Artificial intelligence is one of the major issues of our time. On the one hand, it holds the promise of making complex workflows and multi-layered processes more efficient and systematic. On the other hand, it also brings greater challenges: the same technology is available to attackers. Regulatory requirements and the risk of cyber threats – which have taken on a new urgency with AI – demand consistent and sophisticated security strategies. Key factors here are control over data flows and compliance with data protection and security standards. In addition to prevention and defence, the focus today is increasingly on ensuring that systems remain operational under stress and can be restored in the event of an emergency.
The situation report published by the Federal Office for Information Security (BSI) in November 2025 illustrates how this threat landscape is changing: the situation remains tense; phishing, fraud and identity theft continue to be among the key threats. AI has an impact in two ways. It lowers the barrier to carrying out deception attacks. Fraudulent messages are linguistically flawless and tailored to the individual, whilst voices and video footage can be replicated to look deceptively real as so-called ‘deepfakes’. On the other hand, however, AI also supports fraud prevention by analysing transactions in real time, identifying vulnerabilities more quickly, detecting anomalies and new fraud patterns, and thus improving prevention systems and risk assessment.
A regulatory framework for this is provided, amongst other things, by DORA, MaRisk and the EU AI Regulation (AI Act), which sets out risk-based requirements for the development, deployment and use of AI systems. These requirements place considerable demands on banks, but also have transformative potential, as they enable the establishment of robust structures, resilient processes and effective control mechanisms. Cyber resilience is not achieved through individual technologies alone, but through a robust architecture, transparency and clear lines of responsibility.