Frontier AI heightens cyber risk, asymmetric costs favor attackers
BIS Paper Auf Deutsch lesen

Frontier AI heightens cyber risk, asymmetric costs favor attackers

A new Bank for International Settlements (BIS) Bulletin warns that frontier artificial intelligence (AI) models significantly enhance cyber offensive capabilities. This development could pose systemic risks to the financial system due to asymmetric costs favoring attackers.

AI's dual-edged cyber capabilities

Frontier artificial intelligence (AI) models, such as Anthropic's Mythos and OpenAI's GPT-5.5, are rapidly advancing cyber offensive capabilities.

These models can identify software vulnerabilities, develop exploits, and autonomously execute sophisticated multi-step cyber attacks.

Evaluations by the UK government's AI Security Institute (AISI) show Mythos achieving a 68.6% pass rate for expert-level cyber tasks, with GPT-5.5 performing even better at 71.4%.

Both models demonstrated full network takeover in multi-step attack simulations.

The financial system, with its complex and interconnected infrastructure, is particularly vulnerable to these advancements.

While AI can also strengthen cyber defence, the structured nature of cyber attacks makes them exceptionally well-suited for rapid AI learning and improvement, creating a critical inflection point for financial stability.

The costs of mounting such attacks are also falling, making them accessible to less sophisticated actors.

Asymmetric costs, rising vulnerabilities

The impact of frontier AI on systemic cyber risk depends on access to tools and economic incentives.

Attackers, from state-sponsored groups to criminals, benefit from AI lowering the cost of exploiting vulnerabilities.

While defenders also use AI, the costs are asymmetric: a defender must protect every system, an attacker needs only one entry.

This shifts the balance towards offence.

Data shows a marked increase in security bug fixes, like Firefox's sixfold jump after Mythos Preview.

Critical common vulnerabilities (CVEs) have also accelerated, rising from seven per day in 2018–21 to almost 20 per day after April 2026, coinciding with AI-assisted coding tools.

A wake-up call for resilience

Frontier AI models like Mythos demand a fundamental reconsideration of financial market resilience.

The inherent asymmetry of cyber warfare, where attackers need only one success, is now significantly amplified by AI.

Swift AI adoption for defence and robust international coordination are paramount to prevent systemic cyber risks.

Source: A Mythos moment? Frontier AI and cyber risk

IN: