The first vulnerability in modern banking is no longer technological. It is structural. The four pressure points described below are the ones where adversaries equipped with generative artificial intelligence consistently make progress, not because the controls protecting them are absent, but because they were designed for a slower, more bounded category of threat. Understanding the pressure points is the precondition for defending them.
Identity is the contested perimeter
For two decades, the security architecture of retail and corporate banking has been built around the proposition that a verified identity is a trustworthy identity. The credential establishes the right to access. The session token sustains it. The audit log preserves a record of who acted and when. This proposition is no longer reliable.
Generative artificial intelligence has not broken authentication systems in the cryptographic sense. The mathematics are intact. What it has done is make the surrounding human and procedural layer porous in ways the cryptography cannot defend. Voice cloning convincing enough to satisfy a bank relationship manager is now achievable from a thirty-second public sample. Synthetic identity documents pass automated know-your-customer screening at materially higher rates than they did eighteen months ago. Adversary in the middle proxies, sold as a service, intercept legitimate authentication flows and replay session tokens before the user has finished logging in.
The institutions that have begun adapting are those that have stopped treating authentication as a single moment and started treating identity as a continuously evaluated signal. Behavioural biometrics that score keystroke cadence, mouse movement, and device fingerprint against a baseline are no longer experimental. Hardware security keys and passkeys, which are resistant to proxy interception because the cryptographic challenge is bound to the legitimate domain, are migrating from privileged accounts to mass deployment. None of these controls is a complete answer. Each compresses the surface area available to an adaptive adversary.
Third-party dependency is the unmonitored doorway
Modern banking is not a self-contained system. It is a federation. A typical mid-sized institution depends on hundreds of third parties, ranging from cloud infrastructure providers and payment processors to customer relationship management platforms, document signing services, and specialist analytics vendors. Each dependency is a contractual relationship governed by service level agreements and increasingly by regulatory requirements. None of those instruments was designed to surface what matters most to a security team, which is the real-time security posture of the supplier's own environment.
When an attacker compromises a software vendor whose product is installed inside a bank's environment, the bank's perimeter has been bypassed without the bank's perimeter ever being touched. The supply chain compromises of recent years have made this concrete. Each of them began at a vendor whose customers had no contemporaneous visibility into the breach.
The Digital Operational Resilience Act in the European Union and the third-party risk management expectations of the Office of the Comptroller of the Currency in the United States are explicit attempts to address this asymmetry. They require institutions to maintain registers of critical third parties, to assess the concentration of risk among a small number of providers, and to test exit and substitution arrangements. The requirements are substantial. They are also, in their current form, point-in-time assessments overlaid on a system that is dynamic. The vendor judged secure last quarter may not be secure today.
The institutions making the most progress are those investing in continuous third-party monitoring that ingests telemetry from supplier environments and surfaces anomalies in something close to real time. The technology is imperfect. The direction of travel is correct.
Real-time payments outrun human review
The category of risk that most directly affects retail customers is unauthorised real-time payments. Faster Payments in the United Kingdom, the Single Euro Payments Area instant scheme in the European Union, the FedNow service and The Clearing House's Real-Time Payments network in the United States, and equivalent rails elsewhere have collapsed transaction settlement from days to seconds. The convenience is genuine. The fraud surface that follows is also genuine.
Authorised push payment fraud, in which a customer is socially engineered into authorising a transfer to an account controlled by an attacker, is the dominant fraud typology in jurisdictions with mature instant payments. The losses are substantial. The scheme operators and regulators have responded with reimbursement frameworks, sender warnings, confirmation of payee services, and pattern detection at the network level. These measures have moved the dial. They have not closed the gap.
The reason the gap persists is that the fraud is not occurring in the payment system. It is occurring in the conversation that precedes the payment, and that conversation now arrives in the customer's communication channels with a level of contextual accuracy that is difficult for non-specialists to discount. The defensive response that produces the most consistent results is procedural rather than technological. Out of band verification, in which any unusual instruction is confirmed via a channel separate from the one that received the request, remains the highest-leverage habit a household or treasury function can install.
Detection latency is structural
The fourth pressure point is the most consequential and the least visible. It is the time elapsed between an adversary's first action inside an institution's environment and the institution's recognition that an action has occurred. This interval, in most security operations centres, is measured in days. In some it is measured in weeks. For an attacker operating with generative artificial intelligence and a clear objective, this is more than enough time to complete the engagement.
Detection latency is not a sign of negligence. It is a structural property of detection systems built around thresholds. The premise of threshold-based detection is that anomalous activity will produce a signal large enough to cross a defined trigger, at which point an alert is generated and an analyst investigates. Adversaries who operate continuously below those thresholds, often by design, do not produce signals that the system was built to recognise.
The migration that is now underway is from threshold-based detection to behavioural analytics that score deviations from a baseline rather than absolute values. The premise is that an account exhibiting a small number of unusual behaviours simultaneously is more interesting than the same account exhibiting any one of them in isolation. The technology is not new. The deployment at scale, integrated with the regulatory obligations that govern incident reporting and customer notification, is.
What the four points have in common
The four pressure points share a structural property. Each is the boundary at which a static control encounters an adaptive adversary. Identity is a static credential evaluated against a dynamic threat. Third-party risk is a contractual posture evaluated against an operational reality. Real-time payment authorisation is a single decision evaluated against a conversation that has been engineered over weeks. Detection thresholds are fixed values evaluated against adversaries who have studied the threshold and chosen to operate beneath it.
The institutions that are making the most progress in each area share a corresponding property. They are replacing static evaluations with continuous ones, point-in-time controls with monitoring that runs in something close to real time, and regulatory mappings that are produced annually with mappings that are updated as the operating environment changes. None of these institutions claims to have solved the problem. Each has reduced the asymmetry.
What this means for the institutions that have not begun
For the institutions that have not begun, the practical implication is that the controls inherited from the previous generation of cyber risk management, however well-implemented, are no longer sufficient on their own. The next twelve to twenty-four months are the window in which the gap between adaptive adversaries and static defences is most likely to be exploited materially. The supervisory expectations from the European Banking Authority, the Prudential Regulation Authority, the Federal Reserve, the Office of the Comptroller of the Currency, and the Financial Stability Board have begun to catch up. The expectations are explicit. The clock is running.
The next instalment in this series examines the third structural mismatch, which is the encounter between annual penetration testing, threshold-based detection, and adversaries engineered to operate continuously beneath both.
