Singapore’s financial sector is preparing for a version of cybercrime that moves faster, scales further and may not need much human involvement.
The Monetary Authority of Singapore and the Association of Banks in Singapore have established the AI-Driven Cyber and Technology Risk Taskforce, known as ACT. The initiative brings regulators, banks, payment operators and technology specialists into the same room to confront security threats created or amplified by frontier AI models.
This is not another broad committee discussing responsible AI in abstract terms. ACT is expected to share real cybersecurity use cases, test AI-enabled defence tools and develop practical guidance for financial institutions. That difference matters.
Frontier AI Is Changing the Shape of Cyberattacks
AI has already made routine digital work faster. The same efficiency is available to attackers. According to the joint announcement, frontier AI systems can rapidly identify vulnerabilities, automate attacks and operate at a scale that creates serious concerns for the financial sector. A weakness that once took hours of manual investigation could potentially be discovered, tested and exploited far more quickly.
Banks are tempting targets. They hold money, identity data, transaction records and access to national payment infrastructure. They also depend on complicated networks of cloud platforms, internal software, payment rails and third-party technology providers.
One compromised system can become more than an IT problem. It can disrupt payments, expose customer information or create a wider confidence shock. Singapore’s response is built around a fairly blunt conclusion: individual institutions cannot deal with rapidly evolving AI-enabled threats in isolation.
Singapore’s Biggest Financial Players Join the Taskforce
The Singapore AI cyber risk taskforce includes the Monetary Authority of Singapore, the Association of Banks in Singapore, DBS, OCBC and UOB.
The Singapore Exchange, Network for Electronic Transfers and Banking Computer Services are also participating. Members have been working together since May 2026, although the initiative was formally announced on July 28. That membership gives ACT access to several sides of the financial system at once.
Commercial banks bring frontline experience with fraud, account security and customer-facing infrastructure. SGX contributes a capital-markets perspective. NETS and BCS represent systems that sit closer to payments and shared banking technology. It is a practical mix, not a decorative one.
The Taskforce Will Test AI Against AI
ACT will concentrate on three areas: industry collaboration, capability development and new cybersecurity guidance.
The collaboration work will allow financial institutions to share AI security use cases and lessons without every organisation repeating the same experiments behind closed doors. The taskforce will also work with cybersecurity and AI specialists outside the core membership. The more interesting part may be the proof-of-concept trials.
Members plan to explore and validate advanced AI-enabled security tools against an evolving threat landscape. The announcement does not identify specific products or models, but likely areas could include anomaly detection, attack simulation, automated threat analysis and faster identification of suspicious behaviour. That is an inference from the taskforce’s stated remit, not a confirmed list of trials.
The third area is guidance. ACT intends to develop new measures, controls and potential solutions that help financial institutions detect, prevent and respond to sophisticated AI-enabled attacks. Trials produce evidence. Guidance turns that evidence into something banks can actually use.
Singapore Is Treating AI Risk as a Shared Infrastructure Problem
Most public discussion about artificial intelligence in banking has centred on chatbots, productivity, compliance automation and customer service. Cybersecurity changes the conversation.
The threat is not limited to whether a bank’s own AI model produces a wrong answer. External attackers can use AI to scan systems, create convincing impersonations, write malicious code or coordinate attack activity more efficiently. Smaller institutions and vendors may become entry points into larger financial networks. ACT’s structure suggests Singapore sees this as a system-wide resilience issue rather than a narrow model-governance exercise.
Vincent Loy, MAS assistant managing director for technology and chief technology officer, said frontier AI is increasing the “severity, scale and sophistication” of cyber threats. He argued that the sector needs to respond urgently and through close collaboration. The language is unusually direct for a regulatory announcement. No victory lap. No claim that the problem has been solved.
What Happens Next Will Matter More Than the Launch
Taskforces are easy to announce. Useful outcomes are harder. The real test will be whether ACT produces defensive tools and guidance that can keep pace with the technology it is trying to contain. AI security advice can age quickly. A control designed around today’s attack methods may be less effective once models become more autonomous or easier to deploy.
There is also the question of information sharing. Banks have strong reasons to collaborate on cyber defence, but they must still manage confidentiality, customer privacy and commercially sensitive security data. Singapore has at least chosen to start before AI-enabled attacks become entirely routine.
The country’s financial institutions are not waiting for a single catastrophic incident to force cooperation. They are building the coordination layer now, testing tools while the threat landscape is still taking shape. That may turn out to be the most important part of ACT. Not the acronym. Not the announcement. The head start.

