Cybersecurity and fraud-risk leaders are urging stronger, enforceable security controls as the U.S. Department of the Treasury develops AI cybersecurity and risk-management guidance for the financial sector. Reported expectations for the forthcoming materials include coverage of governance, data practices, fraud, transparency, and digital identity, but analysts warned that non-mandatory “principles” risk being ineffective as AI-enabled attacks increase. Recommended guardrails include mandatory adversarial testing, maintaining an AI inventory, model monitoring, and real-time identity validation, with specific concern for threats such as data poisoning of training pipelines.
In parallel, financial institutions deploying agentic AI (systems that can initiate payments, approve transactions, or freeze accounts) are being warned that traditional authentication models assume a human user and do not adequately address autonomous or semi-autonomous agents. Fraud and AML specialists are calling for managed, revocable digital identities for AI agents—ideally with cryptographic proof—and continuous trust approaches that validate not just identity but delegated authority, detect “scope creep,” and preserve traceability to both the authorizing human and the executing agent.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity analysts and public-sector security leaders urged Treasury to make its forthcoming AI guidance mandatory and enforceable rather than principle-based. They warned that concrete guardrails such as adversarial testing, AI asset inventories, model monitoring, and real-time identity validation are needed as AI-enabled attacks accelerate.
The U.S. Department of the Treasury, through its Artificial Intelligence Executive Oversight Group, began preparing AI cybersecurity and risk-management guidance for the financial sector. The planned guidance is expected to address governance, data practices, fraud, transparency, and digital identity.
Datos Insights' David Barnhardt said financial institutions need managed, revocable digital identities and continuous trust models for agentic AI systems that can initiate payments, approve transactions, and freeze accounts. He argued traditional point-in-time authentication is insufficient for autonomous agents and predicted fraud will shift from credential theft toward direct compromise of AI agents.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.