AI is changing both cyber defence and cyberattack capability
Artificial intelligence is altering cybersecurity in two directions at once. Banks can use AI to analyse large volumes of network activity, prioritise alerts and detect suspicious patterns more quickly. Attackers can use the same capabilities to automate reconnaissance, improve social engineering and lower the expertise required to develop certain forms of malicious activity. The result is not a completely new cyber-risk landscape, but an acceleration of an existing contest between attackers and defenders.
For banks, this matters because they are attractive targets and operate highly interconnected technology estates. Financial institutions hold valuable data, process large volumes of payments and rely on complex combinations of legacy systems, cloud platforms and third-party providers. AI can help attackers navigate that environment more efficiently, while defenders must improve the speed and quality of detection and response.
Social engineering is becoming more convincing
Phishing is one of the clearest examples. Generative AI can produce grammatically accurate, personalised messages in several languages and imitate the tone of a colleague or supplier. Traditional warning signs such as poor spelling are therefore becoming less useful. Staff need stronger verification habits, particularly where a request involves credentials, payment instructions or sensitive information.
Synthetic audio and video create a related risk. An attacker may imitate an executive, customer or supplier convincingly enough to influence an employee under time pressure. High-value instructions should therefore rely on controls independent of the communication channel, such as call-back procedures, dual approval or other authenticated verification.
Technical attack cycles may accelerate
AI can also assist with code generation, vulnerability research and analysis of public information. This does not mean that every criminal suddenly acquires the capability of an advanced threat actor, but it can reduce the cost and time required to perform tasks that previously demanded more specialised knowledge. Banks may therefore face larger volumes of technically competent attacks.
Defensive teams can use AI in similar ways. Security platforms can prioritise alerts, identify anomalies and summarise incident information. This can reduce analyst workload, but automated security decisions still require governance. False negatives may miss genuine attacks, while excessive false positives can overwhelm teams and reduce attention.
AI systems themselves create new attack surfaces
Generative and agentic systems introduce risks that traditional applications did not present in the same form. Prompt injection, for example, can attempt to manipulate an AI system through malicious instructions embedded in external content. The risk becomes more significant when an AI tool has permission to access databases, email or operational systems.
Permissions should therefore follow the principle of least privilege. An assistant that only produces text has a different risk profile from an agent that can send messages or execute transactions. Sensitive actions should retain explicit approval until the organisation has demonstrated that the process and controls are reliable.
Third-party AI providers also create supplier risk. Banks need to understand where data is processed, how security incidents are communicated and what happens if the provider becomes unavailable or materially changes the service. DORA provides a relevant operational-resilience framework for these dependencies.
Training and governance must evolve
Cybersecurity awareness programmes should now include AI-enabled phishing, synthetic media and the risks created by public AI tools. Employees should know how to verify unusual requests and where to report suspicious activity. Finance, treasury and customer-service teams may require different examples because the attack methods relevant to their roles differ.
Developers also need guidance. AI coding assistants can improve productivity but generated code still requires testing, review and vulnerability scanning. Faster development should not create insecure software more quickly.
Boards and senior managers should ask whether cyber-risk scenarios reflect these changes. The key question is not whether the bank has purchased AI security products, but whether threat models, supplier assessments, staff training and incident exercises have been updated for an environment in which both defenders and attackers use increasingly capable systems.
Conclusion
AI does not replace the fundamentals of cybersecurity. Multi-factor authentication, patching, access control, secure software development, monitoring, backups and incident response remain essential. What changes is the speed and sophistication with which both sides can operate. Banks therefore need to strengthen the integration between AI governance, cyber risk and operational resilience.
The eBSI Banking Academy approaches cybersecurity as part of professional banking competence because cyber events affect customers, operations, reputation and regulatory obligations. The institutions best placed to manage AI-enabled threats will be those that combine strong technology with disciplined process and informed people.
Authentication and software development deserve renewed attention
The growth of synthetic media weakens security procedures that depend on recognising a familiar voice, face or writing style. Banks should review whether high-risk approvals rely too heavily on these informal signals. Payment instructions, privilege changes and disclosure of sensitive information should be verified through authenticated channels that remain reliable even when audio or video can be imitated convincingly.
Secure software development also needs to adapt. AI coding assistants can improve productivity substantially, but generated code must still be reviewed, tested and scanned for vulnerabilities. The fact that code is produced more quickly does not reduce the bank's responsibility for its security. Development teams should therefore integrate AI use into existing secure-development standards rather than treat generated code as a separate category.
These examples reinforce a wider point: AI cyber risk is not confined to the security department. It affects payment controls, staff training, software engineering, supplier management and board oversight. The institution needs a coordinated response because attackers are increasingly able to move across these boundaries as well.
Resilience remains the ultimate objective
Cybersecurity programmes should assume that some attacks will bypass preventive controls. Banks therefore need tested recovery processes, secure backups, alternative communication arrangements and the ability to restore critical services without relying on systems that may be compromised. AI does not change this principle; it increases the speed at which an incident may develop.
Management should also ensure that lessons from AI-related incidents feed back into model governance and staff training. A prompt-injection event, synthetic-identity fraud attempt or misuse of a coding assistant may reveal control weaknesses that extend beyond cybersecurity. Cross-functional review helps prevent the same underlying weakness from reappearing elsewhere.