The first sign that an artificial intelligence system has begun probing your bank will not arrive as a warning. There will be no security alert pushed to your phone, no flagged login attempt, no unusual transaction notice. By the time anything visible occurs, the system has already mapped its way to the parts of the institution that matter, and the money may already have moved.
This is not a forecast. It is a description of how a category of attack now in widespread commercial use actually unfolds inside the institutions that hold the deposits, mortgages, and pensions of much of the world. The technology that powers these intrusions is not classified. It is not the property of nation-state intelligence services. It is available to anyone with a payment card and an internet connection, and it has fundamentally changed what banks are defending against.
The problem is not that banks are negligent. The institutions most exposed to this shift are, by every conventional measure, well-defended. They pass their regulatory tests. They maintain certified security operations centres. They invest substantial capital in cybersecurity infrastructure. The problem is that the frameworks they use to assess and contain risk were designed for a slower world, and the world has stopped being slow.
Why This Matters Now
Three developments have converged in the past eighteen months that change the calculus for every retail and institutional customer of a financial institution. First, the cost of executing a sophisticated cyber intrusion has collapsed. The kind of attack that previously required a coordinated team of skilled operators working over weeks can now be carried out by a single person using commercially available tools, in hours rather than days.
Second, the persuasiveness of fraudulent communication has reached a threshold where human detection is no longer reliable. Phishing emails written by generative artificial intelligence are not just grammatically clean, they are contextually accurate, drawing on publicly available information about the recipient and their institution to construct messages that read as ordinary internal correspondence. Voice synthesis has reached a similar threshold, and there are already documented cases of fraudulent transfers initiated on the basis of cloned audio of senior executives.
Third, regulators have begun to acknowledge the gap. The European Banking Authority's supervisory priorities for 2025 and 2026 include explicit reference to artificial intelligence as a threat vector, and similar language is appearing in guidance from the Prudential Regulation Authority in the United Kingdom, the New York Department of Financial Services, and the Office of the Comptroller of the Currency in the United States. The frameworks themselves have not yet been rewritten to address what has changed, but the supervisory expectation is moving faster than the rules.
For consumers, the consequence is straightforward. The probability that an attempted fraud against your bank will succeed has risen, and the time available to detect and reverse it has fallen. For institutions, the consequence is structural. The architecture of operational resilience that the industry has built over the past decade was not designed for adversaries that adapt in real time, and the gap between compliance and actual defence is widening.
The Speed Problem
Financial crime has always been an arms race. Fraud techniques evolve, banks adapt, fraudsters adapt again. The pace of that cycle has historically been slow enough that defensive frameworks built around annual or semi-annual assessment could keep up. That is no longer the case.
For most of the past decade, a sophisticated intrusion into a financial institution required a team of skilled operators working over days or weeks. The institution had time. Not much time, but time to detect anomalous activity, contain the affected systems, and respond before catastrophic harm occurred. Internal monitoring tools were calibrated against the speed at which a human attacker could realistically move through an environment.
Artificial intelligence has compressed that window. The same category of attack that previously took a coordinated team eleven days to execute can now be completed in under eight hours by a single operator working with commercially available tools. Reconnaissance that once required weeks of patient probing now happens in minutes. Lateral movement across internal networks that once produced detectable patterns now mimics legitimate administrative traffic with sufficient fidelity to evade threshold-based detection rules that were updated months earlier.
The asymmetry this creates is the central problem. A defender's knowledge of their own attack surface is built from penetration tests run on an annual or semi-annual cycle. An attacker's knowledge is built from continuous automated scanning that updates in real time. The defender is operating with information that is months old. The attacker is operating with information that is hours old. This gap cannot be closed by adding more controls of the existing kind. It requires a different category of capability.
What This Looks Like in Practice
It begins with a message. Not the obvious phishing attempt with a misspelled domain and a contrived sense of urgency, the kind that staff training has taught employees to recognise. An email that uses your name, references your recent work, and is written in the register of someone who understands your institution. Generative artificial intelligence, trained on publicly available information about you and your organisation, produced it in seconds. It will not look wrong because it is not wrong. The information it contains is accurate.
You click. The session is captured by an adversary in the middle proxy that intercepts your authentication, including the one-time code from your security application. Multi-factor authentication, the control on which most institutions have spent the past several years building their identity assurance, has been bypassed in the time it took you to read the message.
What happens next is invisible from the outside. An automated reconnaissance system, running on infrastructure unrelated to the original phishing source, begins to map the environment your credentials can reach. It identifies privileged accounts, locates the systems that handle payments, and looks for the path of least resistance toward them. The mapping that previously took a human attacker eleven days takes the automated system four hours.
