BIS Warns Frontier AI Is Giving Cyber Attackers a Cheaper Way In
Key Takeaways
- AI Lowers the Cost of Sophisticated Cyberattacks: The BIS warns that frontier AI models such as Anthropic's Mythos and OpenAI's GPT-5.5 can identify vulnerabilities, develop exploits and execute complex attack chains, reducing the expertise and cost required to launch advanced cyberattacks.
- Cyber Defense Still Faces an Uneven Fight: While financial institutions can use the same AI models to discover and remediate vulnerabilities, defenders must secure every potential entry point while attackers need exploit only one, leaving the economics tilted toward offense.
- Financial Stability Risks Extend Beyond Individual Firms: Banks, payment systems and financial market infrastructure rely on interconnected software, cloud services and third-party providers, meaning vulnerabilities in shared technology could create systemic consequences rather than isolated incidents.
- Evidence Suggests the Cyber Arms Race Is Accelerating: The BIS points to stronger AI performance on cybersecurity benchmarks, a sharp increase in security bug fixes and a rising number of critical software vulnerabilities as signs that both attackers and defenders are rapidly adopting frontier AI capabilities.
- International Coordination Will Be Essential: The BIS calls for regulators, financial institutions and governments to expand information sharing, accelerate vulnerability remediation, strengthen third-party risk oversight and adapt resilience frameworks to address AI-enabled cyber threats.
Deep Dive
Anthropic’s Mythos did not merely find a weakness in a computer network. In testing, it followed the weakness through. The frontier artificial intelligence model identified vulnerabilities, developed exploits and carried an attack across multiple stages, adjusting its approach with limited human oversight. In some attempts, it completed a full network takeover. OpenAI’s GPT-5.5, released weeks later, showed similar capabilities and performed slightly better on a benchmark of expert-level cybersecurity tasks.
For the Bank for International Settlements, this is the point at which a promising technical advance begins to look like a financial stability problem. A new BIS bulletin warns that the latest AI models are increasing the speed, scale and complexity of cyberattacks while lowering the expertise and money needed to carry them out. Those same models can help banks and other institutions find and repair vulnerabilities. The trouble is that cyber defense has never been a fair contest. A bank must protect every viable entrance. An attacker needs only one door left open.
That imbalance sits at the center of what the BIS calls a possible “Mythos moment,” a technological wake-up call for banks, payment systems and the sprawling financial infrastructure beneath them. These systems are built on layers of proprietary software, open-source code, cloud services and third-party suppliers. A flaw in one layer may not remain there for long.
The report does not argue that an AI model can bring down the financial system by itself. Its concern is more prosaic and, for that reason, harder to dismiss. AI is making sophisticated cyber work cheaper, faster and easier to repeat. In a system held together by software dependencies that few institutions fully understand, repetition is its own form of power.
The Attack Chain Gets Cheaper
The UK government’s AI Security Institute tested models against 95 cyber tasks divided into four levels of difficulty. The exercises required a model to find and exploit deliberately planted vulnerabilities. Mythos passed 68.6% of the expert-level tasks, the highest score recorded at the time. GPT-5.5 followed with a 71.4% pass rate. In a longer simulation built around a 32-step attack on a corporate network, both models managed a full takeover in some attempts.
Cyber offense lends itself unusually well to these systems. A network attack is not an open-ended conversation or a vague strategic exercise. It is a sequence. Each step produces logs, error messages, credentials, snippets of code and other machine-readable evidence. The model tries something, receives a response and uses that response to decide what comes next.
The important advance is not that a model can spot a single vulnerability. Security tools have done versions of that for years. It is that a model can connect vulnerabilities, adapt to the target and continue through an attack without waiting for a person to direct each move.
The cost is already within reach of more than nation-states and elite criminal groups. The BIS estimates that a complete attack chain using Claude Mythos Preview would consume about 100 million tokens and cost roughly $5,000 to $10,000 at current cloud prices. Comparable attacks using several other frontier models could cost around one-fifth as much. Cheaper models could reduce the price to between $50 and $100.
At those prices, the question is no longer whether advanced cyber capabilities will spread. It is how far, and how quickly. The falling cost does not turn every petty criminal into a skilled operator. Models still require access, computing capacity, useful targets and some understanding of what they are being asked to do. But they can place work once reserved for specialists within reach of less capable actors, including ransomware groups, industrial spies and individuals motivated by money, notoriety or ideology.
The BIS notes that state-backed attackers and organized criminal groups already operate alongside a mature market for stolen credentials, undisclosed software flaws and ready-made hacking tools. Frontier AI enters that market as an accelerant, not as a replacement.
