ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Treasury: AI-fueled cyber threats bring new challenges

Deepfakes, the imperative of third-party risk management and global regulatory fragmentation are leading concerns.

April 11, 2024
Reading Time: 4 mins read
Leveraging Crowdsourced Security to Defend Against Rising Threats

By John Carlson

In response to the Biden administration’s sweeping Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, the Treasury Department released on March 27 Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector.
The 51-page report focuses on the current state of AI-specific cybersecurity risks in financial services, including an overview of current uses cases, best practices recommendations, challenges and opportunities given the current environment.

It is based on 42 in depth interviews with industry experts at financial institutions, information technology, anti-fraud/anti-money laundering companies and industry associations (including American Bankers Association staff). The appendix includes a six-page paper developed by the Financial Services Sector Coordinating Council’s Research and Development Committee titled Artificial Intelligence in the Financial Sector: Cybersecurity and Fraud Use Cases and Risks. ABA organized a series of meetings with financial sector experts, Treasury and other government officials in the fall of 2023 in support of the FSSCC’s R&D Committee. The FSSCC R&D Committee paper examined the current and anticipated use cases of cybersecurity and fraud AI solutions within the financial sector, how adversaries are utilizing AI to introduce risk to the sector and how firms are managing AI-related risks.

ABA RESOURCES > ABA members can access a staff analysis on the president’s 2023 Executive Order on the Safe, Secure and Trustworthy Use of Artificial Intelligence. Learn how risk and compliance professionals are using generative AI by attending a webinar hosted by 360factors, 2 p.m. April 11.
The report starts with the observation that “there is no uniform agreement among participants in the study on the meaning of ‘artificial intelligence.’” The report uses the following definition of AI: “A machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments. Artificial intelligence systems use machine- and human-based inputs to perceive real and virtual environments; abstract such perceptions into models through analysis in an automated manner; and use model inference to formulate options for information or action.”

The report outlines ways cyber threat actors can use AI, including social engineering, malware/code generation, vulnerability discovery and disinformation. The report notes that “AI allows bad actors to impersonate individuals, such as employees and customers of financial institutions, in ways that were previously much more difficult.” These include deepfakes to mimic voice and videos of real people as well as create synthetic identities.

The report adds: “Financial institutions have used AI systems in connection with their operations, and specifically to support their cybersecurity and anti-fraud operations, for years.” The report zeros in on the impact of generative AI, adding that financial institutions “are proceeding with caution on generative AI and are trying to address generative AI risks by providing guardrails and developing internal policies for the acceptable use of this technology.” The report identifies the importance of high quality and vast quantities of data in AI to train, test and refine good artificial intelligence models.

The report emphasizes the importance of third-party risk management and data integrity. It adds: “It is very likely that often overlooked third-party risk considerations such as data integrity and data provenance will emerge as significant concerns for third-party risk management.” The report also cautions that AI will increase dependency on major service providers.

The report notes that the financial services sector is a highly regulated industry and offers a model of responsible artificial intelligence governance at a time when risk management of artificial intelligence remains an unresolved issue across all industries. The report includes an overview of how financial sector regulatory agencies rely on model risk management, technology risk management, data management, compliance and consumer/investor protection, third-party risk management, securities market access risk management and insurance.

While the report states that financial institutions understand the expectations of their US regulators and can have a productive dialogue with regulators on artificial intelligence issues, there are concerns over future regulation and regulatory fragmentation internationally.

The report points out that financial institutions are increasing information sharing around fraud given concerns that AI will be used to perpetrate more sophisticated phishing emails and fraud impersonation. The report highlights private sector efforts to address fraud, including the Bank Policy Institute and ABA “both making efforts to close the fraud information-sharing gap across the banking sector. ABA’s initiative is specifically aimed at closing the fraud data gap for smaller financial institutions.” It adds, “ABA is working to design, develop, and pilot a new information-sharing exchange focused on fraud and other illicit finance activities.” It adds: “The U.S. Government, with its collection of historical fraud reports, may be able to assist with this effort to contribute to a data lake of fraud data that would be available to train AI, with appropriate and necessary safeguards. Treasury can be a leader in this space and will work with the financial sector, including ABA and FS-ISAC, to improve fraud data sharing from Treasury.”

