In the wake of recent reports of AI models launching their own hacks, and growing concern about the capabilities of the latest models, European financial regulators are calling on the industry and authorities to guard against the risks posed by cutting-edge AI models.
In a joint statement, the securities, banking, insurance and pension regulators warned that the latest AI models “significantly accelerate cyber risks, underscoring the urgent need for robust cybersecurity measures and rapid incident response capabilities.”
The regulators stressed that AI tools “could generate systemic risks” given their ability to rapidly discover and exploit weaknesses in the industry’s cyber defences, targeting vulnerabilities in widely used infrastructure, and attacking single points of failure across industry firms.
“Given the accelerating threat landscape, existing weaknesses that remain unresolved may become increasingly material and pose significant risks to operational resilience,” they noted.
Against that backdrop, the regulators called for financial firms to immediately establish governance arrangements to closely track and manage these risks. They also set out measures for firms to deploy to bolster their defences against AI-driven cyber risks, with a focus detecting, managing and preventing these risks.
“While ideally financial entities try and match the speed and sophistication of AI-assisted threat actors, a one-size-fits-all approach when implementing these risk mitigation strategies would not be proportionate and efficient,” it said. “Instead, entities shall take into account their size and overall risk profile, and the nature, interconnectedness, scale and complexity of their services, activities and operations.”
They also called for a consistent, risk-based supervisory approach across various financial sectors to mitigate these risks.