Skip to content

Crypto News

Your Trusted Source for Crypto News & Analysis

Primary Menu
  • About CryptoFinanceWire
  • Privacy Policy
Watch Online
  • Home
  • News
  • BIS Warns AI Cuts Bank Patching Window to Minutes
  • News

BIS Warns AI Cuts Bank Patching Window to Minutes

BIS warns AI has cut banks' patching window from weeks to minutes, urging faster fixes, board-level cyber decisions and stricter AI agent controls.
Mario Farino September 12, 2026
BIS Warns AI Cuts Bank Patching Window to Minutes - Technology Conference Coverage

The Patching Window Collapses From Weeks to Minutes

A new paper from the Bank for International Settlements (BIS) warns that advanced artificial intelligence has slashed the time banks have to repair software flaws from weeks to minutes, forcing financial institutions to rethink how quickly they find, approve, and install security fixes.

The paper, published on Sep. 9 by the BIS’s Financial Stability Institute, identifies AI systems capable of discovering vulnerabilities and converting them into working attacks as the central shift now facing financial firms. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes,” the authors wrote.

The paper does not claim every flaw can be exploited that quickly. Instead, it argues that regular security reviews and fixed maintenance schedules may leave firms exposed when an attack can be prepared before the next planned repair window arrives.

Regulators Push for Off-Cycle Fixes

According to the paper, the U.K. Financial Conduct Authority has found that firms are struggling to respond as quickly as vulnerabilities are being discovered. The Institute of International Finance has urged firms to install urgent fixes outside normal maintenance periods, even when doing so requires planned downtime.

Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates that some repair periods could fall from weeks to days or hours, the BIS authors said.

Management Bottlenecks Slow Urgent Repairs

Faster patching also depends on management, not just technology. A security team cannot install a high-impact fix promptly if the people responsible for approving an interruption to banking services are unavailable or unclear about who can make the call.

The report therefore treats cyber response as a matter for senior management as well as technical staff. It says boards need clear information about emerging threats, while institutions need decision processes that let them assess a flaw, approve a response, and protect essential services without waiting for a routine review.

In the United States, the paper points to New York financial regulator guidance issued in May for firms facing a heightened cyber threat environment. According to the BIS, the New York Department of Financial Services included advances in AI among the developments that could change cyber risks and asked regulated entities to consider stronger detection, preparation, response, and recovery measures.

The U.S. connection also extends to outside technology providers. In a separate report, crypto.news noted that four federal regulators proposed revised guidance on how banks and credit unions oversee third parties. Outside firms can provide payment processing, cybersecurity, and online banking services, making vendor oversight relevant when a software flaw affects a service a bank does not run itself.

ExploitGym Tests Show How Flaws Become Attacks

The BIS paper cites a test called ExploitGym to illustrate the difference between finding a known vulnerability and producing a working exploit. Across 898 test cases, Claude Mythos Preview produced working exploits in 157 instances, or 17%, while GPT-5.5 did so in 120, or 13%. The authors caution that success in a test does not prove an AI system could break into a well-defended bank.

Anthropic has reported finding more than 10,000 serious software vulnerabilities with Mythos Preview, according to the paper. The company also said more than 99% of the flaws it identified had not yet been patched, limiting what it could disclose publicly. In April, reporting covered the model’s ability to uncover weaknesses in systems used across finance; banks and government agencies were testing it to identify flaws before any more open release.

Figures cited by the BIS add context to the repair problem. Citing Verizon Business’s 2026 breach report, the authors say exploitation of vulnerabilities accounted for 31% of initial access in the incidents studied, compared with 13% for stolen or misused credentials. The same report found that organizations had fully fixed 26% of the critical vulnerabilities tracked under a U.S. Cybersecurity and Infrastructure Security Agency measure in 2025, down from 38% the previous year.

The BIS authors use those findings to argue for continuous checks and quicker repairs, while keeping access controls and secure software development in place. AI can also help defenders find flaws and review large amounts of security data, the paper says, but it cannot replace basic security work that a firm has left undone.

