# When the Machines Come for the Vault: How Agentic AI is Rewriting the Rules of Banking Cybersecurity
The RBI's latest Financial Stability Report has confirmed what security researchers have long feared: AI-enabled cyberattacks are now the leading perceived cybersecurity risk to the financial sector. Agentic models capable of autonomously probing infrastructure for vulnerabilities are democratizing offensive hacking in ways that make traditional defensive strategies obsolete. As this article explores, the banking sector's path to survival lies not in preventing every attack, but in building the cyber resilience to absorb, withstand, and recover from whatever intelligent malware comes next.
## The New Threat Landscape: When Hacking Tools Think for Themselves
The cybersecurity landscape has shifted beneath our feet. The Reserve Bank of India's recent Financial Stability Report has identified AI-enabled cyberattacks as the most significant perceived threat to financial stability over the next twelve months. But what exactly makes this generation of threats so different from the malware, phishing campaigns, and ransomware that security teams have been battling for decades?
The answer lies in a category of AI systems known as "agentic models." These sophisticated AI frameworks, such as Claude's Mythos series, can autonomously identify vulnerabilities in a financial institution's infrastructure without requiring significant human intervention. Unlike traditional penetration testing tools that execute predefined scripts, these agentic models can reason about systems, adapt their approaches, and discover novel attack vectors that might otherwise go unnoticed by human security researchers.
The implications for the hacking community are profound. These tools dramatically compress both the time and skill required to launch sophisticated attacks. A threat actor who might previously have needed months of reconnaissance, custom exploit development, and careful planning can now leverage agentic AI to accomplish the same objectives in days or even hours. The scalability of such attacks means that what was once the domain of elite, well-funded criminal enterprises is becoming accessible to a much broader range of actors.
## The Cat-and-Mouse Game of Access Restrictions
There is an uncomfortable truth that security researchers must confront: the barriers currently limiting access to these powerful tools are almost certainly temporary. US government directives have imposed some restrictions on frontier AI models, and leading AI providers have deliberately limited certain capabilities in their public releases. But the track record of such restrictions is not encouraging.
History suggests that restrictions on emerging technologies ultimately fail to contain their spread. Models are being released into the public domain with increasing frequency, and researchers are already finding ways to circumvent safety guardrails. It is only a matter of time before a wider range of actors—including those with malicious intent—gain access to these offensive capabilities. Smart money says this happens sooner rather than later, not in some distant future.
## Why Banks Are Ground Zero for Digital Catastrophe
The banking sector has always been a prime target for cybercriminals, and for good reason: that's where the money lives. Both the RBI and traditional financial institutions have accumulated decades of experience managing cyber risk, developing sophisticated defensive capabilities that have repelled countless attacks. Yet the emergence of agentic AI threat models changes the calculus in uncomfortable ways.
Consider the possibility that the financial infrastructure itself is under-defended against these new threats. The financial sector operates as a deeply interconnected ecosystem, with commercial banks, cooperative banks, NBFCs, microfinance institutions, fintech startups, and countless third-party technology providers all relying on shared infrastructure and interconnected systems.
The 2024 ransomware attack on C Edge Technologies, a core technology service provider, demonstrated this fragility with stark clarity. When that attack hit, it temporarily disrupted payment systems across 300 cooperative and rural banks simultaneously. Customers found themselves unable to withdraw cash from ATMs or complete UPI transactions. One vulnerability in one shared infrastructure provider cascaded across the entire financial sector.
## The Asymmetric Battle Nobody Can Afford to Lose
This interconnectedness creates an asymmetry that deeply favors the attacker. An adversary needs to discover just one vulnerability in shared infrastructure to cause significant, widespread harm. Meanwhile, banks must defensively secure every single potential entry point across distributed, heterogeneous, and often legacy systems. The attack surface extends well beyond any individual institution's walls, incorporating fintech partners, payment gateways, cloud providers, and technology vendors of all descriptions.
The problem is compounded by fundamental uncertainty. Financial institutions have limited control over when, where, and how an AI-enabled cyberattack will occur. The likelihood of attack is unknown. The potential severity is unknowable. And there is genuine uncertainty about whether existing cyber defenses—which have held up against conventional threats—will be effective against emerging AI-powered attack methodologies.
