Third-Party Cyber Risk: Frontier AI Exposes Bank Vulnerabilities
Summary
Banks have invested billions in cybersecurity, but a major cyber risk now lies with third-party service providers. These providers support core financial operations, and their vulnerabilities are a growing concern. Here's the thing: Frontier AI models are accelerating the discovery of these vulnerabilities. The time available to fix weaknesses is shrinking. For example, the average time from public disclosure to active exploitation of a vulnerability decreased from 53 days in 2024 to 22 hours in 2026. What's interesting is that financial regulators are aware of this. A Federal Reserve Board staff report calls these third parties "a hidden cyber fault line." They often have greater vulnerabilities than the banks they serve. Concentration risk makes this worse, as a few technology firms support a large part of the financial sector. These risks are not hypothetical. In October 2025, a 15-hour Amazon Web Services outage caused widespread disruptions. Even though banks had backup plans, they still faced business issues. The bottom line is that third parties currently operate without meaningful direct regulatory oversight, even though federal banking regulators have the authority to examine them. This situation could impact the stability of the financial system.
This is an AI-generated audio summary. Always check the original source for complete reporting.