The newest generation of artificial intelligence is reshaping how cyber threats evolve within financial services. A recent Deloitte analysis warns that AI advances can substantially shorten the time between vulnerability discovery and exploitation, increasing pressure on financial institutions across Europe, the Middle East and Africa (EMEA) to strengthen operational resilience.
What is changing and why it matters
Deloitte highlights that recent AI developments — including innovations tied to the Anthropic Claude Mythos model and the Project Glasswing initiative — point to faster identification and exploitation of vulnerabilities. While the full practical impact of these technologies is still being assessed, the observable trend is that AI can shrink the time window between when a vulnerability is found, disclosed and then weaponized.
Historically, sophisticated cyberattacks were often carried out by state actors or well-organized criminal groups. AI risks democratizing such capabilities, reducing the premium on specialized expertise and shifting the emphasis toward data availability, compute resources and effective use of AI tools.
Financial institutions in the EMEA region may be particularly exposed due to complex technology ecosystems, reliance on third-party providers, interconnected infrastructures, high availability demands and increasingly strict regulatory expectations. Deloitte argues the central risk is not necessarily new kinds of vulnerabilities, but that exploiting existing weaknesses can happen faster than organizations can remediate them.
Expert comments
Szöllősi Zoltán, partner in the Deloitte Central Europe Cybersecurity Advisory practice, said: “The question today is no longer whether vulnerabilities exist, but how quickly organisations can identify, prioritise and remediate them before attackers exploit them.” He added that firms should treat the issue as much as an operational resilience challenge as a cybersecurity one, because response times have materially shortened.
Tóth László, also a partner in Deloitte Central Europe Cybersecurity Advisory, stressed both AI’s benefits and risks: “Artificial intelligence can be of significant help in uncovering vulnerabilities and prioritising remediation tasks. However, only with appropriate governance frameworks, human oversight and clear operational controls can automation genuinely increase resilience rather than introduce new risks.”
Deloitte warns that poorly governed automation could trigger mass configuration errors or uncontrolled changes in complex IT environments, underscoring the continued importance of human supervision and strict controls.
Recommended actions for financial institutions — short, medium and long term
-
Short term: launch targeted vulnerability management programmes, focusing on end-of-life systems, internet-facing assets, critical business services and environments handling high-value data. Review remediation processes and identify operational bottlenecks that slow decision-making.
-
Medium term: build continuous, intelligence-driven vulnerability management capabilities supported by automation and AI-enabled analytics. Boards and senior executives should view AI-related cyber risks primarily as operational resilience issues rather than purely technical problems.
-
Long term: leverage AI to strengthen defensive capabilities by modernising security operations and accelerating vulnerability remediation. Deloitte suggests organisations that modernise now will be better positioned before advanced AI-enabled attack techniques become widespread.
Principles and conclusions
Deloitte reiterates that core cyber hygiene remains fundamental: timely patching, robust identity and access management, network segmentation, continuous monitoring and effective incident response are still the backbone of cyber resilience. The main shift is wider adoption of automation — particularly AI-assisted automation — executed under rigorous controls.
In sum, the Deloitte analysis concludes that while AI accelerates cyber risk dynamics for the financial sector, it also presents an opportunity to modernise cyber operations and shorten remediation cycles, provided organisations implement strong governance and maintain human oversight.



