logo

Singapore sets AI risk deadlines as banks expand autonomous systems

Add The Asian Banker on Google
Discover more trusted banking and financial services insights by adding The Asian Banker as a preferred source on Google.
Singapore sets AI risk deadlines as banks expand autonomous systems
  • 89

Financial Technology Weekly: MAS and Ping An Bank tighten AI accountability as agentic tools reshape bank operations, while DNB cuts 400 roles and CrowdStrike traces agentic attacks on Korean banks.

Singapore’s final AI guidelines hold banks accountable for AI used in their services, including systems supplied by outside providers, with phased deadlines for governance and lifecycle controls. China’s Ping An Bank has assigned AI oversight to its board strategy committee as deployment expands into compliance and operational reviews.

Agentic AI is changing banks’ operations and security risks. DNB plans about 400 full-time-equivalent reductions alongside AI adoption and process improvements. Texas Capital demonstrated controls to withdraw an agent’s authority and correct ledger entries, while CrowdStrike found evidence of agentic tools used against South Korean financial institutions.

Read more on the week’s key developments:

1. MAS gives financial institutions phased deadlines for AI risk controls

The Monetary Authority of Singapore issued its final Guidelines on Artificial Intelligence Risk Management on 7 October. They apply to all financial institutions and forms of AI, with controls proportionate to risk. Institutions are expected to establish board and management accountability, maintain inventories of AI use and apply lifecycle controls and third-party assurance. Governance and risk-management expectations apply from 7 October 2027, with lifecycle controls and capabilities by 7 October 2028. MAS also plans to consult on additional agentic AI guidance in 2027.

Banks can oversee AI through existing committees if these provide adequate oversight and coordination. Where third-party providers leave gaps in assurance, banks should put additional controls in place. If risks still exceed their risk appetite, they should consider limiting, suspending or replacing the service. Simpler policies may suffice where AI failure would have little material impact. MAS’s industry collaboration, Project MindForge, offers a handbook and case studies to help institutions implement AI risk controls.

2. DNB plans 400-FTE reduction as agentic AI changes technology operations

DNB announced on 6 October that it would reduce its Technology & Services workforce by about 400 full-time equivalents as part of a broader restructuring. The Norwegian bank cited process simplification and agentic AI adoption, identifying customer-data controls, know-your-customer work and coding as areas showing efficiency gains. Downsizing is due to finish in the fourth quarter of 2026, with the full cost effect reflected from the second quarter of 2027. Further financial details are due later this year.

DNB targets a cost-to-income ratio below 40%, compared with 40.3% in the second quarter and 38.8% a year earlier. It is now changing staffing and its skills mix alongside automation. The release does not specify how much of the planned workforce reduction is attributable to AI rather than other process improvements.

3. Korean bank attacks reveal use of agentic penetration-testing tools

CrowdStrike published research on 7 October linking attacker-controlled infrastructure to a campaign against South Korean financial organisations active from late September to early October. Its investigation found Claude Code session histories, configuration files for the open-source ARTEX penetration-testing tool and model-related files. The researchers said these records showed extensive use of ARTEX and large language models against financial-sector targets. The number of affected organisations remains unconfirmed, and the campaign has not been attributed to a named adversary.

The research follows a 30 September data breach at Shinhan Bank and subsequent attacks on KB Kookmin Bank and other financial institutions. On 6 October, South Korea’s Financial Services Commission and Financial Supervisory Service warned that leaked personal information could enable targeted phishing and loan scams, even though passwords and one-time passcodes had not been exposed. The authorities directed financial companies to set up dedicated help desks and strengthen fraud monitoring during a month-long response period.

4. Ping An Bank approves formal AI management policy

Ping An Bank disclosed on 30 September that its board had unanimously approved an artificial intelligence management policy. In comments reported by Shanghai Securities News on 8 October, the bank said its board strategy committee would coordinate AI development and application management. It described lifecycle controls covering data security, algorithm risks, ethical review and accountability, with AI risks incorporated into comprehensive risk management and classified by risk level. The bank said the policy implements guidance issued by China’s National Financial Regulatory Administration in June.

Ping An’s interim report records more than 450 large-model use cases by June and the introduction of 140 operational-review agents across 55 scenarios, including anti-money-laundering due diligence and account review. China’s June guidance requires designated board oversight and lifecycle management extending through evaluation and withdrawal. Assigning oversight to the board strategy committee establishes responsibility for AI applications already used in compliance and operational controls.

