The Financial Sector Supervisory Commission (CSSF) expects all members of the management body to put in place appropriate governance arrangements to better manage the risks associated with cutting-edge AI models, to ensure close monitoring of these models, and to strengthen their organisation’s resilience to threats posed by artificial intelligence. The regulator justifies this approach by citing the acceleration and proliferation of cyberattacks made possible by AI. The risks no longer stem solely from new threats, but also from the speed with which already known vulnerabilities can be exploited. Until now, when a vulnerability was discovered, organisations had sufficient time to assess their exposure, test patches and deploy them before the vulnerability was exploited on a large scale. This reaction time is now disappearing; the race against the clock has begun.
The regulator urges organisations to review their priorities: rather than addressing all vulnerabilities indiscriminately, resources should be focused on those that pose a real risk of exploitation, particularly where they relate to systems exposed to the internet or already under active attack. For the supervisor, it is no longer simply a matter of preventing intrusions, but also of minimising the consequences when an incident does occur. A successful attack must not be allowed to escalate into a major crisis affecting the organisation’s operations and data. Prevention is better than cure, as the regulator implicitly reminds us.
Priorities include reducing the attack surface, risk-based patch management, securing the software development chain, network segmentation, the roll-out of Zero Trust and multi-factor authentication, and strengthening proactive detection capabilities.
Detecting vulnerabilities at an early stage
However, some organisations do not yet have the necessary management tools, the supervisor notes. “The time between the discovery of a vulnerability and its exploitation is approaching zero,” the CSSF summarises. The findings are clear: vulnerability assessments remain inadequate, patches are deployed late, and the automation of security checks remains limited.
AI is not only used for attacks. It has also become a tool for strengthening defences. The regulator is encouraging financial institutions to use it to detect vulnerabilities right from the software development stage, to assist security operations centres in analysing alerts, and to identify abnormal behaviour more quickly.
In addition to the technical recommendations, the CSSF urges supervised entities to closely monitor the work of international bodies on AI, in particular the warning from the European Systemic Risk Board on systemic cyber risks associated with cutting-edge AI models and the Financial Stability Board’s consultation on best practices for the responsible adoption of AI.


