Artificial intelligence is reshaping the financial sector at an unprecedented pace. Banks across Europe are investing heavily in AI to improve fraud detection, automate operations and support faster decision-making. What was once considered an emerging technology is rapidly becoming part of day-to-day banking.
However, AI is transforming more than the way banks operate. It is also reshaping cybersecurity. The same advances in artificial intelligence that are strengthening cyber defence are also lowering the barriers to sophisticated cyberattacks, giving criminals new ways to operate at a speed and scale that was previously difficult to achieve.
As AI strengthens both attackers and defenders, banks are rethinking how they approach cyber risk. De Nederlandsche Bank (DNB) recently warned that cyber and operational risks are among the biggest threats to financial stability, while the World Economic Forum found that 87% of organisations identified AI-related vulnerabilities as the fastest-growing cyber risk. At the same time, 77% already use AI within their cybersecurity operations, highlighting that this has become an AI-driven race on both sides.
For financial institutions, the question is no longer whether to adopt AI. It is whether they can build the technology, governance and specialist capability needed to keep pace with a threat landscape that is evolving at machine speed.
When AI Changes the Economics of Cybercrime
Cyber threats are nothing new to financial services. Banks have long invested in cybersecurity to defend against phishing, malware, identity fraud and sophisticated attacks. What AI changes is not the objective of cybercriminals, but how quickly and efficiently those attacks can be carried out.
Rather than introducing entirely new forms of cybercrime, AI is lowering the barriers to sophisticated attacks. Tasks that once required significant expertise and time, such as generating convincing phishing emails, identifying software vulnerabilities and conducting reconnaissance, can now be completed faster and at a much greater scale.
The European Central Bank (ECB) has described frontier AI as creating a structural shift in the economics of cyber risk, reducing the expertise and time needed to conduct sophisticated attacks while increasing the number of actors capable of carrying them out. Dutch banks are already recognising this shift. In April 2026, ABN AMRO warned that AI enables attackers to automate malicious coding, generate convincing communications, identify vulnerabilities and scan organisations at scale, making cyberattacks faster, smarter and cheaper.
The impact is already visible across the sector. Between March and November 2025, criminals used manipulated identity information and deepfake biometric images to bypass ABN AMRO’s identity verification process, resulting in 47 fraudulent bank accounts being opened under stolen identities. ING has also warned corporate customers about deepfake fraud involving synthetic audio and video used to impersonate senior executives, highlighting how AI is increasingly targeting both technology and human decision-making.
Perhaps the clearest indication of where the threat landscape is heading came from Anthropic’s 2025 threat intelligence report. It identified what is believed to be the first reported AI-orchestrated cyber espionage campaign, in which AI autonomously completed an estimated 80 to 90 per cent of operational tasks. Rather than introducing a completely new form of attack, the incident demonstrated how AI can dramatically increase the speed and scale of existing cyber techniques.
The implication is clear. Cybersecurity strategies must now evolve as quickly as the technology driving the threats themselves.
AI Becomes the Defender’s Advantage
While AI is changing the capabilities of attackers, it is also transforming the way banks defend themselves. Across the financial sector, AI is being embedded into security operations to improve threat detection, analyse user behaviour, identify anomalies and automate elements of incident response. Rather than replacing cybersecurity professionals, these technologies enable security teams to analyse significantly larger volumes of information, prioritise risks more effectively and respond to incidents before they escalate.
This is the core dynamic of the AI cybersecurity arms race: the same technology that allows attackers to operate more efficiently is also giving defenders entirely new capabilities. Success is therefore becoming less about who adopts AI first and more about who integrates it most effectively into their wider cybersecurity strategy.
Research from the World Economic Forum and KPMG suggests that organisations doing exactly that are already seeing measurable benefits. Those making extensive use of AI in cybersecurity reduce the average cost of a data breach by approximately $1.9 million while shortening breach lifecycles by around 80 days. These findings suggest that AI is already delivering measurable operational benefits when implemented as part of a broader cybersecurity strategy.
This shift is already visible in the Dutch financial sector. Through DNB’s Advanced Red Teaming programme, financial institutions test their defences by simulating realistic attacks against people, processes and critical systems. By identifying weaknesses before attackers can exploit them, banks are moving from reacting to cyber threats towards preparing for them.
This represents an important shift in mindset for banks. Cybersecurity is no longer simply about building stronger barriers around systems. It is about building organisations capable of learning, adapting and responding as quickly as the threats they face.
Cyber Resilience Becomes a Strategic Priority
As AI changes the speed and scale of cyber threats, banks are rethinking what it means to be secure. While prevention remains essential, today’s threat landscape requires financial institutions to prepare for the possibility that attacks will succeed. The focus is therefore shifting towards cyber resilience, ensuring organisations can detect incidents quickly, minimise disruption and recover while maintaining critical operations.
This shift is reflected in the actions of European regulators. In July 2026, ECB supervisory chair Claudia Buch called on banks to strengthen AI-enabled cyber defences, accelerate software patching and improve oversight of third-party technology providers. Banks were also asked to submit action plans outlining how they intend to address the growing cybersecurity risks associated with frontier AI models, signalling that AI-driven cyber risk now demands immediate action.
