
The Bay Street financial district in Toronto. Canada’s banking regulator says the rapid pace of advance AI models pose fast-moving threats to the sector.Nathan Denette/The Canadian Press
Canada’s banking regular is warning that advanced AI models are amplifying cybersecurity and technology sovereignty risks in the country’s financial system as the technology rapidly accelerates.
The Office of the Superintendent of Financial Institutions highlighted AI risks in its fall update on the biggest threats facing the banking sector. The regulator said the pace of AI development has “accelerated materially” since it unveiled its annual risk outlook in April.
The rate of change in frontier models is “unprecedented,” and the time between discovering a vulnerability and potential exploitation of that gap has shortened, reducing the time financial institutions have to identify the risk and address it, OSFI said.
“In an era of advancing AI capabilities, resilience is a competitive advantage,” OSFI superintendent Peter Routledge said in a statement. “Financial institutions that harness AI responsibly while managing cyber, technology, and third-party risks will position themselves to thrive in a complex environment.”
OSFI superintendent Peter Routledge, pictured in 2023, says the banking regulator is planning to implement a safety code on AI threats to the banking sector.Dave Chan/The Globe and Mail
On Wednesday, Mr. Routledge told a room of financial institution risk professionals that the regulator is planning to implement a “safety code” on AI as threats from AI agents and Anthropic’s powerful Claude Mythos model escalate risks among the country’s banks.
While the initiative is still in its earlier stages, he said guidelines could consist of broad, high-level standards that provide a basic level of safety and protection for the financial system, while also establishing a “wide perimeter for innovation.”
Canadian banks been increasingly conducting AI research and implementing tools that boost productivity and generate revenue. On Tuesday, AI benchmarking platform Evident ranked all of Canada’s five biggest banks in the top 30 of a list of 50 global financial institutions on AI adoption.
But advances in AI also increase the speed and sophistication of cyber-attacks, which could allow weakness that seem minor to be exploited for high-impact attacks, OSFI said.
“Frontier AI models can locate and exploit more vulnerabilities, enabling adversaries to launch coordinated, large-scale attacks across systems, applications, and third-party ecosystems,” the regulator said in the update.
Risks to Canada’s technology sovereignty are also on the rise. The development of frontier models is dominated by a small group of providers, and many are concentrated outside of Canada.
Escalating geopolitical tensions, including technology restrictions and policy actions in foreign markets, could affect access to technology and services for Canada’s institutions, OSFI said.
OSFI has been ratcheting up its oversight of AI in recent years. In 2023, the regulator and the GRI released a report on the implications of AI on financial services institutions. OSFI has also previously cited AI as a key threat in its annual risk outlook.
Earlier this year, OSFI unveiled two technology risk bulletins on how generative and agentic AI and frontier AI are boosting risks and ways to strengthen resilience against vulnerabilities.
More Stories
Food inflation has been tame recently. That might not last
Cold Lake First Nations push for judicial review of Pacific Link pipeline designation
General Fusion achieves technical milestone in plasma heating