FRM Exam Part II · The Financial Stability Implications of Artificial Intelligence
Cyber Risk and Malicious Use of AI in Finance
Updated 11 October 2026 · Fact-checked
Cyber risk and malicious use of AI means attackers use AI to make cyber attacks, fraud, deepfakes, disinformation and market manipulation cheaper, faster and more convincing. To answer exam questions, name the threat, the channel it uses, the loss it causes, how it can become systemic, and the control or AI-based defence that reduces it.
Understand Cyber Risk and Malicious Use of AI
AI does not create new categories of cyber risk so much as it lowers the cost, skill and time needed to run existing attacks. Generative AI can write fluent phishing emails in any language, clone a voice from a short clip, produce a realistic video of an executive, and help write or debug malicious code. The attacker gains scale and credibility.
The main threats you must know are:
- Fraud and social engineering: deepfake voice or video used to impersonate a CEO or client and authorise payments, or to defeat identity checks (KYC).
- Cyber attacks: faster vulnerability discovery, more convincing phishing, adaptive malware, and attacks on the AI systems themselves.
- Disinformation and market manipulation: fake news, fake images or coordinated posts that move prices or trigger deposit withdrawals.
- Attacks on models: data poisoning (corrupting training data), prompt injection and model theft.
The financial stability angle is what the exam stresses. One fraud is an operational loss. But a shared weakness can make losses correlated. Many firms rely on the same cloud providers and the same AI vendors. A single successful attack or outage can hit many institutions at once. A believable false rumour spread by AI can also speed up a bank run, because social media and digital banking let depositors move money in minutes. Trust is the asset at risk.
AI also helps defenders. Firms use it to detect anomalous transactions, spot phishing, monitor networks, triage alerts and detect deepfakes. The result is an arms race. Defence helps, but it brings its own risks: model errors, false positives, dependence on a few vendors and weak explainability. A balanced answer always covers both sides.
Risk managers respond with governance and basics: strong authentication that does not rely on voice or face alone, call-back and dual-approval for payments, staff training, third-party risk management, incident response and testing, and information sharing across firms and authorities. Cyber risk sits within operational risk, so link it to resilience, not only to capital.
Key formulas to remember
- Threat-to-impact chain
- Threat (AI-enabled) → Channel → Loss event → Contagion → Control
- Use this to structure any case answer. Name each link rather than only the headline threat.
- Cyber risk as a scenario
- Expected annual loss = Frequency × Average severity
- A simple operational-risk view. AI mainly raises frequency and success rate; systemic events raise severity through correlation. It is a framing, not a required calculation.
- Systemic amplification rule
- Common dependency (cloud/vendor/model) + speed of information = correlated losses
- Concentration and herding explain why firm-level cyber risk becomes a financial stability issue.
- Dual use principle
- Same AI capability → attack benefit and defence benefit
- Never claim AI only increases risk or only reduces it.
How to solve Cyber Risk and Malicious Use of AI questions
Use this method for any scenario or concept question on AI, cyber risk and malicious use.
- 1Identify the threat type: fraud or impersonation, cyber attack, disinformation or manipulation, or attack on an AI model.
- 2Name the channel: email, voice call, video, social media, API, third-party provider or training data.
- 3State the direct loss: payment fraud, data breach, outage, price distortion, deposit outflow or reputational damage.
- 4Ask whether it can become systemic: common vendor, shared model, herding, or fast-spreading rumour.
- 5Match the control to the threat: call-back and dual approval for deepfake payments, multi-factor authentication, data validation for poisoning, vendor oversight for concentration.
- 6Check for the defensive side: AI-based detection, with its limits such as false positives and explainability.
- 7Eliminate options that are absolute (always, only, eliminates) or that match a different threat than the one described.
Quickest way: Threat, channel, control matching
When to use it: For single-sentence MCQs asking which risk or control fits a described situation.
- Underline the one thing the attacker fakes: voice, video, text, data or news.
- Pick the control that verifies through an independent channel for impersonation, or protects data integrity for model attacks.
- If the question asks about stability, choose the answer mentioning concentration, correlation or contagion.
- Reject answers that say AI removes the risk or that controls can eliminate it.
Common mistakes in Cyber Risk and Malicious Use of AI
Treating AI-enabled fraud as only a firm-level operational loss.
Candidates focus on the single incident and miss the shared dependencies.
Fix: Always ask if many firms rely on the same provider, model or information source. If so, add the systemic channel.
