Banks Warned on AI-Linked Cyber Risks
A high-level meeting chaired by Union Finance Minister Nirmala Sitharaman and Electronics and Information Technology Minister Ashwini Vaishnaw with scheduled commercial banks focused on emerging artificial intelligence-linked threats to the banking sector.
The meeting examined the potential misuse of recent AI developments to weaponise software vulnerabilities, with the Finance Minister describing the emerging threat as unprecedented and calling for a high degree of vigilance and preparedness.
Banks were advised to strengthen their cybersecurity and monitoring capabilities by engaging specialised cybersecurity professionals and agencies. The focus is on ensuring that banks can identify and respond to emerging threats as AI capabilities develop.
A key concern is that AI can potentially make cyberattacks more sophisticated and efficient. The ability to analyse systems, identify vulnerabilities and automate certain activities could increase the speed at which attackers exploit weaknesses.
For banks, this creates a significant technology and operational risk because financial institutions operate highly interconnected systems handling customer information, payment infrastructure and monetary assets.
The Finance Minister advised banks to take pre-emptive measures to protect their information-technology systems, customer data and financial resources. Banks were also asked to report suspicious activities and cyber incidents promptly to relevant authorities, including the Indian Computer Emergency Response Team (CERT-In).
The meeting also emphasised the importance of real-time threat intelligence sharing. A coordinated mechanism involving banks, CERT-In and other relevant agencies was proposed so that information about emerging threats can be identified and disseminated across the banking ecosystem without delay.
This approach is particularly relevant because a vulnerability discovered in one institution can potentially have implications for other financial organisations using similar technologies, software or infrastructure.
The development also highlights the need to move beyond conventional cybersecurity practices. Banks may need continuous vulnerability assessment, threat intelligence, red-team testing, incident-response exercises and stronger monitoring of technology dependencies.
AI-related risks also extend beyond direct cyberattacks. Banks using artificial intelligence internally need to consider model risk, data security, privacy, explainability and appropriate human oversight.
For risk-management functions, AI therefore needs to be treated as both a risk-management tool and a potential source of new risk.
The emphasis on coordination is particularly important. Individual banks can strengthen their own defences, but ecosystem-wide threat intelligence can help institutions respond faster when new vulnerabilities or attack methods emerge.
The meeting reinforces the importance of integrating cybersecurity, technology risk, operational resilience and AI governance within the broader banking risk-management framework.
As artificial intelligence capabilities continue to develop, banks will need to strengthen both preventive controls and response mechanisms. The focus is increasingly shifting towards continuous monitoring, faster intelligence sharing and preparedness for threats that may evolve faster than conventional security processes.