Attempting to anticipate every possible attack vector is a losing proposition. Instead, cybersecurity thinking in the banking sector must shift toward a resilience-based approach. This framework acknowledges uncertainty as an integral part of decision-making, focusing not merely on preventing attacks but on ensuring institutions can withstand, respond to, and recover from successful breaches.
## The Alarming State of AI Security Preparedness
The data on current preparedness is sobering. The RBI's FREE AI Committee Report conducted a comprehensive assessment and found that only one-fourth of surveyed institutions had formal processes in place to mitigate AI-related incidents or failures. Of the 127 entities that reported using AI in their operations, a mere 14 percent conducted regular audits. Only 18 percent maintained proper audit logs, and just 14 percent engaged in real-time performance monitoring.
These numbers reveal an uncomfortable reality: the financial sector's adoption of AI has far outpaced its ability to secure those systems. No single institution possesses the visibility, data, or capability to anticipate and prepare for every unknown threat. The variance across the sector is considerable, with banks, NBFCs, and microfinance institutions operating at vastly different levels of technological maturity, operational capacity, and financial resources.
The RBI has begun responding to these emerging risks. The recent Draft Guidance on Model Risk Management requires banks to safeguard their AI models against cyber threats. The Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions, 2026 mandate that financial institutions dynamically incorporate lessons learned from past incidents and exercises into their response planning. These regulatory interventions are necessary but insufficient on their own.
## Ecosystem-Level Solutions for Collective Defense
Regulatory expectations directed at individual institutions may not suffice. What the financial sector needs are ecosystem-level solutions that leverage collective intelligence and shared capabilities. Several promising interventions are emerging from the broader cybersecurity community.
First, there is an urgent need to operationalize real-time information sharing among financial institutions, coordinated through the Computer Security Incident Response Team-Financial Sector (CSIRT-Fin). If banks shared information about cyberattacks, near-misses, and incidents involving external technology partners, all institutions would benefit from timely threat intelligence, enabling them to anticipate and prepare for similar attacks. For such a mechanism to work effectively, reporting must be non-punitive—a principle successfully pioneered in aviation safety through programs like NASA's Aviation Safety Reporting System, which encourages candid reporting of close calls and hazardous conditions through guaranteed confidentiality.
Second, intelligence generated from these sharing mechanisms should be used to develop a comprehensive catalogue of AI-enabled cyber risk scenarios with plausible mitigation strategies. This catalogue would function as an equalizer, particularly for smaller institutions that lack the resources for independent threat research. It would provide a common understanding of priority risks, including those initially identified by only one or two institutions, covering attack vectors, potential impacts, and recommended containment responses.
The UK Cross Market Operational Resilience Group maintains one such library of cyber scenarios, recently adding threat models involving threat actors using agentic and generative AI to create false employee and customer accounts. Expanding similar initiatives across the Indian financial sector could dramatically improve collective readiness.
Third, there is a critical need to establish baseline resilience standards that apply uniformly across the banking, securities, pensions, and insurance sectors, irrespective of institutional size, geographical footprint, IT architecture, or perceived risk profile. The principle of proportionality in cybersecurity—applying resources proportionate to perceived risk—is being challenged by the unpredictable nature of AI-enabled attacks. Communications channels, shared drives, and email systems may appear relatively low-risk yet can serve as attack vectors precisely because they receive weaker oversight.
## A Call for Collective Cyber Hygiene
As AI's offensive capabilities make cyberattacks cheaper, more pervasive, and harder to anticipate, the fundamentals of cyber hygiene matter more than ever. But the scale and speed of emerging risk demands more than any single financial institution can achieve alone. The RBI's priority must be to raise the baseline of sectoral resilience through ecosystem-level solutions that enable institutions to learn from collective intelligence, anticipate emerging risks, and prepare before challenges become full-blown crises.
The age of autonomous hacking has arrived. The question is whether the defenders are ready to meet it with equally intelligent, collaborative, and resilient defense. The answer will determine the stability of the global financial system in the years ahead.