10/08/2026 | Press release | Distributed by Public on 10/08/2026 06:58
Introduction
In April 2026, we released our 2026-2027 Annual Risk Outlook (ARO) which highlighted four key risks facing financial institutions.
These risks remain highly relevant and continue to drive our regulatory focus.
Since publication of our 2026-2027 ARO, global uncertainty has remained elevated and geopolitical tensions have intensified. Conflicts between the United States and Iran have increased concerns regarding energy supply chain disruptions and broader economic shocks.
Domestic economic conditions have softened. Canadian GDP growth remains volatile, inflation remains elevated relative to policy objectives, and businesses and households continue to face pressure from economic uncertainty.
The ongoing trade war between Canada and the United States discourages business investment, creates supply chain frictions, weakens consumer confidence, and increases financial market volatility. Earlier this year, we proactively reduced the Domestic Stability Buffer to support continued lending through a period of economic uncertainty. This action provides domestic systemically important banks with flexibility and capacity to deploy capital in support of the Canadian economy's adaptation to shifting dynamics in technology, trade, and geopolitics.
Federally regulated financial institutions continue to operate from a position of resilience and profitability but face a more complex operating environment. Rapid technological change is influencing the risk landscape, and the pace of artificial intelligence (AI) development has accelerated materially since publication of the Annual Risk Outlook.
Frontier AI models
AI continues to advance rapidly. Frontier AI models are the most advanced and capable systems currently available. The rate of change in capabilities created by frontier AI is unprecedented. The time between vulnerability discovery and exploitation has been shortened, reducing time available for institutions to understand emerging capabilities, assess associated risks, and adopt defensive measures.
We identified AI innovation as a component of the "other risks" category within the 2026-2027 ARO. Recent developments in AI have amplified cyber, technology, third-party, and reputational risks. These topics warrant focused discussion in this Semi-Annual Risk Outlook update.
Cyber risk
Ongoing advances in AI, including the emergence of autonomous capabilities, increase the effectiveness, speed, and sophistication of malicious cyber-attacks. Capabilities that previously required significant technical expertise are more accessible, enabling a broader range of threat actors to conduct complex attacks.
Frontier AI models can locate and exploit more vulnerabilities, enabling adversaries to launch coordinated, large-scale attacks across systems, applications, and third-party ecosystems. These models can rapidly and autonomously chain together multiple vulnerabilities across interconnected systems, allowing seemingly minor weaknesses to be combined into high-impact attacks.
These technologies reduce the time available for institutions to detect and respond to threats while simultaneously providing the potential for enhanced detection and patching of vulnerabilities before they are exploited. Advances in technology, including quantum computing, will continue to intensify the complexity of the cyber threat environment and elevate the importance of cyber resilience. As cyber threats become increasingly automated and adaptive, institutions need to rapidly enhance their capabilities to effectively defend against attacks.
Third-party risk
A small number of providers currently dominate the development of frontier AI models and the cloud infrastructure used to deploy them. This concentration increases the potential for correlated disruptions if a critical provider experiences an operational failure, cyber incident, or service outage. As a result, third-party concentration risk may pose challenges to operational resilience as AI adoption expands.
Technology sovereignty considerations are also growing in importance. Many technology services are concentrated outside Canada. As institutions incorporate frontier AI capabilities and supporting infrastructure into their operations, cross-border dependencies will likely increase. Geopolitical tensions, including technology restrictions and policy actions in foreign jurisdictions, could affect access to critical technologies and services.
As AI capabilities evolve, institutions may find it difficult to maintain a clear understanding of AI use, vulnerabilities, and controls at critical third-parties. The risks introduced by AI adoption increase the importance of effective due diligence, ongoing monitoring, and strong oversight of critical third-party relationships.
Reputational risk
As frontier AI capabilities continue to advance, technological leadership is increasingly critical to an institution's competitiveness and resilience. Institutions and their third-parties need to remain at the forefront of technological advancement to avoid reputational risks associated with delayed adoption of emerging technologies.
Keeping pace with advancements in cyber security and identification of vulnerabilities is the area of innovation we view as most important in today's changing environment. Where institutions use frontier AI technologies to improve the effectiveness and efficiency of their businesses, it is important to ensure that governance, controls, and testing evolve at a similar pace.
Cyber, technology, third-party, and reputational risks are highly interconnected. As financial institutions become increasingly dependent on complex digital ecosystems, maintaining resilience requires a comprehensive understanding of these interrelated risks.
OSFI response
We continue to monitor developments in cyber, technology, third-party, and reputational risks amplified by frontier AI.
This year, we published two technology risk bulletins on Generative and Agentic Artificial Intelligence and Frontier Artificial Intelligence. The bulletins highlight how advances in AI are amplifying risks and provide considerations to strengthen operational resilience. The cyber risk implications of frontier AI were discussed at a joint OSFI and Canadian Centre for Cyber Security (CCCS) Industry Day in September. Earlier in June, OSFI and CCCS also co-hosted an industry information-sharing session on frontier AI, where CCCS provided institutions with tools, services, and resources to support preparedness for emerging AI-enabled cyber threats.
We engaged in industry outreach by co-hosting the second Financial Industry Forum for Artificial Intelligence, which brought together representatives from industry, academia, and government agencies to discuss best practices for effective AI risk management strategies. This led to the creation of the Awareness, Guardrails, Innovations, Learning, Ecosystem Resiliency (AGILE) framework that is articulated in our report FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial Services.
Alongside the Canadian Security Intelligence Service and Communications Security Establishment Canada, we co-hosted the second annual National Security Threat Forum. The forum brought together senior leaders from federally regulated financial institutions, regulators, and Canada's national security community to share intelligence and strengthen resilience against foreign interference, cyber threats, illicit finance, insider threats, and emerging technology risks.
We also engage in international regulatory forums, such as the Financial Stability Board (FSB). Together with other FSB members, we co-authored Sound Practices for Responsible Adoption of Artificial Intelligence that was published for public consultation in June.
We recognize the need to keep pace with AI developments internally so that we effectively supervise frontier AI deployments at institutions. We will continue to assess the systemic implications of technology concentration and common dependencies on critical service providers.
We support innovation that strengthens the competitiveness and resiliency of the financial sector. Innovation must be accompanied by sound governance and robust risk management practices. Our current regulatory guidance supports responsible innovation while ensuring risks are effectively managed and accurately reported.
We will continue to assess emerging risks and support the resilience of the financial sector through periods of technological disruption and heightened cyber risk.