A Deloitte’s recent analysis warns that next-generation artificial intelligence (AI) capabilities are accelerating the emergence of cyber risk in the financial services sector, particularly across Europe, the Middle East and Africa (EMEA). The report highlights that AI can shorten the window between discovery of vulnerabilities and their exploitation, increasing pressure on operational resilience.
Changes in the threat landscape
The report points to emerging AI capabilities — including developments linked to the Anthropic Claude Mythos model and the Project Glasswing initiative — as indicators that identification and exploitation of cybersecurity vulnerabilities may accelerate. While practical effects require further validation, the trend is clear: AI is expected to reduce the time between discovery, disclosure and exploitation of vulnerabilities.
Historically, sophisticated cyberattacks were largely the domain of well-funded state actors or highly organized crime groups. According to Deloitte, as AI models evolve, advanced offensive capabilities will depend less on specialised human expertise and more on access to data, compute resources and the ability to deploy these technologies at scale.
EMEA financial services firms are particularly exposed because of complex technology landscapes, significant third‑party dependencies, interconnected infrastructures, high availability expectations and increasing regulatory scrutiny. The challenge is not necessarily that AI creates entirely new vulnerabilities, but that it can make identification and exploitation of existing weaknesses faster than organisations can remediate them.
Urgency and how to respond
"The question now is not whether vulnerabilities exist, but how quickly organisations can identify, prioritise and remediate them before attackers act," said Szöllősi Zoltán, Central Europe Partner on Deloitte’s cyber security advisory team. He added: "Financial institutions should treat this at least as much as an operational resilience issue as a cybersecurity one. The fundamentals haven’t changed, but there is no time to delay."
Regulatory developments in the EMEA region also point toward this focus: operational resilience, third‑party risk management and ICT governance are gaining importance in an environment where cyber risks can materialise at "machine speed."
Adapting cyber defence: automation and governance
Deloitte stresses that core cybersecurity priorities remain: rapid patching, strong identity and access management, network segmentation, continuous monitoring and effective incident response. What is changing is the increasing role of automation — and specifically properly governed, AI‑assisted automation — in vulnerability management and security operations.
"AI can materially enhance defensive capabilities, particularly for vulnerability discovery and prioritisation," said Tóth László, Central Europe Partner on Deloitte’s cyber security advisory team. "However, organisations need robust governance frameworks, human oversight and clear operational controls to ensure automation strengthens resilience rather than introducing new risks."
The report warns that automation without appropriate governance can introduce operational and security risks, such as mass configuration errors or uncontrolled changes in complex environments. Therefore human oversight, validation processes and strong control frameworks remain essential when scaling AI‑based cybersecurity capabilities.
Practical priorities for financial institutions
-
Short term: implement targeted vulnerability management programmes that focus on end‑of‑life systems, internet‑accessible assets, critical business services and environments handling high‑value data. Organisations should review patch lead times and identify operational bottlenecks that slow decision‑making and remediation.
-
Medium term: build continuous, intelligence‑driven vulnerability management capabilities supported by automation and AI‑enabled analytics. Boards and senior executives should treat AI‑driven cyber risk primarily as an operational resilience concern rather than only a technical security issue.
-
Long term: if financial institutions use this period to modernise security operations and speed up vulnerability handling before advanced AI‑enabled offensive techniques become widely available, the situation could ultimately improve for defenders.
Overall, Deloitte’s analysis urges disciplined, well‑governed automation, continuous vulnerability management and a focus on operational resilience to address the faster‑emerging cyber risks facing EMEA financial services firms.



