with the authors arguing that institutions must speed up both software repairs and the decisions needed to authorize them.

Myriad: Crude oil's next move? Click to make your prediction.

“The most significant development brought about by frontier AI is autonomous vulnerability discovery and exploitation,” the authors wrote, warning that periodic security assessments and scheduled patching are increasingly insufficient. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes.”

The paper cites a U.K. Financial Conduct Authority review finding that vulnerability discovery is outpacing firms’ ability to respond, alongside Institute of International Finance guidance urging faster patching—even outside scheduled maintenance windows—and greater acceptance of planned downtime.