Singapore’s central bank just admitted a hard truth that every bank security chief already suspects: no single institution can out-build frontier AI on its own. On July 28, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) launched the AI-Driven Cyber and Technology Risk Taskforce (ACT), pulling the regulator, the bank association, three of the country’s biggest lenders, the stock exchange and two shared-infrastructure operators into one standing group built to answer a single question: what does defense look like when the attacker can think?
The Threat That Triggered the Coalition
Vincent Loy, MAS’s Assistant Managing Director (Technology) and Chief Technology Officer, framed the problem plainly: “Frontier AI is increasing the severity, scale and sophistication of cyber threats.” That is not a hypothetical. Large models can now scan code and infrastructure for exploitable flaws, chain vulnerabilities together, and automate the kind of attack sequencing that used to require a skilled human operator working for hours. For a banking sector where a single breach can cascade across payment rails, custody systems and shared clearing infrastructure, that shift changes the math on what “adequate” defense means.
ABS Director Ong-Ang Ai Boon put the response in similarly direct terms: “AI is reshaping the cyber threat landscape, and the financial sector must continue to move together.” The word “together” is doing real work there. Singapore’s approach is not a new rulebook handed down from the regulator; it is a standing operational body that treats cyber resilience as a shared utility rather than a per-institution cost center.
Who Is Actually in the Room
ACT’s membership is the tell. Alongside MAS and ABS sit DBS, OCBC and UOB, the three banks that between them clear the overwhelming majority of Singapore’s retail and corporate transactions, plus the Singapore Exchange (SGX), the Network for Electronic Transfers (NETS) and Banking Computer Services (BCS), the shared back-office and payments infrastructure operators the whole sector depends on. The Taskforce has quietly been convening since May, meaning the July 28 announcement is less a launch than a public unveiling of work already underway. That sequencing, build first, disclose second, suggests MAS wanted operational traction before inviting scrutiny.
The choice of members also signals where MAS sees the real exposure. DBS, OCBC and UOB are not just large; together they anchor the payment and settlement flows the rest of the domestic financial system routes through, which makes their individual cyber posture a systemic variable rather than a private one. Pairing them with SGX, NETS and BCS extends that logic to market infrastructure and shared back-office rails, the layer an attacker could target once to affect many institutions at once rather than compromising each bank separately.
Three Fronts: Sharing, Capability, Guidance
Industry collaboration
The first workstream is straightforward information pooling: member institutions will share AI cybersecurity use cases and operational experience, so that a defense technique proven at one bank does not have to be reinvented at the next.
Capability uplift
The second is harder and more interesting. ACT will run proof-of-concept trials to validate advanced AI-enabled security tools against live, evolving threats, effectively turning the Taskforce into a shared testing ground before individual banks commit budget to unproven defensive AI.
Guidance development
The third workstream will produce sector guidance on new controls and solutions for detecting and preventing AI-enabled attacks, the connective tissue that turns pooled experience and validated tools into something examiners can actually reference.
A Pattern Beyond Singapore
ACT is not happening in isolation. It lands weeks after FIS extended its own partnership with Anthropic to turn frontier AI on its internal security posture, and months after the Bank of England moved to bring cloud providers directly under financial supervision. Line those three up and a pattern emerges: regulators and infrastructure providers are converging on the idea that AI-era cyber risk cannot be contained inside a single balance sheet. FIS chose a vendor partnership model. The UK chose direct supervisory reach into cloud providers. Singapore chose a standing, multi-institution taskforce that blends the regulator, the industry body and the operators of shared infrastructure into one coordinating structure. Different mechanisms, same underlying diagnosis: AI has broken the assumption that each institution’s defenses are its own problem to solve.
What This Means for the Finance Leader
For a chief risk officer or CISO outside Singapore, ACT is worth reading less as a local regulatory item and more as a template. Three implications stand out. First, defensive AI evaluation is moving from a vendor-procurement decision to an industry-coordination problem; expect more regulators to sponsor shared testing grounds rather than leave every institution to validate AI security tools alone. Second, the “we move together” framing signals that supervisors increasingly view uneven AI-driven cyber resilience across a banking system as a systemic risk, not just an institutional one, which raises the odds that lagging institutions get pulled up rather than allowed to opt out. Third, the inclusion of market infrastructure operators like SGX, NETS and BCS alongside banks confirms that AI-driven cyber risk assessments are expanding past the balance sheet and into shared payment and clearing rails that no single bank controls.
The practical takeaway is not to wait for a local version of ACT to appear before acting. Institutions should start mapping which of their AI-relevant cyber defenses depend on knowledge or tooling that would benefit from industry-wide pooling, versus what genuinely needs to stay proprietary, and raise that question with their own regulator or industry association now. That mapping exercise alone tends to surface gaps: security teams often discover that the tools they assumed were unique to their institution are commodity capabilities better validated at industry scale, while the genuinely proprietary layer, customer data models and internal fraud signatures, is narrower than expected. The lesson from Singapore is that the fastest way to keep pace with frontier-AI-enabled attackers is to stop trying to do it alone, and to decide now which parts of the defense stack belong to the industry rather than the institution.
Source: Monetary Authority of Singapore