Artificial intelligence is giving businesses faster ways to analyse information, automate work and improve digital services. But the same technology is also changing the capabilities available to cyber attackers.
Denmark’s Financial Supervisory Authority, Finanstilsynet, issued a warning on 21 August 2026 that advanced AI models are changing the cyber threat landscape. According to the authority, sophisticated AI can help malicious actors identify and exploit vulnerabilities in IT systems faster and on a larger scale than before.

The warning is aimed particularly at Denmark’s financial sector, where operational disruption can have consequences far beyond an individual company. Yet the underlying message has wider relevance. Businesses increasingly depend on interconnected IT systems, cloud providers, external technology vendors and digital data.
That makes AI-powered cyber risk a growing corporate governance issue, not simply a problem for IT departments.
Why Advanced AI Changes the Threat
Cyberattacks are certainly not new. What is changing is the potential speed, scale and sophistication of attacks supported by advanced AI.
Traditional attackers may need considerable time and technical expertise to identify vulnerabilities in an organisation’s systems.
More capable AI tools can potentially accelerate parts of this process.
Finanstilsynet warns that advanced models can make it easier for attackers to identify and exploit vulnerabilities more quickly and at greater scale.
This could put additional pressure on businesses to detect weaknesses before attackers find them.
For management teams, the concern is therefore not simply that new forms of cyberattack will appear. Existing forms of attack may become faster and more efficient.
Danish Regulators Are Paying Attention
Cybersecurity and AI are already moving higher on Denmark’s regulatory agenda.
In its June 2026 risk assessment, Finanstilsynet identified cyber threats and increased use of artificial intelligence as significant areas requiring attention.
The regulator plans to analyse the financial sector’s use of AI and the associated risks during the second half of 2026.
This regulatory direction also matters to businesses monitoring technology, compliance and corporate developments through Lead Roedl. AI is increasingly crossing traditional legal boundaries. A single technology decision can create questions involving cybersecurity, data protection, contracts, operational resilience and management responsibility.
Companies may therefore need to consider AI risk as part of their broader governance structure rather than treating it as an isolated technology issue.
Frontier AI Raises a New Level of Concern
The Danish warning follows concerns expressed at European level.
On 7 July 2026, the European Systemic Risk Board warned about systemic cyber risks associated with so-called frontier AI models.
Frontier AI generally refers to highly advanced general-purpose AI models operating close to the current limits of technological capability.
The concern is that increasingly capable models could increase the speed, scale and complexity of cyberattacks against the financial sector.
European financial supervisory authorities followed with a joint statement on 31 July calling on financial businesses to strengthen their resilience.
Denmark’s Financial Supervisory Authority has now endorsed that assessment.
The sequence of warnings suggests that authorities are treating advanced AI cyber capabilities as an emerging operational risk rather than a distant theoretical problem.
Companies First Need to Know How They Use AI
Interestingly, one of Finanstilsynet’s recommendations starts inside the business itself.
Financial companies are encouraged to understand how AI, including advanced models, is already being used internally and what risks that use creates.
This is an important starting point.
AI tools can enter a business through many routes. A company may formally purchase an enterprise AI platform, while employees independently use generative AI applications for research, coding, writing or data analysis.
Third-party software may also introduce AI functionality through updates.
Businesses can therefore ask:
- Which AI systems are currently approved?
- Which departments use them?
- What company information is entered into AI platforms?
- Are employees using unapproved AI services?
- Which third-party suppliers provide AI-powered functions?
- Can AI systems access sensitive corporate information?
- Who is responsible for assessing their security?
Without an accurate picture of internal AI use, managing the associated risks becomes difficult.
Boards and Senior Management Have a Role
Another significant part of the Danish regulator’s warning concerns responsibility.
Finanstilsynet recommends that responsibility for AI risks be clearly placed with boards and executive management and incorporated into governance and IT risk management.
This moves the discussion beyond the cybersecurity team.
Senior management does not necessarily need to understand every technical detail of an AI model. It does, however, need enough information to understand the company’s exposure and determine whether appropriate controls exist.
Boards may increasingly need to ask questions such as:
- What are our most important digital assets?
- Which systems would cause serious disruption if compromised?
- How quickly are vulnerabilities identified and patched?
- How dependent are we on external IT providers?
- Are AI-related threats included in risk reporting?
- When was our cyber response plan last tested?
Cybersecurity is increasingly connected to business continuity.
A successful attack can interrupt customer services, expose confidential information, disrupt payments, damage systems and create reputational consequences.