Lateral movement begins. The system is configured to mimic legitimate administrative traffic patterns, operating below the threshold at which the institution's security tools would generate an alert. Detection rules calibrated against historical attack signatures do not flag activity that has been specifically engineered to look ordinary. Eight months after those rules were last updated, they are no longer fit for purpose.
The transfers, when they begin, are not dramatic. They are designed not to be. A series of transactions, each within normal operational parameters, distributed across multiple correspondent accounts over a seventy-two hour window. Each individual movement falls below the threshold that would trigger automated review. By the time the cumulative pattern becomes visible, the funds have cleared and the access pathway has been removed. The institution discovers the breach when the liquidity stress emerges, days after the underlying compromise.
Why Banks Struggle to Keep Up
This is not a story about negligent institutions. The banks that financial regulators assess as operationally resilient, the ones that pass their annual stress tests and satisfy their compliance obligations, are exposed to exactly this category of attack. The reason is structural, and it sits at the architectural level of how operational resilience has been defined.
The frameworks that govern operational resilience in modern banking, the Digital Operational Resilience Act in the European Union, the Prudential Regulation Authority's policy on operational resilience in the United Kingdom, the operational resilience guidance from the Federal Reserve and the Office of the Comptroller of the Currency in the United States, share a common architectural assumption. They treat disruptions as bounded events with identifiable start points, known failure modes, and recoverable end states.
This assumption is appropriate for the threats these frameworks were designed around. Infrastructure failures, third party outages, natural disasters, ransomware events with clear impact boundaries. It is not appropriate for a class of threat that is adaptive, continuous, and specifically engineered to operate beneath the thresholds that trigger institutional response.
Impact tolerances are set against maximum tolerable periods of disruption. They define what a material event looks like and how quickly the institution must restore service when one occurs. They do not address an adversary that is specifically motivated to cause harm without ever crossing the threshold that would activate the framework. Critical business service mapping identifies which services matter and to what threshold. It does not surface the silent compromise of a service that continues to function while value is extracted from it.
Scenario testing stress tests these tolerances against defined conditions. The conditions tested reflect the threats the framework was designed to address, which are largely the threats that existed when the framework was written. Adaptive, sub-threshold, artificial intelligence enabled intrusion was not among them.
The Sub-Threshold Problem
The mechanism that makes artificial intelligence enabled attacks structurally different from earlier categories of cyber threat is their ability to operate persistently below the thresholds at which institutional response is triggered. Earlier generations of attack tended to produce detectable signatures. The detection threshold could be crossed accidentally, by tooling that was not subtle enough, by a human operator working too quickly, by a payload that was too large or too obvious.
Adaptive tooling does not have these constraints. It can sustain a presence inside an environment for extended periods, extracting value, mapping systems, and establishing further access without ever generating an event that the institution's controls would classify as material. The threshold becomes the cover under which the attack operates, rather than the line that the attack must cross to succeed.
This is the structural problem. The frameworks that protect financial institutions are built around threshold based detection. They define what counts as significant, and they activate when the significant threshold is breached. An adversary that knows where the threshold sits, and is engineered to operate below it, defeats the framework not by overpowering it but by remaining outside its field of view.
Closing this gap requires a different category of capability than adding more thresholds, or lowering the existing ones. It requires continuous monitoring of behavioural anomalies that may not, individually, cross any threshold, combined with the analytical capacity to recognise that the cumulative pattern of small anomalies is itself a signal. This is not what most operational resilience programmes currently do.
What Adaptive Resilience Looks Like
The institutions that will navigate this shift successfully are not the ones with the largest cybersecurity budgets. They are the ones with the most adaptive risk intelligence. The capacity to detect that something unusual is happening inside their systems before it becomes a loss event, rather than after. The architecture that supports this is different from the architecture that has dominated the past decade of operational resilience investment.
Three capabilities define adaptive resilience, and very few institutions currently have them in integrated form. The first is continuous threat signal ingestion. Not annual or quarterly assessment, but real time monitoring of behavioural metadata that surfaces anomalies before they become impact events. The technical infrastructure to support this exists and is in production use at a small number of institutions. The organisational and governance changes required to act on its outputs are less developed.
The second is automatic mapping of detected anomalies to regulatory obligations. When an anomaly is detected, the institution needs to know immediately which critical business service is potentially affected, which impact tolerance is implicated, and whether a regulatory notification obligation has been triggered. The current state at most institutions is that this mapping happens manually, after the fact, by compliance teams working from incident reports. The latency this introduces is no longer acceptable.
The third is scenario testing that incorporates adaptive attack vectors. The current standard, stress testing against discrete failure events, is necessary but insufficient. Institutions that are serious about adaptive resilience are now stress testing against scenarios in which an adversary operates persistently below the threshold of detection, extracting value over weeks or months, never triggering an alert until the cumulative impact becomes visible.
