HK and Singapore's regulators both warned this. Top financial watchdog just confirmed it

Insurers on alert as frontier AI flagged as most immediate threat to global financial system

HK and Singapore's regulators both warned this. Top financial watchdog just confirmed it

Cyber

By

On 2 June 2026, the Hong Kong Monetary Authority (HKMA) issued a circular to every authorised institution in the territory, warning that the recent emergence of increasingly capable frontier AI models "could mark a step change in the global cyber risk landscape." The regulator pointed specifically to AI's growing capacity to independently identify and exploit zero-day vulnerabilities, a capability that could commoditise cyber attacks by reducing the need for specialist human expertise.

Singapore's regulator was thinking along the same lines: the Monetary Authority of Singapore had already been coordinating with the country's banks on the same threat since May.

Three months later, Andrew Bailey has just made almost the identical point to the G20. Writing in his capacity as chair of the international Financial Stability Board (FSB), the Bank of England governor named frontier AI's impact on cyber risk as the most immediate threat to the global financial system.

A regional banking regulator and the world's top financial stability body, converging on the same warning within a single quarter. For Asia's insurance markets, that's worth sitting up for.

A region already building defences

The HKMA hasn't stopped at the circular. It's establishing a dedicated Task Force on AI-Driven Cyber Risks to bring together financial authorities, institutions and cyber experts, and is developing a Cyber Resilience Testing Framework with the Hong Kong Association of Banks, targeting an initial test run with selected institutions in late 2026.

Singapore's regulator has moved on a similar timeline. The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore announced their own AI-Driven Cyber and Technology Risk Taskforce on 28 July, bringing together MAS, the banking association and major institutions including DBS, OCBC, UOB and the Singapore Exchange, with members reportedly already working together since May.

"Frontier AI is increasing the severity, scale and sophistication of cyber threats," said Vincent Loy, MAS's assistant managing director for technology and chief technology officer, at the announcement. MAS separately described frontier AI's ability to rapidly identify and exploit vulnerabilities and automate attacks at scale as a serious concern for the financial sector.

On the same day as the HKMA circular, Hong Kong's Securities and Futures Commission issued a parallel circular to licensed firms urging enhanced cybersecurity measures against AI-enabled attacks. That coordinated, cross-regulator response, echoed almost exactly by MAS and ABS in Singapore, mirrors the concentration-risk argument Bailey later made to the G20 about a global financial system leaning on a small number of shared technology providers.

What the region's own data shows

INTERPOL's mapping of Southeast Asia's cybercrime ecosystem, spanning Indonesia, the Philippines, Vietnam, Thailand, Malaysia, Singapore and Australia, has documented a pattern of AI-generated, real-time video impersonation now being used in high-value fraud. In one case, a Hong Kong employee transferred US$25 million after deepfakes impersonated company executives on a video call.

In another, a Singapore finance director narrowly avoided losing more than US$499,000 in an almost identical Zoom-based attack. "While AI has not yet emerged as a stand-alone driver of cyber insurance claims, it is already amplifying existing threats, from social engineering and deepfake phishing," Conor Keating, head of cyber in Asia at Willis, said.

The incident behind the warnings

Both the HKMA and the FSB are writing against the backdrop of a real event. In July, OpenAI disclosed that a pair of its models had broken containment during an internal cybersecurity evaluation, with no human steering the attack, and gone on to compromise systems belonging to Hugging Face using a previously unknown flaw, purely to obtain the answers to the benchmark they were being tested against. OpenAI called it an unprecedented cyber incident.

What it means for the region's insurers

Gallagher's 2026 AI Adoption and Risk Benchmarking Survey found that one in five insurance professionals reported that a client had already experienced losses tied to AI risk, often because an AI agent carried out an action directly, with no phishing email or stolen credential involved for underwriters to point to.

Cyber ranks first among risk concerns in every major Asia-Pacific market, according to Allianz's 2026 Risk Barometer, and regulators from Hong Kong to the FSB are now converging on the view that AI is why that concern keeps rising. For brokers and underwriters across the region, that points toward closer scrutiny of policy wording where a loss originates from an AI system's own actions, and continued pressure to price for concentration risk across shared cloud and AI providers rather than treating AI exposure as a subset of conventional cyber cover.

Keep up with the latest news and events

Join our mailing list, it’s free!