That makes preparedness a management issue.
Vulnerability Management Needs to Become Faster
One of the practical risks created by AI-powered attacks is a shrinking response window.
If attackers can identify weaknesses faster, businesses may have less time between a vulnerability becoming known and an attempt being made to exploit it.
Finanstilsynet therefore recommends effective processes for monitoring vulnerabilities and managing security updates.
For businesses, that means understanding not only their own systems but also the software and services on which those systems depend.
A vulnerability may exist in:
- Internal business software
- Cloud infrastructure
- Third-party applications
- Remote access systems
- Employee devices
- Connected services
- Supplier technology
Companies need processes for identifying relevant vulnerabilities, assessing their seriousness and applying updates or other protective measures quickly.
Third-Party Technology Can Expand Corporate Risk
Modern businesses rarely operate entirely on their own technology.
They depend on cloud platforms, payment providers, software vendors, data processors, consultants and other external technology services.
That creates efficiency, but it also creates dependencies.
A company with strong internal cybersecurity can still experience disruption if a critical provider suffers an attack.
This issue is particularly important in the financial sector because the EU’s Digital Operational Resilience Act, known as DORA, places substantial emphasis on ICT risk and third-party technology dependencies.
A July 2026 Finanstilsynet inspection of Nets Denmark provides a practical example of the regulator’s focus. The authority identified deficiencies relating to IT risk management, preparedness and third-party IT risks and issued several orders requiring improvements.
For businesses, supplier due diligence should therefore go beyond price and functionality.
Cybersecurity, recovery capability and operational resilience are becoming increasingly important parts of vendor assessment.
Incident Response Plans Need Real Testing
Having a cybersecurity policy stored somewhere on the company network is not the same as being prepared for an attack.
Finanstilsynet recommends that financial companies update their contingency and recovery plans to reflect AI-driven cyberattacks and test relevant threat scenarios.
Testing matters because real incidents rarely unfold exactly as expected.
Denmark has already been experimenting with more realistic preparation.
In July 2026, Finanstilsynet and Danmarks Nationalbank reported the results of a joint cyber stress test involving 11 important private-sector participants.
The exercise considered an extreme but plausible situation involving manipulation of data and uncertainty over ownership of securities.
The lesson was broader than the particular scenario: interconnected businesses cannot always recover from major disruption independently.
Communication, coordination and preparation across organisations can become essential.
Monitoring Is Becoming More Important
AI-driven threats also increase the importance of detecting unusual activity quickly.
A business cannot respond to an attack it has not noticed.
Companies may therefore need to review whether their monitoring systems can identify unexpected behaviour across networks, accounts, devices and critical applications.
This could include unusual login activity, unexpected data transfers, abnormal system behaviour or suspicious changes to important information.
Monitoring should also connect with escalation procedures.
Employees need to know who should be contacted when something looks wrong and management needs clear information when an incident becomes serious.
Speed matters because delays can allow an attack to spread.
Recovery Is as Important as Prevention
No organisation can guarantee that every cyberattack will be prevented.
This changes the question from simply “How do we stop an attack?” to “How do we keep operating and recover if an attack succeeds?”
Businesses should know which services are essential and how quickly they need to be restored.
Useful preparation can include:
- Maintaining secure backups
- Testing restoration procedures
- Identifying critical systems
- Establishing alternative communication channels
- Defining decision-making authority during incidents
- Preparing customer and stakeholder communications
- Testing cyberattack scenarios
- Coordinating with important technology suppliers
A recovery plan that has never been tested may contain assumptions that fail during a real incident.
AI Creates Opportunities and Risks at the Same Time
The regulatory message is not that businesses should stop using artificial intelligence.
Finanstilsynet itself recognises that AI has significant potential for the financial sector.
The challenge is managing the technology without allowing new capabilities to become new vulnerabilities.
For Danish businesses, the most effective response may be to treat AI and cybersecurity as connected parts of corporate risk management.
That means understanding internal AI use, monitoring the external threat landscape, maintaining strong vulnerability management, examining third-party dependencies and ensuring that senior management has clear responsibility.
AI-powered cyberattacks may continue to evolve as advanced models become more capable.
Companies cannot know exactly what the next major attack will look like. They can, however, make sure they know their critical systems, understand their vulnerabilities and have tested what they will do when something goes wrong.
In a threat environment where AI can increase the speed of an attack, the speed and quality of a company’s response may become just as important as its ability to prevent one.