The rapid emergence of frontier artificial intelligence has fundamentally altered the mechanics of financial cyber defence. Where traditional cyber risk management focuses on static vulnerability patching, machine learning capabilities now enable automated systems to discover security flaws, orchestrate complex intrusions, and execute targeted social engineering on a global scale.
In response to this systemic exposure, the Monetary Authority of Singapore (MAS) and the Association of Banks (ABS) have established the AI-Driven Cyber and Technology Risk Taskforce (ACT).
While publicly announced on 28 July 2026, working groups under the ACT framework have been actively convening key financial market infrastructure participants since May 2026.
Institutional Architecture and Operational Scope
Rather than operating as a purely regulatory advisory panel, ACT integrates public sector oversight with operational market infrastructure.
The taskforce brings together senior leadership across cybersecurity, artificial intelligence, and technology risk from eight founding institutions:
- Public Supervisory & Industry Oversight: Monetary Authority of Singapore (MAS) and The Association of Banks in Singapore (ABS).
- Banking Groups: DBS Bank, Oversea-Chinese Banking Corporation (OCBC), and United Overseas Bank (UOB).
- Market Infrastructure & Settlement Systems: Singapore Exchange (SGX), Network for Electronic Transfers (NETS), and Banking Computer Services (BCS).

The joint mandate published by MAS and ABS structures the ACT taskforce's agenda across three core operational pillars: driving industry collaboration through secure threat intelligence and use-case sharing, accelerating capability uplift via joint proof-of-concept trials for defensive AI tools, and formulating benchmarked guidance to standardise detection, prevention, and incident response protocols against automated cyber threats.
As noted by Mr Vincent Loy, Assistant Managing Director (Technology) and Chief Technology Officer at MAS, the expanding severity and speed of frontier AI threats require an urgent, collaborative defence response across public and private channels. Mrs Ong-Ang Ai Boon, Director of ABS, further highlighted that sustained sector-wide alignment and governance are essential to maintaining resilience as emerging technologies alter the risk landscape.
Alignment with Singapore’s Broader Technology Risk Mandates
The creation of ACT represents the operational layer of a broader supervisory trajectory enforced by MAS throughout 2026.

Earlier in April 2026, MAS issued general advisory guidance directing financial institutions to bolster system perimeter security. This was escalated in July 2026 by an explicit supervisory requirement for major financial institutions to integrate AI-assisted "red teaming" using automated algorithms to simulate sophisticated attack strategies against critical, public-facing digital portals.
In addition, central bank leadership confirmed that upcoming supervisory expectations will require major institutions to submit formalised action plans addressing automated vulnerability patching, pre-deployment code testing, and system recovery resilience during operational outages. These initiatives run parallel to planned supervisory expectations on quantum-resilient cryptography scheduled for late 2026, aiming for total sector compliance before 2030.
Strategic Implications for Risk and Compliance Teams
For chief risk officers, compliance directors, and technology-risk practitioners, the deployment of ACT introduces several immediate operational priorities:
- Transition to Continuous Automated Auditing: The focus on AI-assisted red teaming signals that periodic annual audits are no longer sufficient. Regulators expect real-time, algorithmic vulnerability assessment across all internet-facing endpoints.
- Vendor & Software Vetting Standards: Third-party RegTech and cybersecurity software deployed within core banking environments will face increased scrutiny. Systems will likely be benchmarked against the defensive standards and PoC trial outcomes generated by ACT.
- Integration of Friction in Fraud Architecture: While backend platforms adopt automated detection tools, institutions must maintain front-end security frictions. MAS leadership pointed out that protective measures, including cooling-off periods and digital vault mechanisms like "Money Lock" (which secured S$47 billion in funds as of May 2026), remain indispensable operational circuit breakers against automated fraud.
While the core objectives of ACT are established, some key operational details remain unannounced, and we will be following and reporting closely :
- Enforceability of Guidance: Source documents do not clarify whether guidance developed by ACT will serve as voluntary industry best practices or eventually transition into a mandatory MAS regulatory notice.
- Scope of Future Participation: Membership is currently restricted to primary domestic institutions and market infrastructure providers. The timeline for onboarding foreign full banks, merchant banks, or licensed payment institutions has not been specified.
- Deliverable Timetables: Specific deadlines for the publication of PoC trial results and the release of initial guidance documentation have not been published by either issuing body.
Read the full press release by MAS here.
