Banks will soon need to distinguish human customers and legitimate AI agents from malicious AI in real time, experts warn, after attacks on Taiwanese government websites demonstrated tactics that financial criminals could easily replicate.

In a “first-of-its-kind” breach disclosed this week by Israeli AI firm Dream, suspected China-linked hackers used up to eight autonomous AI agents to compromise at least 85 Taiwanese government user accounts last month. The agents — built using publicly accessible AI models — reportedly extracted thousands of personnel records before targeting Taiwan’s nuclear safety agency and at least seven energy companies.

Banks could be next, as financial criminals “inevitably adopt” similar AI-driven strategies in digital fraud, according to Jonathan Frost, director of global advisory for Emea at Israeli cyber security firm BioCatch.

His comments were echoed by Adrianna Fabijańska, chief executive and founder of Meridian Risk Intelligence, who said the tactics used in the Taiwanese government attacks — 24/7 persistence, tactical adaptation on failure and self-directed research demonstrated by AI agents — could be used for account takeover, co-ordinating money mule networks, synthetic identity creation and APP fraud.

“Fraud has always been constrained by human labour. However, agentic AI removes that constraint,” she said, adding that the economics of financial crime have just changed, with most bank fraud controls not geared towards addressing attacks at machine speed.

The Taiwanese government attacks “mirrored” a human hacker’s approach, with AI agents operating autonomously and, when blocked, adapting their strategy by researching and developing alternative tactics. But unlike humans, the AI likely worked continuously, scaled operations efficiently and did not require rest, said Frost.

What makes the Taiwan breach significant is not the target, it is the architecture, according to Fabijańska. She noted that guardrails were not broken: AI agents simply worked around them by framing the activity as “authorised penetration testing”.

She said this comes just months after AI firm Anthropic disclosed that suspected Chinese state actors had manipulated its large language model Claude to target more than 30 organisations.

Frontier AI models such as Anthropic’s Claude Mythos have “materially increased” the cyber risks banks face by allowing non-experts to more easily find and potentially exploit system or software vulnerabilities the same day.

Yet, according to Frost, the risks posed by AI agents capable of constantly learning and changing tactics cannot be fully addressed by traditional controls, especially those based on static, easily discovered thresholds.

“Banks will increasingly need to distinguish human customers and legitimate AI agents from malicious AI in real time,” he said, adding that institutions that can do so without disrupting legitimate customers will reduce losses and enhance the customer experience.

Fabijańska also highlighted “second-order” risks stemming from quantum computing, with autonomous AI agents able to make “harvest now, decrypt later” industrial-scale adversaries that can “hoover up” encrypted financial data to be unlocked once quantum computing matures.

“AI agents at the front door and quantum at the vault: [bank] boards need to be planning for both now,” she told The Banker.