BSP Warns Banks on Frontier AI Cyberattacks: What the Memo Actually Asks For

TL;DR

  • In a memorandum signed by Deputy Governor Lyn I. Javier, the Bangko Sentral ng Pilipinas (BSP) warned that frontier AI systems can detect software vulnerabilities, generate exploit routes, and run multi-stage cyberattacks with minimal human intervention.
  • Access to these models is still restricted, but the BSP told supervised institutions to prepare now for adaptive, scalable AI-driven attacks against banks, third parties, and critical infrastructure.
  • The controls it asks for are concrete: attack surface visibility, micro-segmentation, zero-trust, hardware-backed MFA, and AI-enabled defensive tooling for detection and patching.
  • This builds on the BSP's AI governance framework in Memorandum M-2026-031 (June 24, 2026).

Most "AI and cyber risk" guidance is vague enough to ignore. This one is not. The BSP named a specific threat model, frontier models that can find and exploit vulnerabilities on their own, and told banks exactly which controls it expects. That combination is rare from a regulator, and it is worth reading closely whether or not you are supervised by the BSP.

What the BSP Actually Said

In a memorandum signed by Deputy Governor Lyn I. Javier, the BSP said frontier AI systems "pose threats to the financial system as they can detect software vulnerabilities and exploitation routes, as well as perform multi-stage cyberattacks with minimal human intervention."

The central bank was direct about the trajectory: "While access to these systems remains restricted and controlled, their emergence signals a shift toward increasingly adaptive and scalable cyberthreats." Its concern is that the same capabilities will eventually reach malicious actors targeting financial institutions, third-party providers, and critical infrastructure.

The BSP also pointed to industry concern over advanced coding models. Per the memo's context, global regulators have flagged models like Anthropic's Mythos, whose high-level coding ability could translate into an unusual capacity to find security vulnerabilities.

One number worth keeping in view

Deputy Governor Javier has previously said social engineering, phishing, account takeover, and identity theft, accounted for 76% of the total amount lost to financial fraud in the first half of 2025. Frontier AI does not replace that problem. It makes the phishing and social-engineering side faster and more convincing.

The Threat Model in Plain Terms

Strip the policy language and the BSP is describing an attacker that can:

  1. Enumerate your exposure faster than your team can inventory it.
  2. Find and chain vulnerabilities into a working exploit path with little manual effort.
  3. Run multi-stage operations (recon, exploit, move, exfiltrate) with minimal human steering.

The defensive implication is uncomfortable but simple. If an attacker can map and probe your attack surface at machine speed, then knowing your own attack surface, continuously, stops being good hygiene and becomes the baseline.

The Controls the BSP Asked For

Control area What the BSP wants
Attack surface visibility Current inventories of internet-facing assets, cloud services, identities, apps, and dependencies
Network segmentation Micro-segmentation to limit lateral movement
Access model Zero-trust architecture
Authentication MFA using hardware security keys, smart cards, or hardware-backed certificates
Defensive AI AI-enabled tools for real-time detection and automated patching
Resilience Reassess Business Continuity Management and plans
Governance An AI Governance Framework proportionate to the institution, per Memo M-2026-031

The authentication line matters. The BSP specifically calls for hardware-backed factors to counter AI-enabled social engineering. That is a direct response to AI that can clone a voice or draft a flawless phishing lure: push-based and OTP MFA are increasingly phishable, hardware keys are not.

If you do one thing this quarter: get an accurate, current picture of your internet-facing attack surface. You cannot defend, or segment, what you have not inventoried.

How to Start, Regardless of Your Regulator

  1. Inventory the external attack surface first. Internet-facing assets, cloud services, forgotten subdomains, exposed APIs, third-party dependencies. Continuous, not annual.
  2. Assume phishing gets better, and harden auth. Move high-value access to hardware-backed MFA. Treat OTP and push as legacy.
  3. Segment to contain. Micro-segmentation and zero-trust so a single foothold does not become domain-wide access.
  4. Automate detection and patching. Prioritize by exploitability, not just CVSS.
  5. Validate exploitability, do not assume it. A vulnerability list is not a risk picture. Test which paths actually chain into an exploit.

A Community Note: See Your Attack Surface the Way Frontier AI Would

The BSP's first ask, attack surface visibility, is exactly where most teams are weakest. You cannot inventory manually at the speed an AI-enabled attacker enumerates.

FireCompass, co-founded by members of the CISOPlatform community, offers a free way to see this for yourself. Its Free Explorer runs AI-driven autonomous penetration testing across infrastructure, web apps, and APIs, from just your organization's name, no asset list and no credit card required. For a bank or any regulated institution, it is a low-friction way to get evidence of real, exploitable attack paths, the kind of visibility the BSP is asking for. Run it and bring what you find back to the community discussion.

30-Day Checklist

  • Week 1: Build or refresh your internet-facing asset inventory. Include cloud, APIs, and third parties.
  • Week 2: Identify high-value access still on phishable MFA. Plan the move to hardware-backed factors.
  • Week 3: Map segmentation gaps that allow lateral movement from a single compromised host.
  • Week 4: Run an external attack-path test. Tabletop an AI-accelerated phishing-to-intrusion scenario.

Related on CISOPlatform

Join the Discussion

  • How current is your internet-facing asset inventory, honestly: continuous, quarterly, or "we run a scan when something breaks"?
  • Have you moved high-value banking access off OTP and push MFA yet? What slowed you down?
  • If a frontier model mapped your attack surface tomorrow, what would it find that you have not?

CISOPlatform is a free community of senior security leaders: breach postmortems, playbooks, fireside chats, and peer discussion. Join free or browse the fireside chat archive.

Sources: BusinessWorld (July 8, 2026); Business Inquirer; Manila Bulletin; BusinessMirror. BSP Memorandum signed by Deputy Governor Lyn I. Javier; AI governance framework per BSP Memorandum M-2026-031 (June 24, 2026).

Votes: 0
E-mail me when people leave their comments –

Priyanka Aash is Co-Founder of CISO Platform, the world's first online community for information security executives, and Co-Founder of FireCompass. She has been nominated for the Cybersecurity Excellence Award for leadership and AI innovation in cybersecurity, honored with the NetApp Excellerate HER award, and featured in SC Media's Women in IT Security series. She is the author of The AI Divide. Security technologist Bruce Schneier advises FireCompass.

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion