This is no longer a science-fiction scenario. But it is also not proof that attacks from now on will run fully autonomously and in real time. Rather, a clear trend is emerging: AI lowers barriers, speeds up individual attack steps, and makes existing methods more scalable. For Switzerland’s highly regulated and financially strong financial and insurance hub, this is relevant. Because where trust, data, and assets come together, precision is especially worthwhile for attackers.
Below, we summarize the most important points for banks and insurers.
When Algorithms Write Exploits: The New AI Threat Landscape for Swiss Banks and Insurance Companies
AI is not only a tool, but also a target
While large language models themselves are generally well secured, many risks arise at the interfaces: in APIs, open-source components, plug-ins, agent frameworks, or poorly controlled integrations into existing system landscapes.
That is exactly where attacks strike. Not always spectacular, but effective: via insecure components, tampered dependencies, faulty permissions, or prompt-injection attacks. For banks and insurers, this is particularly delicate because AI applications are often connected to sensitive data, internal knowledge sources, or operational processes.
The key question therefore is not only: “Which model are we using?” But: “How secure is the entire ecosystem around this model?”The patch window is shrinking
Until now, IT security also relied on time: a vulnerability was published, security teams assessed its criticality, prioritized systems, planned tests, and deployed patches. This process remains correct. But the available time buffer is getting smaller.
AI can help attackers evaluate patch information, code repositories, or technical descriptions more quickly. What used to require in-depth manual analysis can now, in part, be prepared in an automated way. This does not mean that every vulnerability leads to a working exploit within minutes. But it does mean: the speed on the attacker’s side is increasing.
For defenders, the quality of patch management thus becomes even more important: clean asset transparency, clear risk assessment and prioritization, automated triage, tested emergency and exception processes, and the ability to close critical gaps quickly and in a controlled manner.Social engineering becomes more credible
Initial access to corporate networks still often happens via the human factor. AI does not change that. But it does change the quality and scalability of preparation.
Attackers can evaluate public information from social media, annual reports, press releases, or job postings more quickly and use it to construct more credible pretexts. Spear phishing thus becomes less generic. Vishing—phone-based manipulation using synthetic or imitated voices—also becomes more realistic, especially when names, roles, projects, or internal workflows are already known.
This is particularly critical for new employees, in support, in payment operations, in assistant roles, or anywhere speed, trust, and hierarchy interact.
The answer is not distrust of everything and everyone. Rather, it is clear processes: call-back rules, four-eyes principles, secure approval channels, and training that takes real attack patterns seriously.Defense needs more automation—but not blindly
If attacks become faster, better prepared, and more heavily automated, cyber defense will hardly remain effective and efficient without AI support. For FINMA-regulated institutions with high requirements for operational resilience, this is not a future topic, but part of a modern security strategy.
AI-supported tools can help detect anomalies earlier, correlate large volumes of data faster, prioritize suspicious patterns, or relieve security analysts during triage. New possibilities are also emerging in vulnerability management and incident response.
But: autonomy does not replace governance. Especially in regulated environments, clear guardrails, traceable decisions, human oversight for critical interventions, and clean integration with existing security processes are needed.
So it’s not about “machines against machines” as an end in itself. It’s about people with better tools against attackers who are also using better tools.
ConclusionThe Swiss financial center has always protected trust and assets through high standards. These standards remain central. But the rules of the game are changing.
AI does not automatically make cyberattacks successful. But it makes them faster, more scalable, and in certain areas more precise—and it brings many old and forgotten shortcomings back to light. Precisely for this reason, banks and insurers must assess the development soberly—and act consistently.
Those who understand attackers’ tools, responsibly integrate AI into their own defense strategy, and at the same time take governance, resilience, and sovereignty seriously, will be well positioned for the next chapter of cybersecurity as well.
This blog was produced in close collaboration with Carla Caspar from InventxLab.
Author