Artificial Intelligence (AI)-enabled cyberattacks have emerged as the leading perceived cybersecurity risk over the next year, according to the RBI’s recent Financial Stability Report. Agentic models like Claude’s Mythos series can autonomously expose vulnerabilities in a financial institution’s infrastructure that might otherwise go undiscovered. These models reduce the time and skill required by an attacker, thereby making cyberattacks more scalable and potent.

The potential for misuse has already led to access restrictions through US government directives and deliberate restrictions by frontier AI providers. It is reasonable to speculate that such restrictions are temporary, with many restrictions already rescinded and models being launched in the public domain. It is only a matter of time before many more actors, including bad actors, gain access to such capabilities.

In this context, this piece examines how AI is reshaping the cyber risk landscape in the banking sector.