Building these capabilities is technically achievable. It is also, for most institutions, organisationally difficult. It requires breaking down the boundary between security operations and operational resilience, integrating threat intelligence with regulatory compliance, and accepting that the static control framework that has defined the past decade is necessary but no longer sufficient.
Impact on Consumers, Businesses, Governments, and Markets
For retail consumers, the practical implication is that vigilance at the personal level matters more than it did three years ago, but it is also less effective in absolute terms. The phishing message you receive may be indistinguishable from a legitimate communication. The voice on the phone authorising a transfer may sound exactly like the person it claims to be. The bank's fraud monitoring will catch most attempts, but the attempts that succeed will succeed in ways that are harder to reverse. The most useful protective behaviours remain the basic ones: verify out of band before authorising any unusual transaction, treat any unexpected communication that creates urgency with suspicion, and review account activity more frequently than you did before.
For businesses with treasury operations, the exposure is different in character. Voice authorisation workflows are now materially compromised by synthesis technology. Wire transfer approval processes that depend on a single human verifier are no longer adequate. The institutions that have begun adapting are reintroducing structured callbacks, dual authorisation requirements, and out of band verification for any transaction above a defined threshold. These are reversions to older practices that the industry had moved away from in pursuit of efficiency.
For governments and regulators, the question is how quickly the supervisory framework can be adapted without creating new compliance burdens that impose cost without improving resilience. Several jurisdictions are moving toward outcome based supervision, in which institutions are assessed on demonstrated capability to detect and respond to adaptive threats rather than on the formal completeness of their control frameworks. This is the right direction, though the implementation is uneven.
For capital markets, the exposure is concentrated in two places. Custody operations, where the asset transfer mechanisms that handle institutional flows are attractive targets and have not, historically, been built with adaptive threat scenarios in mind. And settlement infrastructure, where the speed of modern payment systems means that the window between a fraudulent instruction and final settlement is narrow enough that detection often has to happen in real time or not at all.
Solutions and Strategic Responses
The strategic response that institutions are converging on has three components. First, investment in continuous monitoring infrastructure that can detect behavioural anomalies in near real time, replacing the threshold based detection that is increasingly being defeated. This is technical infrastructure, but it is also a substantial change in the cost base of the security function, and the business case requires acknowledging the increased severity of the threat being defended against.
Second, integration of threat intelligence with the operational resilience function, so that the institution can move from a model in which incidents are responded to after the fact to one in which the early signals of an emerging incident are surfaced to the resilience team while there is still time to act. This is largely an organisational change rather than a technical one, and it is where the institutions that adapt successfully will diverge from those that do not.
Third, scenario testing programmes that explicitly incorporate adaptive, sub-threshold, artificial intelligence enabled attack vectors. This requires building scenarios that the existing playbooks were not designed to address, and accepting that the result of those scenarios may be uncomfortable. The institutions that have begun running these scenarios are finding that their current impact tolerance settings would not have caught the cumulative loss before it occurred. This is information worth having.
For policymakers, the immediate question is whether to move toward more prescriptive guidance on artificial intelligence enabled threats, or to maintain the principles based approach that allows institutions to develop their own responses. There are arguments on both sides. The principles based approach permits faster adaptation, but it also permits institutions that are not adapting quickly to remain technically compliant. The prescriptive approach addresses that risk, but it freezes the response in a form that may itself become outdated as the threat continues to evolve.
The honest answer is that both will be required, in different proportions, in different jurisdictions, with the balance shifting as the threat landscape stabilises. What cannot continue is the assumption that the existing frameworks, written for a slower threat environment, are adequate to the one that has arrived.
Frequently Asked Questions
Question: What is an artificial intelligence enabled attack on a bank, in plain terms? It is an intrusion into a financial institution's systems carried out using artificial intelligence tools that handle reconnaissance, social engineering, and lateral movement faster and more convincingly than a human attacker could. The end goal is the same as any other intrusion, financial extraction or data theft, but the speed and sophistication are different.
Question: Why is multi-factor authentication no longer sufficient? Multi-factor authentication remains a useful control, but it is no longer a complete answer. Adversary in the middle proxies can capture one-time codes in real time, allowing the attacker to authenticate as the legitimate user. Stronger forms of authentication, including hardware security keys and passkeys, are more resistant, and institutions are migrating toward them.
Question: What is sub-threshold persistence and why does it matter? It is the practice of operating inside a target environment in ways that never trigger the institution's incident response thresholds. The attacker remains resident, extracts value, and removes the access pathway before the cumulative damage becomes visible. It defeats threshold based controls by remaining outside their field of view.