Alongside these expectations, the Digital Operational Resilience Act (DORA) has strengthened requirements around ICT risk management, incident reporting, resilience testing and third-party technology risk. Rather than focusing solely on preventing cyber incidents, DORA requires financial institutions to demonstrate they can continue operating during and after disruptive events, making this an ongoing regulatory requirement rather than a best practice.
Preparation is already becoming more practical. DNB’s Advanced Red Teaming programme, discussed above, is one part of that shift. At a European level, the ECB has taken a similar approach at scale: a cyber resilience stress test involving 109 banks found that almost three-quarters of identified weaknesses had subsequently been addressed, demonstrating that this kind of testing is driving tangible improvements across the sector.
Compliance and cybersecurity strategy are becoming closely intertwined. The organisations best positioned for the future will not simply invest in new technologies. They will embed resilience into their operations, governance and decision-making from the outset.
Technology Is Only Part of the Equation
Artificial intelligence has become a powerful tool for strengthening cyber defence. It can analyse millions of security events, identify unusual behaviour and automate routine investigative tasks far faster than any human team. However, AI does not operate in isolation. It still depends on people to design secure systems, interpret risks, govern AI responsibly and respond when technology reaches its limits.
This is becoming one of the defining challenges for financial institutions. While organisations continue investing heavily in AI, many struggle to recruit and retain the specialists needed to implement and govern these technologies effectively. According to the World Economic Forum, financial services organisations continue to lag behind many other industries in the use of AI across key cybersecurity functions, while more than half of organisations implementing AI for cybersecurity identify limited knowledge and specialist skills as a significant barrier to success.
The challenge extends beyond cybersecurity alone. As AI becomes more deeply integrated into financial services, banks require professionals with expertise spanning cybersecurity, cloud infrastructure, artificial intelligence, software engineering, data, regulatory compliance and operational risk. Competitive advantage now depends not only on investing in technology, but on having the capability to deploy, secure and continuously improve it.
Industry leaders are reaching the same conclusion. Jamie Dimon, Chief Executive Officer of JPMorgan Chase, has argued that AI is making cybersecurity more complex by exposing weaknesses faster than organisations can remediate them. JPMorgan’s own analysts have similarly warned that frontier AI could reduce the discovery time for previously unknown software vulnerabilities from months or years to just hours. Beyond the challenges facing individual banks, JPMorgan’s Global Chief Information Security Officer, Patrick Opet, has also called on software providers to place security on an equal footing with product innovation, arguing that weaknesses across the wider software ecosystem can quickly become risks for the organisations that depend on it.
The challenge for banks is therefore not simply adopting AI, but ensuring that innovation is supported by governance, operational resilience and the specialist capability needed to manage complex technology environments.
Key Takeaways
1. AI is reshaping both cyber threats and cyber defence
Artificial intelligence is accelerating both attackers and defenders. While banks are using AI to strengthen fraud detection, automate threat analysis and improve incident response, cybercriminals are using the same advances to make phishing, deepfake fraud and vulnerability discovery faster, cheaper and more scalable.
2. Cyber resilience has become just as important as cyber defence
Preventing attacks remains essential, but financial institutions must also be prepared to detect, respond to and recover from sophisticated incidents while maintaining critical operations.
3. Specialist capability has become the competitive advantage
AI is transforming cybersecurity, but technology alone is not enough. Banks rely on specialists with expertise across cybersecurity, AI, cloud, software engineering, data, governance and operational risk to implement, secure and continuously improve these technologies.
4. Regulation is accelerating the shift towards resilience
Initiatives such as DORA, the ECB’s cyber resilience programme and DNB’s Advanced Red Teaming framework are making it an operational and regulatory priority across the European financial sector.
5. The organisations best prepared for the future will combine AI with governance, resilience and specialist expertise
Long-term success will depend not only on investing in AI, but on combining technological innovation with strong governance, operational resilience and the specialist talent needed to adapt to a complex threat landscape.
Where This Leaves Banks
Artificial intelligence is transforming far more than the technology used by financial institutions. It is reshaping how cyber threats emerge, how banks defend themselves and how quickly they can recover when incidents occur. As AI accelerates both innovation and cybercrime, cybersecurity can no longer be viewed as a standalone technical function. It has become a strategic capability that underpins operational resilience, regulatory compliance and long-term business performance.
Across the industry, that shift is already underway. Banks are embedding AI into security operations, strengthening governance, investing in resilience testing and responding to increasingly rigorous regulatory expectations. At the same time, cybercriminals are using many of the same advances in artificial intelligence to automate familiar attack techniques and operate at a speed and scale that challenge traditional security models. The AI cybersecurity arms race is therefore not defined by technology alone, but by how effectively organisations can adapt to an environment where both attack and defence continue to evolve.
The organisations best positioned for the future will not necessarily be those deploying the most advanced AI. They will be those that combine technological innovation with the governance, operational resilience and specialist expertise needed to deploy AI securely, responsibly and at scale. As the pace of change continues to accelerate, competitive advantage will increasingly depend on an organisation’s ability to integrate these capabilities into a resilient operating model that can adapt to an increasingly complex threat landscape.