A bank discovers a serious vulnerability at 9:00am. The security team investigates, assesses which systems are exposed, contacts the relevant technology owners, tests a patch and begins the approval process. By then, an AI system could potentially have scanned the same infrastructure, identified the weakness, tested multiple attack paths and moved on to the next target. That difference in speed is becoming one of the most important questions in cybersecurity. OpenAI’s warning that an upcoming frontier model could potentially reach its highest cybersecurity capability threshold offers an early glimpse of what may be coming: a world where sophisticated cyberattacks are no longer constrained by how quickly a human attacker can work. For banks, the challenge may soon be less about whether AI can make cyberattacks more powerful and more about whether their defences can move fast enough to keep up.
The Cyber Threat Is Moving Beyond AI-Assisted Attacks
Banks are already familiar with AI-enabled cybercrime. Generative AI can make phishing messages more convincing, accelerate malware development, improve social engineering and help attackers automate reconnaissance.
But there is an important distinction between an attacker using AI and an AI system capable of completing significant parts of an attack itself.
OpenAI’s Preparedness Framework illustrates how significant that distinction could become. Its “Critical” cybersecurity threshold includes systems capable of identifying and developing functional zero-day exploits against hardened real-world systems without human intervention, or devising and executing sophisticated end-to-end attacks from relatively high-level objectives. OpenAI’s GPT-5.5 was classified as “High” rather than Critical, but the company has now raised concerns that its upcoming Astra model could cross that boundary, prompting additional safeguards and restrictions around its development.
That matters because cybersecurity changes dramatically when automation moves from assisting individual tasks to connecting them together.
An AI system capable of scanning infrastructure, identifying a vulnerability, testing possible attack paths, modifying its approach and continuing until it succeeds does not necessarily need to operate on the same timetable as a human attacker.
For banks, that could compress the time between vulnerability discovery and attempted exploitation from days or hours to minutes.
The Traditional Patch Cycle Could Become Too Slow
Most enterprise cybersecurity processes still contain significant human dependencies.
A vulnerability is identified. A security team assesses its severity. The affected systems are located. Business owners are consulted. A patch is tested. Change approvals are obtained. Deployment is scheduled.
Those controls exist for good reason. Banks cannot casually modify systems responsible for payments, customer accounts, trading, lending or regulatory reporting.
The problem is that attackers do not have to follow the same process.
The European Banking Authority warned in its June 2026 Risk Assessment Report that highly capable frontier AI models could represent a generational change in autonomous vulnerability exploitation. The EBA specifically highlighted the possibility that AI could identify and exploit large numbers of vulnerabilities, including previously unknown zero-day weaknesses, at speeds that make it increasingly difficult for defenders to respond through conventional patching processes.
That creates an uncomfortable asymmetry.
A bank might require several layers of approval before changing a production system. An autonomous attacker could potentially test thousands of possibilities while those approvals are still being discussed.
The vulnerability may therefore no longer be simply outdated software. The vulnerability could be the speed of the organisation itself.
Banking’s Technology Complexity Creates a Bigger Attack Surface
This becomes even more significant because modern banks are no longer contained within neatly defined technology environments.
Core platforms connect with cloud infrastructure, payment processors, identity systems, APIs, data platforms, cybersecurity vendors, software-as-a-service applications and hundreds of other external services.
As Finnoex previously explored in The Biggest Technology Risk Facing Banks Isn’t Legacy Systems. It’s Vendor Concentration, the increasing concentration of critical banking functions among technology providers means that cyber risk can extend far beyond infrastructure directly controlled by a bank.
The IMF has raised a similar concern. Its June 2026 analysis of AI and cybersecurity in financial services warned that artificial intelligence could increase the speed, frequency and breadth of vulnerability discovery while shared infrastructure and common technology providers could amplify the consequences across the financial system.
This is where machine-speed cyberattacks could become particularly dangerous.
An autonomous system does not need to understand a bank’s organisational chart. It can potentially look for the weakest accessible component across an interconnected digital ecosystem.
That weakness might sit inside the bank. It might sit inside an API. It might belong to a software supplier. It could be an overlooked cloud configuration or an old application that nobody considered important enough to modernise.
AI could make finding those weaknesses much cheaper.
Banks May Need Machines to Defend Against Machines
There is another side to this development, and it may ultimately be the more important one.
The same capabilities that make advanced AI potentially useful to attackers can make it extraordinarily valuable to defenders.
