DNB warns of faster AI attacks on banks
A specific bank heist in Italy could not be independently confirmed, but regulators do see a growing systemic risk.
De Nederlandsche Bank warns that powerful AI models could make cyberattacks on financial institutions faster and larger in scale. We could not independently verify an AI bank heist in Italy mentioned in the new reports through public sources.
DNB writes that so-called frontier AI can identify vulnerabilities more quickly and help attackers exploit security weaknesses on a larger scale. This shortens the time between discovering a vulnerability and an attack, while banks must continue protecting their systems and suppliers.
The warning is not a report of a specific attack on a Dutch bank. DNB does say that financial institutions should reassess their ICT priorities, investments and capacity. According to the regulator, dependencies on critical technology companies also deserve extra attention.
The Financial Stability Committee, which includes representatives of DNB, the Netherlands Authority for the Financial Markets and the Ministry of Finance, previously warned that AI-driven cyber risks could affect financial stability. The committee calls for better cooperation and information-sharing between institutions and sectors.
The European Systemic Risk Board also sees frontier AI as a potential systemic risk. It cites, among other things, faster discovery of vulnerabilities, less time for defence, larger attacks and new dependencies on technology providers.
For banks, the warning does not mean that every AI application is a means of attack. The same technology can help detect anomalies, test security and restore systems more quickly. DNB therefore stresses both opportunities and risks, with governance, human oversight and explainability as conditions.
The precise Italian case mentioned in the new reports remains unconfirmed for now. It is clear, however, that Dutch and European regulators regard the issue as urgent. Whether new rules, stricter requirements for suppliers or higher investment are needed remains part of the policy debate.
One story, several perspectives
What is established
- DNB and European regulators warn of AI-driven cyber risks.
- The regulators identify both opportunities and risks associated with AI.
- The specific Italian case has not been independently confirmed.
Left
Arguments Emphasises public oversight, stricter requirements for large technology companies and protecting consumers and workers from risks that private companies will not automatically shoulder.
Values Collective security, democratic oversight and protection of public infrastructure.
Consequences Fears that banks and technology companies will pass costs on to customers and taxpayers after a major cyberattack.
Centre
Arguments Wants risk-based supervision, mandatory incident reporting, independent testing and cooperation between banks, regulators and technology providers.
Values Stability, proportionality and innovation within clear parameters.
Consequences Accepts higher compliance costs if they demonstrably increase resilience, but does not want rules that block useful applications.
Right
Arguments Emphasises the responsibility of individual institutions, market incentives and investment in security without unnecessary bureaucracy.
Values Ownership, competition and technological progress.
Consequences Fears that broad regulation will slow innovation and that banks will be less able to manage risks if liability becomes too diffuse.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved with corrections · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The general risk analysis has been confirmed by multiple regulators. The original suggestion of a specific Italian bank heist has been toned down because no verifiable public confirmation was found.
- confirmed DNB warns that frontier AI can make cyberattacks faster and larger in scale. — DNB describes faster vulnerability discovery and a greater scale of attacks. source
- confirmed The Financial Stability Committee identifies AI-driven cyber risks as relevant to financial stability. — This is stated in the official FSC press release. source
- confirmed The European Systemic Risk Board identifies frontier AI as a potential systemic risk. — The ESRB warning cites consequences for cyber resilience and financial stability. source
- uncertain A specific AI bank heist in Italy has been confirmed. — The claim appears in the supplied headlines, but was not independently confirmed in the public sources consulted. source
1 correction(s) applied
- Was: The specific Italian AI bank heist is the basis for an established warning.Now: A specific AI bank heist in Italy could not be independently confirmed; regulators are nevertheless issuing general warnings about AI-driven cyber risks. (The specific case cannot be verified in public primary or independent sources.)
Editor's note
The general warnings from DNB, AFM and ESRB are well substantiated. The specific claim about an AI bank heist in Italy was not found in a public primary or independent source and has therefore not been included as fact.Sources
- Krachtiger AI-modellen vragen nieuwe afwegingen rond cyberrisico's — De Nederlandsche Bank
- FSC: AI-modellen vergroten urgentie cyberweerbaarheid — De Nederlandsche Bank
- Frontier AI models could strain cyber resilience in the financial system — European Systemic Risk Board
- Intensiever toezicht op cyberweerbaarheid en AI — Autoriteit Financiële Markten
More on this in Dutch media
- De Telegraaf — „dnb banken”
- Trouw — „dnb banken”
- RTL Nieuws — „dnb banken”