Question: What should retail banking customers actually do differently? Verify any unusual transaction request out of band before authorising it, treat any communication that creates urgency with suspicion regardless of how legitimate it appears, review account activity more frequently than monthly, and use stronger authentication methods such as hardware security keys or passkeys where the institution offers them.
Question: What is operational resilience and how is it different from cybersecurity? Operational resilience is a regulatory framework that requires financial institutions to identify their critical business services, set tolerances for acceptable disruption, and demonstrate the capability to remain within those tolerances under stress. Cybersecurity is one of several inputs to operational resilience, alongside third party risk, business continuity, and infrastructure reliability.
Question: How is this different from a ransomware attack? Ransomware is a discrete event with a clear start point, an obvious failure mode, and a defined recovery state. Adaptive artificial intelligence enabled intrusion is the opposite. It is continuous, it does not announce itself, and the recovery state is often that the institution discovers the breach long after the value has been extracted.
Question: What are regulators actually doing about this? Supervisory authorities in Europe, the United Kingdom, and the United States have begun referencing artificial intelligence enabled threats explicitly in their supervisory priorities for 2025 and 2026. Formal rule changes are slower, but the supervisory expectation is shifting faster than the underlying regulation, which means institutions are being assessed on capability rather than on formal compliance with rules that have not yet been updated.
Question: What is continuous intelligence and how is it different from current security monitoring? Current security monitoring is largely threshold based and rule based. It alerts when a defined condition is met. Continuous intelligence monitors for behavioural anomalies that may not, individually, cross any threshold, and recognises the cumulative pattern as itself a signal. The infrastructure to support this exists and is in production use, though it remains the exception rather than the standard.
Glossary
Adversary in the middle proxy. A technical capability that intercepts the connection between a user and a service, capturing authentication credentials and session tokens in real time, including one-time codes from authenticator applications.
Continuous intelligence. A monitoring approach that ingests behavioural metadata in real time and surfaces anomalous patterns before they cross threshold based detection rules.
Critical business service. Under operational resilience frameworks, a service whose disruption would cause material harm to consumers, the institution, or the wider financial system. Institutions are required to identify these services and set impact tolerances for them.
Deepfake voice fraud. The use of synthetic audio, generated from a small sample of a target's voice, to impersonate that person in fraudulent communication, typically to authorise transfers or extract sensitive information.
Digital Operational Resilience Act. The European Union regulation, in force since January 2025, that establishes a unified framework for the management of information and communication technology risk in financial institutions.
European Banking Authority. The European Union body responsible for prudential regulation of banks, which sets supervisory priorities and issues guidance on operational resilience and risk management.
Generative artificial intelligence. A category of artificial intelligence systems capable of producing text, audio, images, or other content that is contextually accurate and difficult to distinguish from human-produced material.
Impact tolerance. Under operational resilience frameworks, the maximum tolerable period of disruption to a critical business service before material harm occurs.
Lateral movement. The phase of an intrusion in which an attacker, having gained initial access, expands their presence across the target environment to reach systems of higher value.
Multi-factor authentication. An identity verification method that requires two or more independent forms of evidence, typically a password and a second factor such as a one-time code or biometric.
Phishing. A category of social engineering attack in which the target receives a fraudulent communication, typically by email, designed to induce them to disclose credentials or authorise an action that benefits the attacker.
Security information and event management. The class of technical platform that aggregates security log data from across an institution's environment and applies detection rules to surface incidents requiring response.
Social engineering. The use of psychological manipulation, rather than technical exploitation, to induce a target to take an action that compromises security.
Sub-threshold attack. An intrusion specifically designed to operate beneath the thresholds at which an institution's controls would generate an alert, thereby remaining undetected for an extended period.
Synthetic identity. An identity constructed from a combination of real and fabricated information, typically used to open accounts or establish credit relationships fraudulently.
Threshold based detection. A monitoring approach that generates alerts when a defined metric crosses a defined boundary. The dominant approach in current security operations, increasingly defeated by adversaries that operate below the threshold.
Torchlight Insight
The shift from human-speed to machine-speed intrusion is not a future risk. It is the current operating environment for every institution that holds deposits, processes payments, or maintains custody of financial assets. The frameworks that have governed operational resilience for the past decade are necessary but no longer sufficient, and the institutions that recognise this earliest will define what adequate defence looks like for the decade that follows. For consumers, the practical lesson is to treat the boundary between legitimate and fraudulent communication as more porous than it was, and to compensate with verification habits that do not depend on the surface plausibility of the message in front of you. For institutions, the lesson is structural, and the work to address it has already begun at the leading edge of the industry. The gap between leading and lagging on this question is widening, and it will be visible in the next significant incident.
