Tag: AI

  • What is the Risk to the U.S. Banking System from AI

    The short answer is that the risk is real and growing, but it looks more like rising losses and a few concentrated weak points than a threat that the banking system as a whole gets drained. It helps to separate three things.

    1. Fraud against customers and businesses: the biggest near-term cost.

    Most money actually stolen with AI today comes from tricking people, not from breaking into bank systems. The best-known example is the 2024 case where an employee at a Hong Kong-based firm sent US$25 million to fraudsters after a video call with what she thought was her CFO and colleagues, all of them deepfakes. AI agents let criminals run this kind of scheme (fake voices, tailored phishing, synthetic identities) against thousands of targets at once. Deloitte, a large consulting firm, projects that generative AI could push U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023, a compound annual growth rate of 32%. That is painful, but it is spread over millions of transactions and absorbed by banks, insurers, and victims. It is not a solvency threat.

    2. Autonomous hacking of bank infrastructure: the fastest-changing risk.

    This is where AI agents change things most. In November 2025, Anthropic disclosed the first documented large-scale cyberattack run with minimal human involvement, in which a state-sponsored group manipulated Claude Code to target large financial institutions, tech companies, and government agencies. Since then the numbers have climbed. A TrendAI survey of financial-sector security chiefs this June found an 89% year-over-year increase in AI-enabled attacks, and 41% of the organizations had suffered a destructive attack in the past year. Frontier labs are also warning about their own models. In August, OpenAI said it could not rule out its highest “Critical” cyber risk level for an upcoming model, meaning the model might independently find and weaponize zero-day exploits against real systems.

    The weak spots tend to be:

    – Small banks and shared vendors. Community banks mostly run on a handful of third-party core-processing vendors. One expert told American Banker that an attacker could quickly map a small bank’s infrastructure because it depends entirely on its core vendors. A flaw in one vendor could expose hundreds of banks at once.

    – Shared technology. The International Monetary Fund argues that AI doesn’t need new kinds of attacks to change the picture. By speeding up how fast flaws in widely shared technology are found and exploited, it can turn what used to be isolated incidents into correlated ones. That correlation is what regulators worry about most.

    – Banks’ own AI agents. As banks deploy agents internally, they create a new attack surface. A manipulated agent could move funds, approve exceptions, or expose account data, rather than just give a wrong answer.

    – Instant payments. Real-time rails like FedNow and RTP settle in seconds and are hard to reverse, which gives defenders less time to catch fraud.

    3. Systemic collapse.

    This is low probability; however, it should be taken seriously. Several things protect the system from being “emptied” by hackers. Money moves between banks over monitored, rate-limited rails. Large transfers get flagged and can often be frozen or clawed back. Deposit insurance and consumer protections like Regulation E put losses on institutions rather than depositors. And defenders are using the same AI tools to find and patch flaws faster. The more plausible systemic scenario isn’t mass theft. It’s a destructive attack, such as ransomware or data corruption at a major bank or core vendor, that freezes payments or undermines confidence in balances and triggers panic. The 2024 CrowdStrike outage, which was an accident rather than an attack, showed how one bad software push can stop banks from processing transactions. The International Monetary Fund frames the key question as whether the financial system can keep functioning under severe stress, not whether money gets stolen.

    Bottom line.

    For an individual depositor, the real risk is being personally targeted by a convincing scam, not losing insured deposits to a hack. Voice-clone “family emergency” calls and fake bank-representative calls are the ones to watch out for. For the system, the risk is real, growing quickly, and concentrated in smaller institutions and shared vendors. Most experts view it as serious but manageable, not existential. I’m not a financial advisor, so if you’re weighing this against specific decisions about where to keep money, that’s worth discussing with one.