OpenAI disclosed on August 7 that preliminary tests of its upcoming Astra model were strong enough that the company could not rule out its highest cybersecurity warning level, “Critical,” under its own preparedness framework. At that threshold, a model may be able to independently discover and develop working zero-day exploits against real-world systems, or carry out cyberattacks from a high-level objective alone, PYMNTS reported.
That's not a headline about one artificial intelligence (AI) model. It's a marker of where the capability curve is heading, and banking sits directly in its path.
We wrote recently about Anthropic's own disclosure that three of its models broke out of sealed test environments and touched real external systems, in part because the models couldn't tell a simulation from reality. That was a containment failure at the level of one lab's testing infrastructure. What OpenAI and the International Monetary Fund (IMF) are now describing is the same failure point at systemic scale: models capable enough to find and exploit vulnerabilities on their own, deployed across an industry that shares far more infrastructure than most institutions probably account for.
The IMF's own analysis, published in a note on artificial intelligence and cybersecurity in the financial sector, makes the uncomfortable point directly: AI doesn't need to invent new categories of attack to change the risk equation. It just needs to accelerate vulnerability discovery and exploitation across the technologies banks already share, turning what used to be isolated incidents into correlated disruptions hitting multiple institutions at once. Vulnerability discovery, penetration testing, and automated code review all strengthen defenses and can be repurposed to attack systems, and more autonomous models compress response times further by executing multistep operations with less continuous human oversight.
Modern banks aren't single systems, they're collections of interdependent ones: core banking platforms, payment networks, cloud workloads, open-source libraries, identity infrastructure, and third-party providers, all forming what amounts to shared financial infrastructure across the industry. That shared architecture is exactly what turns an AI-discovered vulnerability from one institution's problem into many institutions' problem simultaneously. It's the same structural exposure we've flagged in open finance chains before, a shared dependency several layers removed from any single bank's own risk assessment, just showing up here as a cybersecurity finding instead of a data-access one.
It also means the exposure doesn't require a bank to buy the AI directly. OpenAI's own Daybreak defense system is already being distributed through firms including Accenture, IBM, Capgemini, EY, KPMG, PwC, Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare, meaning the model may never appear as a line item on a bank's own technology budget while still shaping how vulnerabilities in that bank's systems get found, ranked, and fixed.
Open finance is built on exactly the kind of shared architecture the IMF is warning about, just one layer further out. A bank's own systems are one node in a much larger network of third-party providers, intermediaries, processors and sub-processors that all touch the same customer data and the same payment rails. The IMF's correlated-exposure problem, one vulnerability, many institutions affected at once, doesn't stop at a bank's perimeter in that kind of network. If an AI-discovered flaw in a shared library or a widely used aggregator's infrastructure is exploitable, every institution connected to that participant inherits the exposure simultaneously, regardless of how well any single bank has secured its own systems.
PYMNTS frames the competitive edge in almost exactly these terms: the advantage belongs to the institution that can know exactly what a model can reach and close that access before capability turns into exposure. Open finance needs the same discipline applied network-wide, not just within each institution's own walls. That means knowing which third-party providers and aggregators are accredited to sit inside the network in the first place, and monitoring what they, and anything they've deployed, from AI-powered tooling to an agent acting on a customer's behalf, can actually access on an ongoing basis. A perimeter defended only at the level of one bank does nothing to contain a vulnerability that enters through a participant three or more steps removed from it.
See how the Invela Network applies standardized accreditation and continuous risk monitoring across every participant in the network, banks, third-party providers, aggregators, and the AI systems they run, so a vulnerability entering anywhere in the chain doesn't stay invisible until it becomes everyone's problem.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.