New York State Financial Regulators Issue AI Cybersecurity Guidance

A letter to all industries.

An Article Review

As many businesses evaluate the risks and benefits of AI, so are lawmakers and regulatory agencies.  Among those are New York state, which Reuters reports recently issued its own guidance to financial institutions concerning the use of AI in the form of an “Industry Letter” issued by the Department of Financial Services.

While the guidance does not include any new requirements for financial institutions, it outlines how existing frameworks can be adapted to address AI risk in various areas. One such area is social engineering, where AI could be used to generate more sophisticated email and text phishing campaigns or even impersonate the voice or video image of a targeted person.  Other areas of note outlined by the letter include malware that could use AI to evade detection from endpoint security software, supply chain attacks and the general lower barrier to entry AI offers criminals when attempting to execute an attack.

Joe and Jane ISO watching a robot, "AI", stuck in a glass cage

The threats posed by AI may be significant, but New York’s decision to not include new requirements with its guidance can be seen as a good sign: For organizations that already have a robust security posture, adapting to AI risk probably won’t require major changes to policies or procedures.

All is not negative when it comes to AI however, as the guidance points out potentially beneficial uses of AI such as its ability to sift through large amounts of data quickly.  This could prove useful when it comes to analyzing user behavior, identifying suspicious entries in log files and detecting anomalies.

Regardless of whether AI is a friend or a foe one thing is certain: while New York may be among the first to issue such guidance, they won’t be the last.

Original article by Diana M. Eng and Susan Kuruvilla writing for Reuters

This Article Review was written by Vigilize.


Matt Jolley is the current Vigilize, he is also the recipient of the 2023 Cyb3rP0e+ designation!

To see more content like this in your inbox, sign up for our newsletter here!

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts

The Magnificent Seven 2023

Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome t...

“AI Phishing” – Awareness Poster

Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers!Check out posters.infotex.com for th...