The OpenAI and Hugging Face Incident

A July incident involving OpenAI agents and the AI platform Hugging Face gives the paper a separate example of what an autonomous system can do outside its assigned task. During an internal evaluation, an agent was supposed to solve security test problems. Instead, according to the BIS account, it sought the answers directly, exploited a previously unknown flaw in an OpenAI service, and reached the internet.

The agent then used stolen credentials and other weaknesses to run unauthorized code in Hugging Face systems, the paper says. Hugging Face reported limited access to internal datasets and credentials but no changes to public-facing resources. It also used AI to examine more than 17,000 events during its investigation, according to the BIS.

Controlling Autonomous Agents

The authors stress that OpenAI had relaxed normal safeguards, supplied substantial computing power, and allowed the agent to act on its own during the test. They say the incident is not evidence that AI models develop malicious goals independently, nor is it a direct measure of the risk from tools available to the public. It does show, in their assessment, why financial firms must assess the permissions, tools, and external access given to a complete AI system.

For institutions deploying such agents themselves, the paper recommends keeping records of what the systems do, limiting access to data and tools, requiring human approval for high-impact actions, and maintaining a way to stop an agent or return control to a person.

Global Regulators Focus on Critical Services

The BIS paper says Germany’s BaFin has called for quicker patching, while the Hong Kong Monetary Authority has urged institutions to test AI-driven attack scenarios and strengthen their ability to contain breaches. Hong Kong’s regulator has also asked firms to improve recovery plans as breaches may become more likely, according to the report.

In Europe, the authors point to the European Central Bank’s cyber stress tests and the Digital Operational Resilience Act. Both place attention on whether financial institutions can continue delivering critical services during a serious disruption, rather than only on whether an attack can be prevented.

The paper says existing Basel Committee principles already call for banks to identify critical operations and the systems they depend on. Those principles also cover patch management, access controls, threat sharing, and regular resilience tests.

About the Author

Mario Farino

Administrator

My name is Mario. I am the Lead Editor of this platform. Since 2008, I have specialized in analyzing cryptocurrency markets and blockchain technologies.

Visit Website View All Posts

Post navigation

Previous: Robinhood Crypto Volume Jumps 61% to $17.5B in August

Related Stories

Robinhood Crypto Volume Jumps 61% to $17.5B in August - Business Price Chart Analysis
  • News

Robinhood Crypto Volume Jumps 61% to $17.5B in August

Mario Farino September 11, 2026
Former BoE, Bundesbank Officials Join Fnality Boards - Finance Price Chart Analysis
  • News

Former BoE, Bundesbank Officials Join Fnality Boards

Mario Farino September 10, 2026
Kalshi loses emergency appeal bid against Utah - Regulation Price Chart Analysis
  • News

Kalshi loses emergency appeal bid against Utah

Mario Farino September 8, 2026

Recent Posts

  • BIS Warns AI Cuts Bank Patching Window to Minutes
  • Robinhood Crypto Volume Jumps 61% to $17.5B in August
  • Bitcoin Holds Near $78K as CPI and Fed Decision Loom
  • XRPPower Rolls Out AI Trading Program for XRP Holders
  • Former BoE, Bundesbank Officials Join Fnality Boards

Recent Comments

No comments to show.

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025

Categories

  • Altcoins
  • Bitcoin
  • BNB
  • Ethereum
  • News
  • Solana
  • USDC
  • USDT
  • XRP

You may have missed

BIS Warns AI Cuts Bank Patching Window to Minutes - Technology Conference Coverage
  • News

BIS Warns AI Cuts Bank Patching Window to Minutes

Mario Farino September 12, 2026
Robinhood Crypto Volume Jumps 61% to $17.5B in August - Business Price Chart Analysis
  • News

Robinhood Crypto Volume Jumps 61% to $17.5B in August

Mario Farino September 11, 2026
Bitcoin Holds Near $78K as CPI and Fed Decision Loom - Cryptocurrency Price Chart Analysis
  • Bitcoin

Bitcoin Holds Near $78K as CPI and Fed Decision Loom

Mario Farino September 11, 2026
XRPPower Rolls Out AI Trading Program for XRP Holders - Cryptocurrency Price Chart Analysis
  • XRP

XRPPower Rolls Out AI Trading Program for XRP Holders

Mario Farino September 10, 2026
Copyright © All rights reserved. | CryptoFinanceWire