For the Commonwealth Bank, its upcoming full-year results meeting in two weeks doubles as a critical checkpoint on cyber readiness, not just financial performance. Other major rivals schedule similar board sessions in the coming weeks and each confronts the same dilemma of how to protect sprawling, interconnected systems from attackers supercharged by generative artificial intelligence.
Cyber incidents that once ranked behind credit, market and conduct risk have shifted into the front rank of board priorities. The threat is no longer theoretical and is becoming the problem that defines the operating environment for Australia’s largest financial institutions.
Powerful AI models accelerate that shift. Anthropic’s Mythos system, designed to rapidly uncover long-standing software vulnerabilities, shows how next-generation tools can unearth weaknesses that sat unnoticed for decades.
Companies now assume adversaries will soon wield tools of similar capability, if they do not already. That prospect forces a rethink of old playbooks that relied on slower, more manual detection and patching cycles.
What looked robust even a year ago can be dangerously sluggish when AI reduces the time between discovery and exploitation. Legacy incident-response processes highlight the gap.
Many banks still require senior executives to authorise taking down a compromised system before a breach can spread, a workflow that once felt prudent and controlled. In practice, those decisions could take a full day if decision-makers were travelling, unavailable or deep in deliberation about business impacts.
Such delays were tolerable when attacks unfolded over hours or days, not milliseconds. AI-enhanced threats now pressure boards to delegate authority, automate containment steps and rewrite governance so response times match the speed of the attackers.

