
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
The National Bank of Romania (BNR) and the European Systemic Risk Board have issued preventive warnings about the potential for advanced AI models to amplify cyberattacks on the financial sector. While no incident has occurred, authorities stress increased vigilance and resilience against possible AI-enabled threats to banking infrastructure.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions AI systems (advanced AI models) and their potential to increase cyberattack risks, which is a plausible future harm scenario. However, it clearly states that no AI-driven incident or attack has occurred yet, and the warnings are preventive and macroprudential in nature. The focus is on monitoring, testing, and preparedness, not on an actual realized harm. Therefore, this event fits the definition of an AI Hazard, as it describes a credible risk of AI-related cyberattacks that could plausibly lead to harm in the future, but no incident has materialized. It is not Complementary Information because the main narrative is about the risk warning itself, not a response to a past incident. It is not an AI Incident since no harm has occurred. It is not Beneficial Use or Unrelated.[AI generated]