AI Governance

When AI governance meets cyber defense: the convergence banks can't ignore

NIST's AI cybersecurity profile gives banks one vocabulary for a risk that used to fall between two org charts. One program, not two.

By Jonas Osman AbdelghafourPublished 29 July 2026

For years, banks have run AI governance and cybersecurity as separate programs with separate committees, separate frameworks, and separate budgets. That separation is collapsing, and the regulators pushed it. The OCC's risk reporting now describes AI as significantly transforming the cyber threat landscape — lowering barriers to entry for attackers, accelerating attacks, industrializing fraud — while NIST's Cybersecurity Framework Profile for Artificial Intelligence gives institutions a common structure for a problem that used to fall between two org charts.

The NIST profile's three-part framing is usefully blunt. Secure the AI systems you deploy. Use AI to strengthen your own defenses. Defend against AI-enabled attacks from others. Every bank has work under all three headings, and the honest ones admit the third is moving fastest: deepfake-enabled social engineering and machine-speed vulnerability discovery do not wait for a bank's AI strategy to mature.

Securing what you deploy An AI system is software plus a model plus data pipelines plus, increasingly, agency — and each element widens the attack surface. Prompt injection turns a helpful assistant into an exfiltration channel. Data poisoning corrupts a model before it ever reaches production. Access sprawl lets a chatbot in one business line reach data it should never see — the exact "data boundary" question US examiners now ask in routine exams. Treating these as exotic AI risks is a category error; they are application security, identity, and data-loss prevention wearing new clothes, which is precisely why NIST anchored its profile to the existing cybersecurity framework rather than inventing a parallel one.

The practical implication for control owners: map every deployed AI system into your existing security architecture reviews, threat models, and penetration testing scope. An AI system that has never been red-teamed is an untested internet-facing application by another name.

One program, not two The organizational fix matters more than any single control. Put AI risk and cyber risk in the same room: shared threat intelligence, shared incident taxonomy, shared tabletop exercises where the scenario is an AI-enabled attack on an AI-dependent process. Extend third-party security assessments to model suppliers. And report both under one operational-resilience umbrella to the board, because directors should not need to reconcile two dashboards to understand one converged risk.

Frameworks converge slowly; attackers converged already. The banks that fuse these disciplines now will meet the coming supervisory guidance — and the next attack — with one coherent answer instead of two partial ones.

Related reading - [Every bank exam is now an AI exam](/insights/ai-bank-examinations-occ-fed-jonas-osman-abdelghafour) - [Generative AI just fell out of model risk guidance](/insights/generative-ai-model-risk-management-gap-jonas-osman-abdelghafour) - [You didn't build it, but you own it: third-party AI risk comes of age](/insights/third-party-ai-vendor-risk-financial-services-jonas-osman-abdelghafour)

See also Banking Risk, Enterprise Risk and Model Risk.

About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.

Frequently asked questions

What should risk leaders know about securing what you deploy?

An AI system is software plus a model plus data pipelines plus, increasingly, agency — and each element widens the attack surface. Prompt injection turns a helpful assistant into an exfiltration channel. Data poisoning corrupts a model before it ever reaches production. Access sprawl lets a chatbot in one business line reach data it should never see — the exact "data boundary" question US examiners now ask in routine exams. Treating these as exotic AI risks is a category error; they are appli...

What should risk leaders know about one program, not two?

The organizational fix matters more than any single control. Put AI risk and cyber risk in the same room: shared threat intelligence, shared incident taxonomy, shared tabletop exercises where the scenario is an AI-enabled attack on an AI-dependent process. Extend third-party security assessments to model suppliers. And report both under one operational-resilience umbrella to the board, because directors should not need to reconcile two dashboards to understand one converged risk.

What should risk leaders know about related reading?

See also [Banking Risk](/expertise/banking-risk), [Enterprise Risk](/expertise/enterprise-risk) and [Model Risk](/expertise/model-risk).

What should risk leaders know about about the author?

Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.