AI systems can continuously analyse software, identify vulnerabilities, examine security alerts, investigate suspicious activity and potentially recommend remediation far faster than traditional security teams.
This could become essential because many security operations centres already struggle with the volume of information they receive. The next generation of cybersecurity may therefore be less about replacing security professionals and more about giving them autonomous defensive systems capable of operating at comparable speed to the threats they face.
That transition has already begun. Research into AI-driven cybersecurity for financial services is exploring multi-agent architectures in which specialised AI agents work alongside conventional security platforms while retaining human oversight for critical decisions.
The strategic question for banks may eventually become straightforward: if attacks operate at machine speed, how much of defence can realistically remain dependent on human speed?
Autonomous Defence Creates Its Own Risk
Giving AI greater defensive authority is not a simple solution.
Consider an AI security agent that detects what it believes is an active compromise of a payment platform.
Should it automatically disconnect the system?
Should it block thousands of customer transactions?
Should it disable employee accounts?
Should it isolate a third-party connection?
Should it deploy a software change without waiting for approval?
The faster banks allow defensive AI systems to act, the greater their ability to contain machine-speed attacks. But greater autonomy also increases the consequences when an AI system makes the wrong decision.
This is similar to the governance questions banks are already encountering as AI agents enter mainstream operations. Finnoex examined these issues in 5 Questions Every Bank Should Ask Before Deploying AI Agents, particularly around permissions, accountability, human oversight and the boundaries within which autonomous systems should operate.
Cybersecurity raises the stakes considerably because waiting for human approval could allow an attack to spread, while acting incorrectly could disrupt critical banking services.
The solution is unlikely to be unrestricted autonomy. Banks will need clearly defined thresholds determining what defensive AI can investigate, what it can contain automatically and what still requires human authorisation.
Cyber Resilience Becomes More Important Than Perfect Prevention
There is also a broader lesson.
If AI dramatically lowers the cost of discovering vulnerabilities and conducting attacks, the assumption that every intrusion can be prevented becomes even harder to sustain.
Banks will still need strong perimeter security, identity controls, vulnerability management and threat detection. But architecture capable of limiting the impact of a successful compromise becomes equally important.
Segmentation, zero-trust access, rapid isolation, immutable backups, continuous monitoring and tested recovery processes become more valuable when attackers can move faster.
That reinforces an argument Finnoex previously made in Every Bank Will Be Hacked. The Winners Will Recover First. Cyber resilience increasingly depends not only on whether an attacker gets inside, but on how quickly the institution can identify the intrusion, contain it and restore normal operations.
AI could compress every part of that timeline.
Speed Is Becoming a Cybersecurity Capability
Banks have traditionally measured cybersecurity maturity through controls, technologies, compliance frameworks and investment levels. Increasingly, they may also need to measure something simpler: how quickly the institution can respond.
How quickly can a newly discovered vulnerability be identified across thousands of systems?
How quickly can affected infrastructure be isolated?
How quickly can defensive controls adapt to an unfamiliar attack?
And how many of those decisions can safely be automated?
These questions will become more important as frontier models continue improving.
The significance of OpenAI’s latest warning is therefore not that autonomous AI cyberattacks are suddenly inevitable. Nor does it mean human hackers are about to disappear. It signals that the technological capability required to automate increasingly sophisticated cyber operations is advancing rapidly enough that leading AI developers are preparing for it.
Banks should be doing the same.
The cybersecurity arms race has always been about finding vulnerabilities before the other side does. The difference is that the next participant in that race may never sleep, never become distracted and may be capable of testing possibilities at a scale no human security team could replicate.
When both attack and defence begin operating at machine speed, cybersecurity will no longer be determined only by who has the strongest controls.
It may be determined by who can respond first.
What it means for the industry
- Cybersecurity response speed will become a strategic capability. Banks may need to redesign processes that depend on lengthy human approvals when threats can evolve in minutes.
- AI-powered defence will become increasingly necessary. Security teams will need automation capable of detecting, investigating and containing threats at speeds closer to those of AI-enabled attackers.
- Legacy and third-party systems become more exposed. AI could dramatically reduce the time and cost required to discover vulnerabilities across complex banking ecosystems.
- Human oversight will have to become risk-based. Banks cannot approve every cyber response manually, but high-impact autonomous actions will still require strong governance.
- Resilience matters more than ever. Institutions able to isolate compromised systems and recover rapidly will be better positioned for an era of machine-speed attacks.

