The Morning Note
Bank breaches hit Korea as regulators start flagging AI risk
In the past week, global and regional regulators began flagging AI as a risk to finance, and South Korea's banks were hit by a string of breaches in which authorities say AI tools may have been used.
Korea's breach spreads to nonbanks
President Lee Jae Myung ordered a thorough investigation after breaches spread from Shinhan Bank to KB Kookmin Bank, Hana Bank and BNK Busan Bank, then to nonbank institutions: Yegaram Savings Bank, where about 40,000 customers were affected, and Hyundai Capital, where data on 146 housing loan agents was exposed. Regulators convened an emergency meeting with chief executives across banks, insurers, card companies, savings banks and fintechs, and the FSC chairman said the industry must remain on "the highest alert."
Basel reviews its AI risk categories
The Basel Committee on Banking Supervision said after it met in Indonesia on 28-29 September that AI has the potential to amplify operational vulnerabilities, including from cyber attacks and correlated dependencies in the financial system. It agreed to review the adequacy of its operational risk loss categories, with a focus on cyber risk and AI developments.
ASEAN+3 feels the exposure
AMRO, the ASEAN+3 regional surveillance body, said in its Financial Stability Report that a sharp repricing of AI-related assets could trigger broader market corrections, forced deleveraging and tighter credit conditions across the region. It still raised the region's 2027 growth forecast to 4.1 percent, pointing to stronger AI-related exports and investment.
Tokyo ties AI to rate risk
Bank of Japan deputy governor Shinichi Uchida said the AI boom, "a big positive demand shock," may have eased financial conditions by boosting demand and asset prices, but warned there is a risk of correction if profits do not follow. He said bond issuance by AI-related firms is pushing up long-term interest rates, and the BOJ has flagged AI-related demand as a factor that could push underlying inflation above its 2% target.
Malaysia drafts a risk-based AI law
Malaysia's Digital Minister Gobind Singh Deo told the Dewan Rakyat that high-risk AI systems will face stricter safety controls, testing and human oversight under a new AI Bill expected to be tabled early next year. The Bill, still being drafted, will adopt a risk-based approach, with controls and obligations assessed by an AI system's potential harm. For increasingly powerful and autonomous AI systems, he said safety controls, testing and human oversight "must be strengthened before their use is expanded."
What this means for risk teams
Treat AI exposure as a formal risk category before a breach forces the question. Risk and compliance teams should check whether AI incidents already fall under their operational-risk, credit-risk or compliance categories, or whether they would simply slip through the gap.
The Morning Note, by email
The AI-in-finance stories that matter, before work
One short email each morning, readable in under three minutes. Free, and you can leave anytime.