71% of Central Banks Already Use AI. 19% Have a Strategy for It.
The Bank for International Settlements ran an ad hoc survey through the Global Cyber Resilience Group in January 2024, gathering 32 responses from cyber security experts at major central banks. Seventy-one percent of them answered yes to a single question: "Are you currently using AI systems in your organisation?" (Bank for International Settlements, 2024, p. 8, n. 9). Note what that question does not ask. Not generative AI specifically, and not inside the security function — the paper reports the figure as gen AI adoption, which is a looser reading than its own instrument supports. The number is real; it is a measure of AI in the organisation, not of AI in the SOC. Another 26% planned to adopt it within one to two years, which led the authors to observe that the adoption rate "could therefore approach 100% in the near term" (Bank for International Settlements, 2024).
Nineteen percent had a concrete strategy for adopting and integrating it. Twenty-three percent had none at all. The remaining 55% described their strategy as "in development" (Bank for International Settlements, 2024).
Those two paragraphs describe central banks — the most governance-heavy institutions in finance, the ones whose entire operating culture is built on documented control. If adoption outran governance there, the pattern is not a story about one careless sector.
The spine: the gap is real, but reading it as recklessness is the misread. Look at which risks those experts actually named — social engineering, zero-day attacks, and unauthorised data disclosure. Not hallucination. Not bias. Not model explainability. Every one of those belongs to a control family that a regulated institution already operates. The governance work that matters is not writing a parallel AI control set. It is re-scoping the controls you have for a tool that writes convincing prose.
What the experts named, and what they did not
The BIS paper is direct about where concern sits: "Risks related to social engineering and zero-day attacks as well as unauthorised data disclosure are of highest concern" (Bank for International Settlements, 2024). Elsewhere it lists the specific threat set as "AI-generated social engineering, zero-day attacks and malware attacks for data leakage."
Read that against the way generative AI risk is usually discussed in a governance forum. The standing agenda is model quality — does it hallucinate, can we explain it, is the training data biased, who signs off on the output. Those are real questions and they belong in a model risk framework. They are simply not the questions the people running security at central banks put first.
Adoption ran ahead of strategy, at central banks
- Already use AI systems71%
- Strategy still "in development"55%
- Plan to adopt within 1–2 years26%
- No strategy at all23%
- Have a concrete strategy19%
The distinction matters because it changes who owns the work. A hallucination problem routes to model risk and data science. A social-engineering problem routes to identity, awareness training and email security. A data-disclosure problem routes to data loss prevention and access control. Those second and third teams have been operating mature controls for years — controls that were scoped, tested and audited in a world without a machine that writes fluent, personalised English on demand.
The standard-setter says the same thing, more plainly
Eighteen months after the BIS survey, the G7 Cyber Expert Group published its own statement on the subject. The CEG advises G7 Finance Ministers and Central Bank Governors on cyber security policy, so it is speaking to precisely the population the BIS surveyed.
It names the same threat: "Generative and agentic AI can generate hyper-personalized phishing messages and deepfakes, complicating detection efforts" (G7 Cyber Expert Group, 2025).
And its recommendation, stated as a bullet rather than buried in an annex, is this: "Integrate AI-related risks into existing risk management processes" (G7 Cyber Expert Group, 2025).
That is a standard-setter telling the financial sector not to build a parallel regime. It is also the least quoted line in a document that gets quoted for its threat list.
Why this lands differently in Canada
Canadian federally regulated financial institutions have a dated instrument coming. OSFI Guideline E-23, Model Risk Management, covers artificial intelligence and machine learning models explicitly, and it takes effect on 1 May 2027 (Office of the Superintendent of Financial Institutions, 2027).
E-23 is routinely quoted as though it already binds. It does not, and the difference is the entire planning window. But notice what E-23 governs: models. It is a model risk instrument, and it is the right instrument for model risk. The two risks the BIS respondents ranked highest are not model risk. An institution that reads E-23 as its complete answer to generative AI will have governed the part its peers ranked below the part they worried about most.
The same institutions already run B-13 for technology and cyber risk, in force since 31 July 2022, and E-21 for operational risk and resilience, in force since 22 August 2024 (Office of the Superintendent of Financial Institutions, 2022, 2024). Those are where a phishing control and a data-disclosure control live. They are in force now.
What I would actually check first
This is the part that costs nothing and gets skipped. Before an AI governance framework is drafted, four existing controls need re-reading against a specific question: were you scoped for an attacker who writes better than your staff?
Your phishing awareness programme almost certainly still teaches spelling errors and odd grammar as detection cues. That advice was correct for a decade and is now actively harmful, because it trains people to trust well-written messages. Your email security stack was tuned on signatures and sender reputation, neither of which degrades when the prose improves. Your data loss prevention rules were written for files leaving the perimeter, not for text pasted into a browser window. And your access reviews assume a human reads what they retrieve, at human speed.
None of those four is an AI control. All four are the controls that the risks in the BIS survey actually land on.
Where Sagentix fits, and where it does not
Sagentix prepares organizations for independent assessment. The party who reviews the work is always someone else — a certification body, an examining firm, a regulator, or the department that grants the authority to operate. That separation is the point: an adviser who also assured the work would be answering the first question an auditor asks, in the wrong direction.
What that looks like in practice for this problem: a control-scoping pass that maps your existing B-13 and E-21 control set against the threat list the BIS and the G7 CEG actually name, and produces the evidence package an examiner reads — not a new framework document. The research library behind it runs to 1,414 catalogued artifacts, every deliverable passes an 18-check quality gate before it reaches you, and full engagements run six to eight weeks at CA$4,500 to CA$45,000 depending on scope. Phase 1 carries a money-back guarantee, subject to terms.
Three ways to act on this
Do it yourself, this week, for nothing. Pull your phishing awareness curriculum and find every place it teaches grammar or spelling as a detection cue. Pull your DLP rule set and find every rule keyed to file movement rather than text entry. That is two meetings and it will tell you how much of a gap you actually have. Most organizations find more than they expected, which is a useful and free finding.
Have your second line do the mapping. If you have an independent risk function with capacity, the exercise above scales into a proper control-scoping review — the BIS threat list on one axis, your in-force B-13 and E-21 controls on the other, and an honest column for "scoped before generative AI existed." No external help required. The constraint is usually capacity, not capability.
Bring in an adviser who does not also assure the result. Worth it when the output has to survive an examiner rather than an internal committee, when you need the evidence package rather than the finding, or when the second line is already fully committed. Ask any adviser you evaluate whether they or an affiliate hold an accreditation as a certification body or assessment firm. If the answer is yes, they cannot be independent of the work they are recommending.
References
- Bank for International Settlements. (2024, May 23). Generative artificial intelligence and cyber security in central banking (BIS Papers No. 145). Bank for International Settlements.
- G7 Cyber Expert Group. (2025, September). G7 Cyber Expert Group statement on artificial intelligence and cybersecurity. U.S. Department of the Treasury.
- Office of the Superintendent of Financial Institutions. (2022). Guideline B-13: Technology and cyber risk management (effective 31 July 2022). Government of Canada.
- Office of the Superintendent of Financial Institutions. (2024). Operational risk management and resilience — Guideline (E-21) (effective 22 August 2024). Government of Canada.
- Office of the Superintendent of Financial Institutions. (2027). Guideline E-23 — Model risk management (2027) (effective date 1 May 2027). Government of Canada.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.