The New York Department of Financial Services has released new guidance addressing the risks associated with artificial intelligence in the financial services industry, specifically to do with cybersecurity.
The big picture: As AI adoption accelerates across the financial sector, cybercriminals are leveraging this technology to enhance their attack capabilities, making financial institutions increasingly vulnerable to sophisticated cyber threats.
Key takeaways:
- AI-enabled social engineering: AI has drastically increased the sophistication of social engineering attacks. Threat actors are using deepfakes — highly realistic audio, video, and text manipulations — to deceive employees into sharing sensitive information or even making unauthorized transfers.
- AI-enhanced cyberattacks: AI enables cybercriminals to identify system vulnerabilities faster and develop new malware variants, increasing the frequency and severity of cyberattacks. The proliferation of publicly available AI tools lowers the barrier for less-skilled attackers to launch complex attacks.
- Data exposure risks: AI often requires vast amounts of data, including nonpublic information (NPI) and biometric data, which makes financial institutions attractive targets. Securing this data is crucial to preventing breaches and misuse.
- Supply chain vulnerabilities: AI systems often rely on third-party service providers (TPSPs), creating potential supply chain vulnerabilities. Each vendor and partner introduces additional risk, making rigorous TPSP management essential.
- Mitigation measures: The DFS recommends several cybersecurity controls, including robust risk assessments, comprehensive third-party management policies, multi-factor authentication (MFA), and cybersecurity training. Companies must focus on AI-specific risks in their cybersecurity programs to protect against AI-driven threats.
Between the lines: This guidance doesn’t introduce new regulatory requirements but emphasizes applying existing standards to manage AI-related risks. Covered Entities should align their cybersecurity programs with DFS’s cybersecurity regulation (23 NYCRR Part 500), focusing on risk assessments, third-party service provider oversight, and access controls.
What they said: “AI has improved the ability for businesses to enhance threat detection and incident response strategies, while concurrently creating new opportunities for cybercriminals to commit crimes at greater scale and speed,” said DFS Superintendent Adrienne A. Harris. “New York will continue to ensure that as AI -enabled tools become more prolific, security standards remain rigorous to safeguard critical data, while allowing the flexibility needed to address diverse risk profiles in an ever-changing digital landscape.”
.