Saying voice or face biometrics fully solve identity fraud.
Biometrics sound strong, but deepfakes can imitate them.
Fix: Recommend layered controls: multi-factor authentication, liveness checks and out-of-band call-back.
Confusing data poisoning with prompt injection.
Both are attacks on AI systems.
Fix: Poisoning corrupts training data before or during learning. Prompt injection manipulates a model through inputs at use time.
Ignoring AI as a defensive tool.
The topic title stresses malicious use.
Fix: Include AI-based anomaly detection and monitoring, while noting model risk, false positives and vendor dependence.
Forgetting disinformation can trigger runs and price moves.
Candidates link disinformation only to reputation.
Fix: Connect fake news to market manipulation and fast deposit outflows through social media and digital banking.
Choosing absolute statements about prevention.
Candidates want a definitive control.
Fix: Controls reduce likelihood and impact. Resilience, response and recovery are still required.
Worked examples
Example 1
A bank's treasury clerk receives a video call from someone who looks and sounds like the CFO and instructs an urgent transfer of USD 2 million to a new account. The transfer is made and later found to be fraudulent. Which control would have been most effective?
A. A longer password policy for the payments system
B. Mandatory out-of-band call-back verification and dual approval for new-beneficiary payments
C. Higher capital held against market risk
D. Faster quarterly review of the trading book
Show the solution
- Identify the threat: deepfake impersonation, a social engineering fraud.
- Identify the weakness: one person accepted a visual and voice instruction as proof of identity.
- Match the control: verify the instruction through an independent channel and require a second approver.
- Check the others: A protects credentials, not a voice-and-video instruction. C and D address market risk and are unrelated.
Answer: B. Call-back verification with dual approval breaks the attack because the deepfake cannot control the independent channel or a second approver.
Example 2
Which statement best explains why AI-enabled disinformation can be a financial stability concern rather than only a reputational one?
A. It can only affect a single firm's website
B. It can spread quickly and trigger correlated deposit withdrawals or price moves across institutions
C. It reduces the speed of information flow in markets
D. It affects only firms that do not use AI
Show the solution
- Recall the stability test: does the event produce correlated losses across many firms?
- Disinformation travels fast on social media, and digital banking lets depositors act within minutes.
- Test A: too narrow. Test C: opposite of reality, since it increases speed. Test D: wrong, it is not limited by a firm's AI use.
- B matches the transmission chain: false information, fast reaction, correlated outflows or price moves.
Answer: B. Speed and correlation turn a false rumour into a possible run or market disruption.
Exam tips
- Expect applied scenarios. Name the threat first, then the control that matches it.
- When the question says stability or systemic, look for concentration, common vendors, herding or contagion in the answer.
- Be wary of options saying AI eliminates risk or only increases risk. Balanced, conditional statements are usually correct.
- Know the FSB and IMF 2024 AI readings are on the 2026 Current Issues list, so link cyber risk to their themes of third-party dependence and model risk.
Practice questions from The Financial Stability Implications of Artificial Intelligence
- A bank's AI fraud-detection model flags a much higher share of transactions from one customer group, though fraud rates are similar across g…
- A bank's market risk team observes that during recent volatility spikes, several AI-based trading desks across institutions sold the same as…
- A supervisor reviews a survey showing that 70% of banks in a jurisdiction rely on the same two cloud and AI model providers for credit scori…
- A supervisor notes that most banks in her jurisdiction use AI models from the same two cloud and model providers. Which vulnerability identi…
- A bank deploys a third-party generative AI model to summarise credit files for underwriters. The vendor does not disclose training data or m…
Cyber Risk and Malicious Use of AI: frequently asked questions
How do deepfakes threaten financial stability?
A single deepfake fraud is mainly an operational loss. Stability risk arises when fake content spreads fast, shakes confidence and prompts correlated withdrawals or price moves. It also weakens identity checks that many firms rely on.
Does AI increase or reduce cyber risk for banks?
Both. Attackers use AI to scale phishing, fraud and malware. Defenders use it for anomaly detection and monitoring. Net effect depends on controls, and firms must also manage the model and vendor risks that AI brings.
What is the difference between data poisoning and prompt injection?
Data poisoning corrupts the data used to train a model so it learns wrong patterns. Prompt injection feeds crafted inputs to a working model to make it behave in unintended ways.
Is this topic about calculations?
No. It is conceptual and case-based. You are expected to identify threats, transmission channels and suitable controls, not to compute a number.