Cybersecurity has always been a race between the speed at which attackers discover weaknesses and the speed at which defenders can identify, contain and remediate them. Frontier artificial intelligence is beginning to change the terms of that race.
The latest generation of AI models is moving beyond vulnerability identification and code generation. They are increasingly capable of connecting multiple stages of an attack, adapting to a target and operating with less human intervention. The same capabilities, however, can also help defenders review code, identify weaknesses and accelerate remediation.
This creates a more complex risk environment. AI is potentially making cyberattacks faster, cheaper and more scalable, while reducing the time available for organisations to respond.
The Bank for International Settlements’ July 2026: A Mythos moment? Frontier AI and cyber risk bulletin provides important evidence of this shift. Its analysis points to implications extending beyond cybersecurity into operational resilience, third-party risk and financial stability.
From AI Assistance to Greater Autonomy
The most important development is not simply automation, but AI’s increasing ability to work through a sequence of technical tasks.
The bulletin references UK AI Security Institute testing across 95 cybersecurity tasks covering four levels of difficulty. Anthropic’s Mythos achieved a 68.6% pass rate on expert-level tasks, while OpenAI’s GPT-5.5 subsequently achieved 71.4%. In simulated corporate environments, both models were able in some attempts to complete enough stages to achieve a full network takeover.
Cyberattacks are particularly compatible with AI because logs, source code, vulnerability databases, error messages and system responses provide machine-readable feedback. An AI system can potentially use the outcome of one action to determine its next step.
The critical shift is therefore from using AI as a coding or research assistant towards systems capable of participating more actively in an attack workflow.
The Economics of Cyberattacks Are Changing
Capability is only one part of the equation. Cost could determine how widely these capabilities are adopted.
The bulletin estimates that a complete AI-enabled attack chain can consume around 100 million tokens. At then-current cloud prices, an attack using Claude Mythos Preview could cost approximately $5,000-$10,000, while other frontier models could cost around one-fifth as much. Some lower-cost models could reduce the estimated computational cost to approximately $50-$100 per attack.
These figures should not be interpreted as the total cost of a real-world cyberattack. They illustrate something more important: the potential decline in the computational cost of sophisticated cyber activity.
If that trend continues, advanced capabilities may become accessible to a wider range of threat actors, not only highly organised groups.
The Asymmetry Between Attackers and Defenders
The same technology can strengthen both sides. AI can help defenders analyse systems, identify vulnerabilities, detect anomalous behaviour and accelerate remediation. The risk emerges from the difference in incentives and operating environments.
An attacker may need to find only one exploitable weakness. A financial institution must continuously protect an entire technology environment comprising proprietary applications, cloud platforms, APIs, legacy systems, open-source software and third-party services. This creates a potential speed mismatch.
If attackers can identify and chain vulnerabilities faster than organisations can discover, prioritise and remediate them, even mature security programmes could face greater pressure.
Why Financial Infrastructure Is Particularly Exposed
The financial sector presents a particularly interconnected cyber-risk environment.
Banks, payment systems, securities markets and other financial infrastructures depend on complex technology stacks and extensive networks of external providers. A vulnerability in a widely used software component or service can therefore affect multiple institutions simultaneously.
Consider a trading environment dependent on market-data providers, cloud infrastructure, authentication systems, APIs, network services and third-party applications. A compromise in one part of that chain can create operational consequences elsewhere. This makes the issue larger than conventional confidentiality, integrity and availability. The critical question becomes continuity.
Can trading continue? Can transactions be settled? Can payment systems operate? Can transaction records be trusted? And can critical services be restored before a technology incident develops into a market-confidence problem? These are questions of operational and financial resilience.
Vulnerability Management May Need to Move Faster
Frontier AI also challenges traditional vulnerability-management cycles. Scheduled assessments, penetration testing and periodic patching remain important, but increasingly capable AI could compress the time between discovering a vulnerability and attempting to exploit it.
The answer is not necessarily to patch everything immediately. In financial environments, changes to critical systems themselves carry operational risk.
The objective instead is to accelerate the entire lifecycle: discover, assess, prioritise, test, remediate and validate.
AI can potentially help compress this defensive cycle. But the technology must be integrated into governance and security processes rather than treated as a standalone solution.
Third-Party Risk Becomes More Significant
The expanding digital perimeter makes third-party exposure increasingly important.
A bank may maintain strong internal controls while relying on external cloud providers, software vendors, payment processors, network operators and open-source components.
Frontier AI could make common vulnerabilities more valuable because attackers may be able to identify and scale exploitation across organisations using the same technology.
For risk managers, vendor assessment therefore needs to go beyond annual questionnaires and certifications.
Organisations increasingly need visibility into which suppliers support critical services, what technologies those suppliers depend upon and how quickly vulnerabilities can be communicated and remediated. A vulnerability affecting one provider can become an exposure shared across an entire ecosystem.
Cyber Resilience Is Becoming an Ecosystem Exercise
This is why cyber resilience cannot be built entirely within an individual institution. Financial organisations operate within interconnected ecosystems, and their resilience partly depends on the resilience of technology providers, market infrastructures, cloud platforms and other participants.
Information sharing consequently becomes more important. A vulnerability discovered by one institution may already exist elsewhere. Delayed disclosure can leave multiple organisations exposed.
The July bulletin highlights this broader externality: the private benefit of discovering and disclosing a vulnerability may be smaller than the system-wide benefit when many organisations depend on the same software or supplier.
For financial markets, faster information sharing can therefore become a form of collective defence.
What the Market Reaction Tells Us
The implications are also being considered by investors. The bulletin examined market reactions following the announcement of Mythos, when cybersecurity stocks experienced negative cumulative abnormal returns. The reaction was interpreted as reflecting concerns that increasingly capable AI could make some existing cybersecurity products or services less valuable.
This creates an unusual market dynamic. A more dangerous cyber environment should theoretically increase cybersecurity demand. But AI could simultaneously automate some security functions, potentially changing the economics of existing security products and services.
The cybersecurity industry may therefore face both greater demand for protection and pressure to reinvent what protection means.
From Cybersecurity to Financial Resilience
Frontier AI does not make existing cyber-risk frameworks irrelevant. It makes them more demanding. Risk assessments increasingly need to consider AI-enabled attack paths, faster exploitation and concentration through common technology providers. Resilience exercises may need to examine scenarios in which a vulnerability is discovered and exploited across multiple interconnected institutions within a compressed timeframe.
For financial institutions, the objective cannot simply be preventing every attack. It is ensuring that critical services continue even when prevention fails.
That requires faster vulnerability discovery, stronger third-party oversight, intelligent monitoring, AI-enabled defence, coordinated information sharing and recovery mechanisms that have been tested against extreme scenarios.
The most important lesson from the frontier AI developments examined in July is therefore not that cyber defence has become impossible. It is that the time available to defend, respond and recover may be shrinking.
The same technology accelerating offensive capabilities can also become a resilience multiplier for defenders. The strategic advantage will increasingly belong to organisations that can identify weaknesses first, respond fastest and maintain critical financial services when an attack succeeds.
The emerging “Mythos moment” may ultimately be less about one AI model than about recognising that cyber resilience can no longer be designed around the assumption that attackers will move at human speed.
