Skip to main content
    Back to LUMINAIRE
    AI & Capital№ 000 / 2026

    Four Systemic Weak Points in Modern Banking

    Identity, third-party dependency, real-time payments, and detection latency. The four pressure points where AI-enabled threats most reliably break through.

    Four Systemic Weak Points in Modern Banking

    AI & Capital
    13 min read7 sourcesLIVE

    Click to generate an iQ-powered summary of this article

    The first vulnerability in modern banking is no longer technological. It is structural. The four pressure points described below are the ones where adversaries equipped with generative artificial intelligence consistently make progress, not because the controls protecting them are absent, but because they were designed for a slower, more bounded category of threat. Understanding the pressure points is the precondition for defending them.

    Identity is the contested perimeter

    For two decades, the security architecture of retail and corporate banking has been built around the proposition that a verified identity is a trustworthy identity. The credential establishes the right to access. The session token sustains it. The audit log preserves a record of who acted and when. This proposition is no longer reliable.

    Generative artificial intelligence has not broken authentication systems in the cryptographic sense. The mathematics are intact. What it has done is make the surrounding human and procedural layer porous in ways the cryptography cannot defend. Voice cloning convincing enough to satisfy a bank relationship manager is now achievable from a thirty-second public sample. Synthetic identity documents pass automated know-your-customer screening at materially higher rates than they did eighteen months ago. Adversary in the middle proxies, sold as a service, intercept legitimate authentication flows and replay session tokens before the user has finished logging in.

    The institutions that have begun adapting are those that have stopped treating authentication as a single moment and started treating identity as a continuously evaluated signal. Behavioural biometrics that score keystroke cadence, mouse movement, and device fingerprint against a baseline are no longer experimental. Hardware security keys and passkeys, which are resistant to proxy interception because the cryptographic challenge is bound to the legitimate domain, are migrating from privileged accounts to mass deployment. None of these controls is a complete answer. Each compresses the surface area available to an adaptive adversary.

    Third-party dependency is the unmonitored doorway

    Modern banking is not a self-contained system. It is a federation. A typical mid-sized institution depends on hundreds of third parties, ranging from cloud infrastructure providers and payment processors to customer relationship management platforms, document signing services, and specialist analytics vendors. Each dependency is a contractual relationship governed by service level agreements and increasingly by regulatory requirements. None of those instruments was designed to surface what matters most to a security team, which is the real-time security posture of the supplier's own environment.

    When an attacker compromises a software vendor whose product is installed inside a bank's environment, the bank's perimeter has been bypassed without the bank's perimeter ever being touched. The supply chain compromises of recent years have made this concrete. Each of them began at a vendor whose customers had no contemporaneous visibility into the breach.

    The Digital Operational Resilience Act in the European Union and the third-party risk management expectations of the Office of the Comptroller of the Currency in the United States are explicit attempts to address this asymmetry. They require institutions to maintain registers of critical third parties, to assess the concentration of risk among a small number of providers, and to test exit and substitution arrangements. The requirements are substantial. They are also, in their current form, point-in-time assessments overlaid on a system that is dynamic. The vendor judged secure last quarter may not be secure today.

    The institutions making the most progress are those investing in continuous third-party monitoring that ingests telemetry from supplier environments and surfaces anomalies in something close to real time. The technology is imperfect. The direction of travel is correct.

    Real-time payments outrun human review

    The category of risk that most directly affects retail customers is unauthorised real-time payments. Faster Payments in the United Kingdom, the Single Euro Payments Area instant scheme in the European Union, the FedNow service and The Clearing House's Real-Time Payments network in the United States, and equivalent rails elsewhere have collapsed transaction settlement from days to seconds. The convenience is genuine. The fraud surface that follows is also genuine.

    Authorised push payment fraud, in which a customer is socially engineered into authorising a transfer to an account controlled by an attacker, is the dominant fraud typology in jurisdictions with mature instant payments. The losses are substantial. The scheme operators and regulators have responded with reimbursement frameworks, sender warnings, confirmation of payee services, and pattern detection at the network level. These measures have moved the dial. They have not closed the gap.

    The reason the gap persists is that the fraud is not occurring in the payment system. It is occurring in the conversation that precedes the payment, and that conversation now arrives in the customer's communication channels with a level of contextual accuracy that is difficult for non-specialists to discount. The defensive response that produces the most consistent results is procedural rather than technological. Out of band verification, in which any unusual instruction is confirmed via a channel separate from the one that received the request, remains the highest-leverage habit a household or treasury function can install.

    Detection latency is structural

    The fourth pressure point is the most consequential and the least visible. It is the time elapsed between an adversary's first action inside an institution's environment and the institution's recognition that an action has occurred. This interval, in most security operations centres, is measured in days. In some it is measured in weeks. For an attacker operating with generative artificial intelligence and a clear objective, this is more than enough time to complete the engagement.

    Detection latency is not a sign of negligence. It is a structural property of detection systems built around thresholds. The premise of threshold-based detection is that anomalous activity will produce a signal large enough to cross a defined trigger, at which point an alert is generated and an analyst investigates. Adversaries who operate continuously below those thresholds, often by design, do not produce signals that the system was built to recognise.

    The migration that is now underway is from threshold-based detection to behavioural analytics that score deviations from a baseline rather than absolute values. The premise is that an account exhibiting a small number of unusual behaviours simultaneously is more interesting than the same account exhibiting any one of them in isolation. The technology is not new. The deployment at scale, integrated with the regulatory obligations that govern incident reporting and customer notification, is.

    What the four points have in common

    The four pressure points share a structural property. Each is the boundary at which a static control encounters an adaptive adversary. Identity is a static credential evaluated against a dynamic threat. Third-party risk is a contractual posture evaluated against an operational reality. Real-time payment authorisation is a single decision evaluated against a conversation that has been engineered over weeks. Detection thresholds are fixed values evaluated against adversaries who have studied the threshold and chosen to operate beneath it.

    The institutions that are making the most progress in each area share a corresponding property. They are replacing static evaluations with continuous ones, point-in-time controls with monitoring that runs in something close to real time, and regulatory mappings that are produced annually with mappings that are updated as the operating environment changes. None of these institutions claims to have solved the problem. Each has reduced the asymmetry.

    What this means for the institutions that have not begun

    For the institutions that have not begun, the practical implication is that the controls inherited from the previous generation of cyber risk management, however well-implemented, are no longer sufficient on their own. The next twelve to twenty-four months are the window in which the gap between adaptive adversaries and static defences is most likely to be exploited materially. The supervisory expectations from the European Banking Authority, the Prudential Regulation Authority, the Federal Reserve, the Office of the Comptroller of the Currency, and the Financial Stability Board have begun to catch up. The expectations are explicit. The clock is running.

    The next instalment in this series examines the third structural mismatch, which is the encounter between annual penetration testing, threshold-based detection, and adversaries engineered to operate continuously beneath both.

    #banking#cyber#operational-resilience#ai-risk#fraud

    Sources & References

    LUMINAIRE verifies all sources for accuracy and relevance.Read our editorial standards.

    Editorial Q&A

    Frequently Asked Questions

    8 questions answered by the LUMINAIRE editorial desk.

    Didn't find your answer?

    Ask LUMINAIRE iQ a follow-up question grounded in this article.

    Glossary

    Key Terms & Definitions

    16 terms defined for this briefing.

    A
    Adaptive adversary
    An attacker whose tools, techniques, and procedures evolve in response to defensive controls, often using automated systems to adjust attack parameters between attempts.
    Adversary in the middle proxy
    An intercepting infrastructure that sits between the user and the legitimate service, capturing credentials and session tokens in real time including one-time authentication codes.
    Authorised push payment fraud
    Fraud in which the legitimate account holder is socially engineered into authorising a payment to an account controlled by the attacker, leaving the sending institution with limited recovery options.
    B
    Behavioural analytics
    Detection methodology that scores deviations from a learned baseline of normal activity, surfacing combinations of small anomalies rather than relying on single threshold breaches.
    C
    Confirmation of payee
    A pre-payment check that verifies the name on the destination account matches the name supplied by the sender, designed to interrupt mis-direction before settlement.
    Critical third party
    Under DORA and equivalent regimes, a service provider whose disruption would cause material harm to the institution or to financial stability, attracting heightened oversight.
    D
    Detection latency
    The interval between an adversary's first action inside an environment and the institution's recognition of that action, typically measured in hours, days, or weeks.
    F
    Federated identity
    An authentication architecture in which identity is established once with a trusted provider and asserted to multiple downstream services, common in modern enterprise environments.
    H
    Hardware security key
    A physical device that performs a domain-bound cryptographic challenge during authentication, resistant to interception by adversary in the middle proxies.
    I
    Instant payments
    Payment rails that settle in seconds with finality, including FedNow, Real-Time Payments, Faster Payments, and SEPA Instant.
    O
    Out of band verification
    Confirming an instruction via a communication channel separate from the one in which the instruction was received, the principal procedural defence against social engineering.
    P
    Passkey
    A standards-based credential built on public-key cryptography that is bound to the legitimate domain and resistant to phishing-style interception.
    R
    Real-time payments
    Payment systems that authorise, clear, and settle individual transactions in seconds, twenty-four hours a day, with finality at settlement.
    S
    Sub-threshold persistence
    Adversary technique of maintaining presence in an environment without producing activity large enough to trigger threshold-based detection rules.
    Synthetic identity
    A fabricated identity composed of real and invented attributes, often constructed to pass automated screening while having no real-world counterpart.
    T
    Third-party concentration risk
    The systemic exposure that arises when many institutions depend on the same small set of suppliers, such that a single supplier failure can produce sector-wide disruption.

    This article was researched and written by human editors with analytical assistance from AI tools. All conclusions are independently reviewed.

    The Byline

    LUMINAIRE Editorial

    The LUMINAIRE Editorial Team brings together analysts, technologists, and subject matter experts to chronicle humanity's transformation in the age of artificial intelligence.

    Report an issue with this article