Artificial intelligence promises to make banking faster, cheaper and more efficient. But regulators are increasingly warning about the other side of the equation: the same technology being installed inside banks can give criminals powerful new tools to attack them.
LONDON / BASEL — September 17, 2026
The threat from artificial intelligence to the financial system is moving beyond theoretical discussions about algorithms replacing bank employees.
The more immediate danger may be AI attacking the infrastructure of banking itself.
The Bank for International Settlements has warned that advanced frontier AI models are changing the economics of cybercrime. They can increasingly identify software vulnerabilities, develop exploits and conduct complex multi-stage cyber operations with less human expertise, time and resources than previously required.
For banks, that potentially changes the cyber-security equation.
From hackers to autonomous attacks
Traditional sophisticated cyberattacks require skilled hackers to identify weaknesses, write code and navigate networks.
AI can increasingly automate parts of that process.
The BIS warns that frontier models can compress the time between discovering a vulnerability and exploiting it. That gives banks less time to patch systems before attackers can move.
The risk is particularly significant for finance because banks are connected through payment networks, cloud infrastructure, software suppliers and other shared technology providers.
The International Monetary Fund has separately warned that AI could amplify cyber incidents sufficiently to create funding problems, solvency concerns and disruption across financial markets.
The deepfake enters the bank
The attack does not necessarily need to begin with software.
It can begin with a face.
Or a voice.
The Financial Action Task Force says criminals are increasingly using AI for impersonation, deepfake video, fake websites and sophisticated online scams. Its president, Giles Thomson, has warned that operations which once required large fraud compounds can increasingly be conducted by very small groups equipped with powerful AI systems.
That creates a fundamental problem for banking.
Modern financial systems depend heavily on establishing identity.
Know Your Customer procedures, facial recognition, voice authentication, documents and behavioural analysis are all designed to answer essentially the same question:
Is this person really who they claim to be?
Generative AI is making that question considerably harder to answer.
A recent survey of financial institutions found that 25 per cent reported a known deepfake, voice-cloning or AI impersonation incident, while another 21 per cent were unsure whether they had already experienced one.
AI agents create another problem
The next stage could be even more complicated.
AI is moving from systems that recommend actions towards autonomous agents capable of executing them.
State Bank of India chairman Challa Sreenivasulu Setty recently argued that banking may therefore need to move beyond Know Your Customer towards something resembling “Know Your Agent” — establishing who or what is actually responsible when an AI system initiates financial activity.
Banks may eventually face transactions in which an AI system communicates with another AI system, makes decisions and executes instructions with limited human involvement.
That raises questions about authentication, responsibility and control that traditional banking regulation was never designed to answer.
Banks are also fighting AI with AI
The picture is not entirely defensive.
Artificial intelligence can simultaneously strengthen banks by detecting unusual transactions, identifying vulnerabilities and responding to cyber incidents faster than human security teams.
That creates an unusual technological arms race.
AI attacks banks.
AI protects banks.
And both sides become faster.
The European Central Bank has described advanced AI as a structural change in the economics of cyber risk. More than 85 per cent of significant banks under European banking supervision already use artificial intelligence.
The question is therefore no longer whether AI will enter banking.
It already has.
The emerging question is whether financial institutions can deploy defensive AI quickly enough to keep pace with criminals using the same technology.
For centuries, banking security was built around vaults, signatures, passwords and eventually digital encryption.
The next generation of banking security may be different.
Banks may increasingly have to determine whether the customer is real, whether the voice is real, whether the employee issuing an instruction is real — and whether the intelligence attacking their systems is human at all.
Newshub Editorial in Europe – 17 September 2026

Recent Comments