The number to take to your next risk committee is 29 minutes. That is the average time an intruder needed in 2025 to move from a first foothold to the rest of the network, according to CrowdStrike data quoted in a paper the Bank for International Settlements published on September 9, 2026, and it is 65 percent faster than the year before. The paper’s authors, at the BIS Financial Stability Institute, argue that frontier AI models have changed what a bank’s cyber programme is defending against: not a person with a toolkit, but software that can find a flaw, write the exploit and chain the steps on its own (BIS FSI Occasional Paper 28).
For a Canadian compliance officer the question is narrower than the headline. Canada’s banks and insurers already answer to OSFI’s Guideline B-13 on technology and cyber risk and to its incident reporting advisory. A registered crypto asset trading platform answers to the CSA, CIRO and FINTRAC instead. What the BIS paper adds is a clock, and a checklist of the controls that every authority it reviewed, OSFI included, now wants run faster.
This piece sets out what the paper found, what OSFI already expects and where a Canadian crypto platform stands. It is a summary of published rules and a published paper, not legal advice.
What the BIS found
“When machines attack: frontier AI cyber threats and policy responses in the financial sector” is FSI Occasional Paper 28, by Juan Carlos Crisanto, Adrien Currat and Jeffery Yong. Its central claim is that frontier models differ from earlier AI in one way that matters for defenders: they can autonomously identify critical vulnerabilities, develop effective exploits and carry out increasingly complex multi-step operations. That lowers the expertise, time and money an attack needs, and it collapses the window between a vulnerability being discovered and being used.
The paper’s evidence is drawn from vendors and labs rather than from supervisory data, and it says so. Three of its data points:
- AI-enabled attacks rose 89 percent in 2025, and the average eCrime breakout time fell to 29 minutes (CrowdStrike, as cited in the paper).
- Anthropic examined 832 accounts banned for malicious cyber activity between March 2025 and March 2026 and mapped 13,873 observed actions to 482 techniques across all 14 tactics of the MITRE ATT&CK framework. The most common use was defence impairment, which in practice means trying to disable security controls, followed by preparing phishing infrastructure.
- A study the paper cites (Aldasoro et al, 2026) estimates the cost of mounting a full attack chain at US$5,000 to US$10,000 with one frontier model and as little as US$50 to US$100 with an open-weight model.
The paper also walks through a documented campaign, attributed to the security firm Gambit Security, in which an AI-assisted attacker turned reconnaissance on hundreds of servers into targets and tailored exploits in hours rather than days or weeks. Its conclusion is the line every board should hear: many of the vulnerabilities exploited could have been addressed through standard controls such as patching, credential rotation, network segmentation and endpoint detection. The tools were new. The holes were old.
Two further risks get their own paragraphs. Unpatched software has become the leading initial access vector in many incidents, because the gap between a patch being released and an exploit being available has shrunk. And reliance on a small set of cloud, software and frontier AI providers creates concentration and what the authors call sovereign access risk: a single provider’s outage or policy decision can cascade across firms and countries. For a Canadian institution whose model provider and cloud both sit in the United States, that sentence is worth reading twice.
What the regulators are doing about it
The paper’s second half surveys financial authorities in the United States, the United Kingdom, the European Union, Australia, Singapore and Canada, among others, and finds them converging. None is writing a new AI-specific cyber regime. All are reinforcing the cyber risk management and operational resilience rules they already have, and adapting supervisory expectations to a threat that is faster and more autonomous.
Frontier AI does not call for a fundamental change to the prudential framework but rather a significant acceleration in the execution of existing cyber resilience practices. BIS Financial Stability Institute, Occasional Paper 28, September 9, 2026
Where autonomous agents are in use, the paper lists the targeted additions the authorities are asking for: inventories and activity logs for every agent, limits on which tools, data and external systems an agent can reach, human approval for high-impact actions, and a reliable way to stop an agent or hand control back to a person.
On Canada, the paper records that OSFI has published two technology risk bulletins, one on generative and agentic AI and one on frontier AI, describing how the technology amplifies risk and setting out considerations for strengthening operational resilience. It also notes OSFI’s industry outreach, which produced the FIFAI II framework for responsible AI adoption in Canadian financial services (OSFI, FIFAI II). On governance, the paper quotes OSFI’s expectation directly: boards and senior management should receive timely, actionable information on how accelerated threats could affect prevention, detection, response and recovery.
That sits on top of two documents Canadian banks already work from. Guideline B-13, Technology and Cyber Risk Management, published July 31, 2022, applies to every federally regulated financial institution, foreign bank branches included, and covers governance, technology operations and cyber security on a risk-based footing. The Technology and Cyber Security Incident Reporting Advisory, effective August 13, 2021, requires institutions to notify OSFI of technology and cyber incidents in a timely way and to reflect that requirement in their own procedures. Neither document mentions frontier models. Neither needs to: the paper’s point is that the expectations are already written, and the timelines inside them have shrunk.
Where a Canadian crypto platform stands
OSFI does not supervise crypto asset trading platforms. A platform registered in Canada is a securities registrant under the CSA’s regime, typically a CIRO dealer member, and a money services business registered with FINTRAC, whose definition of an MSB expressly includes dealing in virtual currency, both exchange and transfer services (FINTRAC, money services businesses). Its cyber obligations flow through those registrations rather than through B-13.
Two Canadian documents speak to the AI side of the same problem. CSA Staff Notice 11-348, published December 5, 2024, says market participants are responsible for the outputs of the AI systems they use and expects registrants to test systems before deployment and keep a human in the loop (CSA Staff Notice 11-348). We set out what that notice and the rest of Canada’s AI patchwork require in our piece on Canada’s AI rules in 2026. The Canadian Centre for Cyber Security’s awareness note on generative AI, updated December 2025, is the plain-language guide to the attacker’s side: convincing phishing, cloned voices and generated code (ITSAP.00.041).
The practical reading is that a platform holding client crypto in Canada faces the attacker the BIS describes with a thinner rulebook than a bank and, usually, a thinner security team. The paper’s checklist does not care about the regulator’s name. When a hardware wallet maker’s shipping provider exposed customer data this month, the lesson for Canadian holders was the same one: assume the breach, and plan for what happens after it (what Canadians can do after a wallet or exchange leak).
The defender’s side of the same models
The paper is not one-sided. The same capabilities that compress the attacker’s timeline compress the defender’s: faster vulnerability discovery, threat detection and incident response. It cites Hugging Face using AI to detect an intrusion and analyse more than 17,000 events in hours rather than days. The UK’s cross-market operational resilience group, CMORG, whose guidance the paper summarises, expects remediation timelines to compress from weeks to days and in some cases hours, and its message is the same as the authorities’: the controls are established practice; what changed is the speed, scale and intensity with which they must run.
For Canadian institutions the near-term work is therefore unglamorous. Patch faster than the exploit cycle. Know every agent you run. Keep a human on the high-impact actions. Brief the board in those terms. And watch the law tracker for the day OSFI’s bulletins become expectations with dates on them; on the evidence of this paper, the dates will be sooner and shorter than the last ones.