Defense Has to Be Right Every Time
Banks and cybersecurity teams have access to the same technology. They can use AI to review code, scan networks, identify weaknesses and shorten the time between discovery and repair. There are signs that this is already happening. Monthly security fixes for Firefox increased sixfold after Mythos Preview was announced. The number of critical software vulnerabilities being cataloged has also risen sharply. From 2018 through 2021, roughly seven critical vulnerabilities were reported each day. The average rose to 10 a day from 2022 through 2025, then climbed to nearly 20 a day after April 1, 2026.
Those figures require some restraint. A rise in reported vulnerabilities may mean that AI is finding more flaws. It may also reflect a larger software industry, more security researchers and better reporting. The data show that discovery is accelerating. They do not neatly explain why.
What the numbers do suggest is that the defensive race has begun. Vulnerabilities that might once have remained buried in old code can now be found in volume. That is useful when the person finding them is responsible for fixing them. It is rather less comforting when the same search is being run by someone looking for a way inside.
The economics favor the latter. Defenders must continuously protect legacy systems, public-facing assets, open-source components, cloud environments and third-party connections. Attackers can move on from nine failed routes if the 10th one works.
AI may help both sides. It does not follow that both sides benefit equally. Defensive use may also prove more expensive. Financial institutions must run monitoring and detection systems continuously, process a growing volume of alerts and keep enough computing capacity available to respond quickly. An attacker can concentrate resources on one campaign and one target. A bank must be ready for all of them.
Reported data breaches have continued to rise, and the BIS found that a growing share involve automation rather than direct human action. The data do not identify which models were used, and attackers are not known for their voluntary disclosures. Still, the direction is difficult to mistake. Automation is moving deeper into the mechanics of intrusion.
Investors appear to have noticed. Cybersecurity stocks recorded sharp negative abnormal returns after Mythos was announced, according to the BIS analysis. The market reaction was widely interpreted as concern that existing security products could be made obsolete by more capable AI systems.
That interpretation may prove too severe. Companies may buy more security products as threats grow, or they may use AI to strengthen internal defenses and rely less on outside vendors. The reaction matters because it shows how quickly assumptions about the cybersecurity market can change when a model demonstrates that it can do more than assist a human analyst.
The Financial System’s Shared Weaknesses
The danger becomes systemic when many institutions depend on the same code, cloud provider or technology supplier. A vulnerability inside one bank is a problem for that bank. A vulnerability embedded in widely used software can become a route into dozens or hundreds of institutions. The private reward for discovering and disclosing such a flaw may be modest compared with the damage prevented across the financial system. Firms may therefore spend less on discovery and remediation than the system as a whole requires.
The BIS sees that gap as a case for coordinated scanning, faster information sharing and closer cooperation among financial institutions, central banks, supervisors, national security agencies and technology providers.
The first priority is speed. Defenders need access to capable models early enough to find weaknesses before attackers do. Banks also need to address the less glamorous parts of cybersecurity that become more consequential when attacks accelerate, including legacy systems, unpatched software, exposed internet assets and poorly understood third-party dependencies.
Exercises will have to change as well. A simulation in which an institution assumes days or weeks between stages of an attack may say little about a model capable of compressing the same work into hours. Tests should include compromised suppliers, AI-enabled attack paths and failures that move quickly across connected institutions.
International coordination will be harder. Countries do not share threat intelligence freely when national security, espionage and strategic competition are involved. Yet payment, trading and post-trade systems do not respect those political boundaries. An attack moving through a global supplier can reach institutions in several jurisdictions before authorities have agreed on which secure channel to use.
The BIS argues that regulators can build on existing frameworks from the Financial Stability Board, the Basel Committee and CPMI-IOSCO rather than create an entirely new architecture. Those frameworks can be adapted to include AI-driven attack scenarios, faster incident timelines and stronger oversight of supply chains.
Operators of systemically important infrastructure could also participate in pretesting new models, allowing authorities and institutions to study their capabilities before those capabilities become broadly available. Shared assessments and voluntary pilot programs would give smaller jurisdictions access to findings they might not have the resources to produce themselves.
None of this eliminates the advantage held by an attacker who needs one success. It may keep that advantage from becoming decisive. Payment systems and market infrastructure operate at a scale where even a temporary disruption can travel outward through banks, businesses and households. Their software is complex, their supply chains are crowded and failures can be difficult to detect before they are equally difficult to reverse.
The technology is moving faster than the institutions built to oversee it. For the BIS, the answer is not to wait for a spectacular failure to settle the argument. Banks and authorities need to use these models now, against their own code and their own assumptions, before someone else does it for them.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