5. CaixaBank brings AI deployment and data governance into a dedicated division

CaixaBank announced on 2 October that it had created an AI and Data Division with more than 40 specialists, led by Jorge Arandilla. The division brings together data governance, analytics, AI and engineering capabilities across business and technology teams. It will prioritise investments and oversee applications from development through deployment and monitoring under a common security and control framework.

The bank is already extending AI into customer service and internal workflows. In April, it announced the phased expansion of its product-application assistant beyond pre-approved loans, retaining access to human specialists. Its first-quarter presentation reported approximately 75% less preparation time for commercial customer meetings and 50% less AI-agent development time. The new division provides coordinated oversight as these applications expand.

6. Texas Capital demonstrates how an AI agent can lose authority and reverse ledger entries

Texas Capital Bank described a demonstration on 5 October in which an AI system gains permission to act through measured agreement with human reviewers. If performance deteriorates, that permission is withdrawn and earlier ledger entries can be reversed through compensating transactions. The bank and Amazon Web Services tested the approach on Apache Fineract, an open-source core banking system, using synthetic data. Texas Capital already has document-processing automation in production, but this autonomy framework remains a demonstration.

In the demonstration, withdrawing the agent’s authority triggered a compensating repayment linked to the original disbursement through its transaction identifier. The correction remained traceable and used the same access boundary as the initial action. This addresses a gap in controls that only stop an agent from acting again, leaving earlier entries untouched. A compensating ledger entry does not, however, demonstrate recovery of funds already transferred outside the system.

7. Evident finds faster AI progress but limited disclosure of financial returns

Evident’s 2026 AI Index, released on 6 October, ranks JPMorgan Chase, Capital One and Royal Bank of Canada as its top three banks. The benchmark covers 50 large banks using 75 indicators across talent, innovation, leadership and transparency. The average score rose 26% year on year. However, among the use cases tracked by Evident, only 12% reported impact against operational performance indicators, while barely 1% disclosed concrete financial returns.

Twelve banks now report realised or projected returns across their AI programmes, up from eight, although that measure combines achieved outcomes with targets. Evident also finds that developer-tool results are converging while leading banks report greater impact from general productivity assistants through training, reusable prompts and data integration.

8. Major banks back shared open-source security fixes through OSERA

The Fintech Open Source Foundation (FINOS) announced on 7 October that its Open Source Enterprise Resiliency Alliance (OSERA) was operational, following its formation announcement in June. Initial funding comes from six Premier members, including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and Royal Bank of Canada. The alliance has published its first patching and attestation standard and delivered security updates for more than 50 widely used Spring and Java projects. FINOS said the updates address publicly disclosed vulnerabilities and are available for immediate production use by members.

Banks using the same open-source components can otherwise end up commissioning or maintaining separate fixes for the same vulnerabilities. OSERA combines shared remediation with a standard defining what a patch must demonstrate before adoption, giving technology teams a common basis for assessing fixes from different producers. Each bank still needs to test compatibility and manage deployment across its own applications.

9. Plaid applies financial foundation model to credit scoring

Plaid said on 6 October that its sequential foundation model now powers three intelligence products, including LendScore Arc, a transformer-based credit risk model. Arc analyses the order, timing and interaction of transactions alongside established underwriting features. It supplies ranked reason codes that lenders can incorporate into adverse-action notices explaining credit decisions.

Plaid is also addressing the effort required to obtain cash-flow data during lending applications. Its accompanying Instant Link service lets consumers consent to access without reconnecting their bank account on subsequent applications. Lenders would still need to validate the score for their borrowers and ensure its reason codes explain the decisions they make.

10. BIS researchers examine circular investment links among AI companies

A Bank for International Settlements bulletin published on 1 October examines overlapping investment and commercial relationships among AI companies. Between 2021 and 2025, investment deals involving other AI firms accounted for 55.2% of the disclosed value of deals in which AI firms received investment. Among AI-to-AI investment deals, 46.4% by disclosed value involved firms that also had commercial supply-chain relationships during the period. The authors say these arrangements can secure critical inputs but increase opacity and create macroeconomic risks. Their views do not necessarily represent those of the BIS or its member central banks.

The authors draw a parallel with telecommunications suppliers that financed customers’ equipment purchases. When operators’ revenues disappointed, suppliers faced both financing losses and falling orders. An AI supplier investing in its customer can face a similar combination of investment and commercial exposure. For banks financing these firms, apparently separate counterparties may depend on the same underlying demand, allowing a customer’s difficulties to weaken its suppliers as well.

Chat with us WhatsApp