Financial Regulators Race to Arm Themselves with AI as Cyber Threats Outpace Defense
Global supervisory bodies are moving to deploy artificial intelligence tools in their own operations after a new class of AI model demonstrated it can uncover decades-old software vulnerabilities faster than banks can patch them.
Marlene Amstad, Chair of Switzerland's financial regulator FINMA and Chair of the International Organization of Securities Commissions' SupTech Forum, publicly called on regulators and banks last week to urgently adopt supervisory technology, known as SupTech, to counter an emerging wave of AI-powered cybersecurity threats. Her statements coincide with a June 18 IOSCO report drawing on a survey of 49 regulatory jurisdictions, which concluded that SupTech has moved beyond the experimental phase and is now entering institutional consolidation.
The immediate trigger for this urgency is Claude Mythos, Anthropic's frontier AI model released in April 2026. During an evaluation run, the model identified 271 zero-day vulnerabilities in Firefox 150 in a single pass. It also surfaced a 27-year-old bug in OpenBSD and a 17-year-old remote code execution flaw in FreeBSD. Zero-day vulnerabilities are previously unknown software weaknesses with no available patch at the time of discovery, making them immediately exploitable. Anthropic CEO Dario Amodei has warned of "some enormous increase in the amount of vulnerabilities, in the amount of breaches, in the financial damage" as models like this become more widely accessible. Anthropic estimates adversarial actors could obtain comparable capability within 6 to 12 months. The Federal Reserve and US Treasury convened major US bank CEOs in direct response to Claude Mythos' release, and the IMF has separately flagged AI-powered cyber threats as a systemic risk to global banking systems.
Corporate security teams take an average of 87 days to patch known vulnerabilities, while threat actors exploit them in roughly 44 days. That gap has grown more consequential as AI-assisted discovery tools accelerate the pace at which weaknesses are found and weaponized. The IOSCO report identifies cybersecurity vulnerabilities in regulators' own infrastructure as one of the primary barriers to SupTech adoption, alongside funding shortages, skills gaps, and reliance on ad-hoc training rather than structured workforce development. Most regulators globally are running what analysts describe as medium-tech solutions built for operational reliability, not frontier threat response. Approximately 40 technology companies received early access to Claude Mythos through a program called Project Glasswing. Most central banks and government regulators were not included in that initial rollout.
Amstad's statements come as FINMA has separately been active on crypto regulatory infrastructure. The Swiss regulator published Guidance 01/2026 in January, clarifying how Swiss banks, securities firms, and collective asset managers must handle custody of crypto-based assets, including segregation requirements, capital treatment, and third-party custodian risk. The Swiss Federal Council has separately proposed two new FINMA-supervised license categories: payment instrument institutions and crypto-institutions. A public consultation launched in October 2025 puts implementation on track for late 2026 or early 2027. Amstad has described the SupTech Forum as a platform for regulators to exchange experiences on how technology is reshaping supervision, pointing specifically to "opportunities for technology to strengthen supervisory effectiveness, particularly in evolving sectors like digital assets."
IOSCO Board Chair Jean-Paul Servais added that "SupTech is becoming an essential part of modern securities regulation," with authorities increasingly relying on technology to enhance supervision. Amstad has also emphasized a constraint on that ambition: "Supervisory decisions must remain explainable and accountable," requiring a human in the loop for any significant regulatory intervention. Switzerland is operating within a regional framework shaped by the European Union's Digital Operational Resilience Act, known as DORA, which has been in force since January 2025 and sets mandatory technical controls and governance requirements across EU financial institutions.
The urgency is not confined to Switzerland. India's Reserve Bank issued its AI-Accelerated Cyber Threats and Related Safeguards advisory in June 2026, requiring all regulated entities to complete board-approved resilience gap assessments across payments infrastructure, digital channels, cloud environments, and identity management by June 30, a deadline just four days away at the time of publication. The advisory warned that "threat actors are now leveraging AI to scale reconnaissance, find vulnerabilities faster, automate malware," framing the threat in terms that apply directly to Indian financial infrastructure. Indian banks face the same threat window as their Swiss and US counterparts, given that Claude Mythos was made accessible across approximately 15 or more countries in its initial rollout. On June 24, the RBI released draft AI governance rules mandating kill switches for every AI model deployed by a bank, board-level risk committee approval for high-risk applications, and full model inventories covering everything from spreadsheets to large language models. Public comment closes July 24. Indian fintech developers building AI tools for compliance, fraud detection, or anti-money laundering screening should treat these requirements as applying to third-party vendors as well as in-house systems.
Africa faces the sharpest asymmetry. Sub-Saharan Africa processed $205 billion in on-chain transaction value between July 2024 and June 2025, a 52 percent year-on-year increase. Nigeria ranks sixth and Ethiopia ranks twelfth globally for crypto adoption, according to the 2025 Global Crypto Adoption Index. Yet African regulators were largely excluded from Project Glasswing, and formal AI governance frameworks remain absent across most of the continent. South Africa's financial regulators published an AI risk survey in late 2025 but have not yet issued binding rules. Nigeria's Investments and Securities Act 2025 and Kenya's Virtual Asset Service Provider Bill, signed in October 2025, both lack AI or SupTech provisions, illustrating how recent legislative activity has not yet extended to supervisory technology governance. South Africa's 300-plus licensed crypto asset service providers are effectively operating in a gap where regulatory capacity has not kept pace with market growth or threat exposure.
The IOSCO report's findings point to a structural problem that Amstad's forum has so far been unable to solve: regulators are sharing experiences with each other but are not building shared tools. Each jurisdiction is developing SupTech independently, and an analysis of the available evidence suggests the jurisdictions operating on the smallest budgets carry the largest relative exposure to AI-powered threats. The next milestone to watch is the RBI's July 24 public comment deadline and the Swiss Federal Council's expected legislative progress on crypto licensing by late 2026 or early 2027.