The paper lays out several best practices for managing AI-specific cybersecurity risks, including:

  • Situate AI risk within enterprise risk management programs.
  • Develop and implement an AI framework.
  • Integrate risk management functions for AI.
  • Evolve the chief data officer role and map the data supply chain.
  • Ask the right questions of vendors.
  • Survey NIST’s cybersecurity framework for AI opportunities.
  • Implement risk-tiered multifactor authentication mechanisms.
  • Pick the right tool for the job and risk tolerance.

The paper also highlights several next steps and opportunities, including:

  • Need for common AI lexicon.
  • Address the growing capability gap between the largest and smallest financial institutions.
  • Narrow the fraud data divide.
  • Clarify how AI will be regulated in the future.
  • Expand the NIST AI Risk Management Framework.
  • Develop best practices for data supply chain mapping disclosures (aka “nutrition labels”).
  • Decipher explainability for black box AI solutions.
  • Address gaps in human capital.
  • Untangle digital identity solutions.
  • Coordinate with international authorities.

Last year, Treasury launched a public-private sector collaboration to address challenges in the expanding use of cloud computing. The AI report references this effort and how Treasury leveraged the Cloud Executive Steering Group, which is chaired by leaders in the financial sector with expertise in financial sector cybersecurity, in developing the AI report. Treasury could leverage this public private-sector collaboration model to advance some of the next steps and opportunities outlined in the report.

John Carlson is SVP for cybersecurity regulation and resilience at ABA.

Tags: Artificial intelligenceCybersecurityDataRisk management
ShareTweetPin

Related Posts

Study: Weak fundamentals primary cause of bank failures

Study: Weak fundamentals primary cause of bank failures

Compliance and Risk
April 16, 2026

A recent study of more than 150 years of U.S. bank data has concluded that weak fundamentals are the primary driver of bank failures, and that strong banks usually survive runs.

ABA: Policymakers should avoid changes that reduce credit availability

ABA: Policymakers should avoid changes that reduce credit availability

Compliance and Risk
April 16, 2026

The Fair Credit Reporting Act is a critical consumer protection law that supports responsible lending, and policymakers should avoid changes that could restrict credit availability by reducing data accuracy or adding complexity, banker Veneshia Ferdinand told House lawmakers...

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN touts nearly $2B in interdicted funds related to cybercrime

Compliance and Risk
April 15, 2026

FinCEN's Rapid Response Program has facilitated the interdiction of over $268 million in stolen funds on behalf of U.S. victims since the start of 2025, bringing the total to more than $1.8 billion since its inception, according to...

FinCEN issues advisory on Iranian illegal activities

Treasury steps up Iranian sanctions, eases order against Mexican bank

Compliance and Risk
April 15, 2026

OFAC announced new sanctions to target illicit oil smuggling by Iran. In addition, the FinCEN announced it was easing a fentanyl-related order against a Mexican bank to allow the dissolution of the institution.

ABA Foundation testifies on protecting older Americans from financial exploitation

ABA Foundation testifies on protecting older Americans from financial exploitation

Compliance and Risk
April 15, 2026

During a Senate hearing, the ABA Foundation outlined the critical role banks play in protecting older Americans from fraud and financial exploitation while calling for strengthened national coordination, expanded financial literacy efforts and clear federal authority for banks...

Senators introduce bill requiring online platforms to crack down on scam ads

ABA, state associations: SCAM Act will reduce consumer fraud losses

Compliance and Risk
April 13, 2026

Legislation to hold social media companies accountable for the scam ads appearing on their platforms would reduce consumer fraud losses by targeting “a key entry point” for the crime, ABA and 52 state bankers associations said in a...

NEWSBYTES

Industrial production fell in March

April 16, 2026

Mortgage rates dip

April 16, 2026

Study: Weak fundamentals primary cause of bank failures

April 16, 2026

SPONSORED CONTENT

Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

How leading banks are enhancing customer engagement through financial data insights

April 10, 2026
Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

April 1, 2026
How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026

PODCASTS

Podcast: Capitalizing on opportunities to serve high-net-worth clients

April 9, 2026

Podcast: Are credit union commercial loans risky business?

March 30, 2026

Podcast: Risk and strategy in sponsor banking

March 19, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.