Posted on Leave a comment

MAS, ABS launch ACT taskforce as AI raises cyber risks for banks

Singapore’s financial sector is moving to coordinate its defence against a new generation of cyber threats, as frontier artificial intelligence models begin to change how attacks are planned, scaled and executed.

The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) have established the AI-Driven Cyber and Technology Risk Taskforce, or ACT, an industry-wide group aimed at strengthening the sector’s collective cyber and technology resilience. The taskforce has brought together members since May 2026, MAS and ABS said in a statement.

Also Read: Ransomware in Singapore is becoming a human problem, not just a malware one

ACT includes MAS, ABS, DBS, OCBC, UOB, Singapore Exchange, Network for Electronic Transfers, and Banking Computer Services. Its remit is to help financial institutions understand and respond to AI-enabled threats through shared learning, trials of defensive tools, and new guidance on controls and response measures.

The move reflects a growing concern among regulators and financial institutions globally: AI is no longer just a tool for improving productivity or customer service. In the hands of attackers, it can also lower the cost of cybercrime, speed up reconnaissance, and make phishing, malware development and vulnerability discovery more effective.

“Frontier AI is increasing the severity, scale and sophistication of cyber threats. The financial sector must respond with urgency and through strong collaboration,” said Vincent Loy, Assistant Managing Director for Technology and Chief Technology Officer at MAS.

Why AI changes the cyber equation

Banks and financial market infrastructure providers have long been prime targets for cybercriminals, given the value of the data and transactions they handle. But frontier AI models add a new layer of complexity.

These systems can be used to rapidly scan code, identify weak points in digital infrastructure, draft convincing social engineering messages, and automate parts of an attack chain. A less skilled attacker may now be able to perform tasks that previously required more technical expertise. More capable groups, including state-linked actors, can use AI to accelerate operations that are already sophisticated.

For Singapore, the issue is especially sensitive. The city-state is both a regional financial hub and a major technology node for Southeast Asia. Its banks, exchanges and payment systems serve consumers, corporates and investors across borders. A serious disruption would not remain a local operational incident; it could affect regional confidence in digital banking, payments and capital markets.

This is why MAS and ABS are framing the response as a sector-wide effort rather than a matter for individual institutions alone. In a connected financial ecosystem, one organisation’s weakness can become another’s exposure, particularly when vendors, payment rails, cloud systems and shared infrastructure are involved.

ACT will focus on three areas: industry collaboration, capability uplift, and guidance development.

The first is information sharing. Financial institutions will exchange AI cybersecurity use cases and experiences, and engage with cybersecurity and AI experts. This matters because AI-enabled threats are still developing quickly, and no single institution is likely to have a complete view of the risk landscape.

The second is practical capability building. The taskforce will help uplift cyber defence knowledge and conduct proof-of-concept trials to test advanced AI-enabled defensive tools. This suggests the group will not only discuss risks in principle but also experiment with ways to detect, prevent and respond to them.

Also Read: Cybersecurity in the AI age: How startups can stay ahead

The third is guidance. ACT will work on measures, controls and solutions that financial institutions can adopt to improve their cybersecurity posture against AI-enabled threats.

A regional signal from Singapore

Singapore has often set the tone for financial technology regulation in Southeast Asia. Its approach tends to combine innovation with tight operational and risk-management expectations. The creation of ACT fits that pattern.

Across the region, banks and fintech firms are racing to use AI for customer support, fraud detection, credit assessment, compliance and internal automation. At the same time, regulators are under pressure to ensure that faster adoption does not create hidden weaknesses.

AI risk is not limited to model bias or data privacy. It also includes operational resilience: whether critical systems can withstand attacks, whether staff can identify AI-generated fraud, whether vendors are secure, and whether incident response plans are ready for machine-speed threats.

This is particularly relevant in Southeast Asia, where digital finance has expanded quickly over the past decade. Mobile wallets, instant payments, digital banks and embedded finance platforms have brought millions of users into the formal financial system. That growth also broadens the attack surface. Cybercriminals now have more digital entry points, more user data to exploit, and more interconnected platforms to target.

Singapore’s taskforce could therefore become a reference point for neighbouring markets. While each country has its own regulatory structure, the underlying challenge is shared: financial institutions need to defend against attackers who are adopting the same technologies that banks themselves are using to modernise.

Collaboration over isolated defence

The most notable feature of ACT is its collective structure. It brings together regulators, major banks, exchange infrastructure, payments players and technology service providers.

That matters because cyber resilience in finance is rarely about one organisation alone. A phishing campaign targeting bank employees may use information stolen from a vendor. An attack on payment infrastructure may affect merchants, consumers and banks at once. A flaw in a third-party technology stack can spread risk across multiple institutions.

A coordinated taskforce can help reduce duplication, speed up learning and establish common expectations. It can also create a safer environment for testing defensive tools, especially when AI systems themselves can introduce new risks if poorly implemented.

The proof-of-concept trials will be worth watching. AI can help defenders by analysing large volumes of alerts, detecting anomalies, generating threat intelligence and assisting security teams during incidents. But these tools need careful governance. False positives can overwhelm teams; false negatives can create misplaced confidence. Models can also be manipulated through adversarial inputs or compromised data.

Also Read: AI phishing is turning trust into APAC cybersecurity’s weakest link

Ong-Ang Ai Boon, Director of ABS, said AI is reshaping the cyber threat landscape and that the financial sector must move together to stay resilient. She added that close coordination, governance and continued partnership with regulators and industry stakeholders would be central to strengthening cyber and technology resilience.

Her emphasis on governance is important. The question is not simply whether banks can buy or build more AI tools. It is whether they can deploy them responsibly, monitor them continuously, and ensure human accountability remains clear when automated systems are involved in cyber defence.

The next test: execution

ACT’s creation is timely, but its impact will depend on execution. Information sharing must be specific enough to be useful. Guidance must keep pace with evolving threats. Proof-of-concept trials must lead to practical adoption, not just reports.

The taskforce will also need to account for smaller financial institutions and ecosystem players that may not have the same cyber budgets as major banks. In Southeast Asia’s digital finance landscape, risk often travels through the weakest link. Strengthening only the largest players will not be enough if attackers can exploit smaller vendors, fintech partners or outsourced service providers.

Still, the initiative is a clear sign that Singapore sees AI-enabled cyber risk as a systemic issue. The financial sector’s response cannot be fragmented, slow or purely reactive.

As frontier AI becomes more capable, the line between cyber offence and defence will keep shifting. Singapore’s bet is that the best response is not for each institution to fight alone, but for the sector to build shared muscle before the next wave of attacks arrives.

The post MAS, ABS launch ACT taskforce as AI raises cyber risks for banks appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *