TREE NEWS reports: The Bank for International Settlements said advanced AI has compressed the window banks have to fix software flaws before attackers exploit them, from weeks to minutes. In a new report, the BIS said the most significant change from frontier AI is the autonomous discovery and exploitation of vulnerabilities, and that periodic security assessments and scheduled patch cycles are no longer sufficient. It urged financial institutions to patch software faster and speed up authorization decisions.
BIS Warns AI Cuts Bank Patch Window From Weeks to Minutes
The BIS is effectively conceding that the defensive rhythm banks have relied on — scheduled assessments, patch cycles, layered approvals — was built for a threat tempo that no longer exists. The sharper point is institutional rather than technical: the binding constraint becomes governance latency, since authorization and change-management processes, not detection tooling, set how fast a flaw actually closes. That shifts pressure onto supervisors and risk committees as much as security teams, and it widens the gap between institutions that can compress decision-making and those that cannot. Whether patch governance genuinely accelerates, or the warning is absorbed as another compliance exercise, is the open question.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.