Frontier AI Models Shrink Vulnerability Patch Time to Hours
A recent Bank for International Settlements (BIS) paper warns that frontier AI models have shrunk the time banks and crypto platforms have to patch vulnerabilities from weeks to hours.
The paper, titled 'When machines attack: frontier AI cyber threats and policy responses in the financial sector', found that AI-enabled attacks rose 89% in 2025, with an average eCrime breakout time of just 29 minutes.
This is a significant concern for Canadian institutions, as OSFI's Guideline B-13 on technology and cyber risk management already applies to banks and insurers. While crypto platforms are not directly subject to OSFI regulations, they still face similar threats from attackers using AI models.
The paper suggests that the main issue is not a lack of regulations or rules, but rather a need for financial institutions to run their existing cyber controls faster. This includes implementing inventories and activity logs for agents, setting limits on tool access, and requiring human approval for high-impact actions.