On 22 May 2026 the Japan Financial Services Agency and the Bank of Japan jointly requested financial institutions to take short-term measures against the changed cyber threat posed by frontier AI, which can discover vulnerabilities and generate attack code far faster than before. The request, addressed to the heads of relevant firms, asks for direct involvement of management including the top executive and sets nine measures, such as treating frontier AI as a management issue, prioritising critical services and IT systems, adding patching resources, making patching risk-based rather than CVSS-only, strengthening defences beyond patching, and preparing for proactive shutdown of services. It expects institutions to proceed in roughly one month. It applies to banks and is a supervisory request, not a rule.
OFFICIAL TEXT: fsa.go.jp ↗ · IN FORCE · JAPAN FSA
| Document | Japan FSA/BOJ frontier AI request — Request regarding 'Short-term Responses by Financial Institutions in Light of Threat Changes from Frontier AI' (「フロンティアAIによる脅威変化を踏まえた金融機関等の短期的な対応」に係る要請について) |
| