BSP urges stronger bank cyber defenses against AI risks
MANILA — The Bangko Sentral ng Pilipinas is urging banks and other BSP-supervised institutions to strengthen their cybersecurity systems as advances in artificial intelligence increase the speed, scale, and sophistication of potential attacks.
The guidance seeks to protect consumers from attacks that could compromise financial systems or disrupt access to payments, transfers, deposits, and other essential services, particularly as Filipinos increasingly rely on digital transactions.
Digital channels accounted for 57.4% of the Philippines’ monthly retail payment volume and 59% of its value in 2024, with monthly digital transactions reaching about USD 136 billion.
The BSP warned that frontier AI systems could identify software vulnerabilities, generate possible routes for exploitation, and execute multi-stage cyberattacks with minimal human intervention.
Although access to such systems remains restricted and controlled, their emergence points to more adaptive and scalable threats that malicious actors could eventually use against financial institutions, third-party service providers, and critical infrastructure.
BSP Deputy Governor Lyn I. Javier said, “Cybersecurity is essential to maintaining trust in the financial system. By encouraging financial institutions to strengthen their cyber defenses and preparedness, we help protect consumers, safeguard financial services, and support confidence in an increasingly digital economy.”
Memorandum No. M-2026-034, issued July 6, 2026, outlines six recommendations for managing emerging risks arising from frontier AI systems.
The BSP first advised institutions to maintain accurate and updated inventories of externally accessible assets, cloud services, identities, critical applications, and software dependencies, including third-party and open-source components.
Institutions were also encouraged to strengthen credential security, implement multi-factor authentication for critical systems and assets, enforce least-privilege access, and establish device-hardening standards.
The central bank recommended reducing institutions’ attack surfaces through micro-segmentation, zero-trust security controls, faster patching, upgrades or replacements for end-of-life systems, and limits on unnecessary internet exposure.
For administrative and privileged accounts, the BSP recommended hardware security keys using FIDO2 or WebAuthn, smart cards, or hardware-backed certificate-based authentication.
The memorandum also called for discontinuing password-based and SMS- or push-based authentication for administrative and privileged access to reduce exposure to AI-driven social engineering.
Financial institutions were advised to adopt AI-enabled cybersecurity tools for patch management, continuous threat hunting, exposure management, and security orchestration.
The BSP also recommended virtual patching to block possible routes of exploitation in critical systems before the underlying software can be updated.
Institutions should review and strengthen their incident-response capabilities, business continuity management frameworks, and business continuity plans to prepare for AI-enabled threats and maintain uninterrupted financial services during cyber incidents.
The recommendations are consistent with the risk-based information technology and cybersecurity framework under Section 148 of the Manual of Regulations for Banks and Sections 147-Q, 145-S, 142-P, and 126-N of the Manual of Regulations for Non-Bank Financial Institutions.
The BSP also recommended that supervised institutions formally develop AI governance frameworks proportionate to the nature, extent, scale, complexity, and materiality of their AI systems, as well as their operational complexity and risk profiles.
These frameworks should follow the principles under BSP Memorandum No. M-2026-031, dated June 24, 2026.
The guidance complements the BSP’s existing cybersecurity and AI governance measures while reinforcing responsible AI use and sound risk management in the financial sector.
The memorandum is available through the BSP’s official website.
Comments (0)
LEAVE A REPLY
No comments yet
Be the first to share your thoughts!
Related Articles

Capiz launches first battery energy storage system
PANITAN, Capiz — Capiz launched its first battery energy storage system on Thursday, July 23, in Barangay Timpas, Panitan, in a move expected to improve power reliability across the province and the Panay subgrid. The mechanical completion ceremony marked a major construction milestone for the 20-megawatt, 40-megawatt-hour Panitan Battery Energy Storage


