Germany's financial regulator, Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin), has warned of growing cyber risks tied to rapid advances in artificial intelligence (AI) and announced the creation of a new division to carry out targeted inspections of financial institutions' IT systems, according to Reuters.
Why the move?
Mark Branson, President of BaFin, said on Tuesday that new AI models can uncover vulnerabilities in IT systems at remarkable speed, and that discovered weaknesses are being exploited increasingly quickly. He warned that this threat affects both new and existing infrastructure, with legacy systems particularly at risk.
Branson called strengthening cyber defenses an urgent and necessary investment, noting that the financial sector can afford such expenditures.
Anthropic's Mythos and international concern
The regulator's decision follows the emergence of the Mythos AI model from Anthropic, which has set off a competitive rush across the global banking sector and has already been made available to several U.S. banks. Regulators worldwide are examining what cybersecurity risks the new model poses and how prepared financial institutions are to face them.
Experts have singled out Mythos as a particular threat to banks' legacy IT systems, where discovered flaws may lead to significant disruption.
What will the new BaFin unit do?
BaFin's new unit will perform targeted, so-called "IT-spotlight" inspections at financial companies. Branson emphasized that these reviews take substantially less time than full-scale audits; as a result, the regulator can carry out more procedures and respond more swiftly to developments and cyber incidents.
The approach is intended to allow denser, event-driven oversight and a more agile response to risks generated by emerging AI models.
Related events
The topic of AI and cybersecurity will also be covered at the Financial IT conference's cybersecurity session on May 28.


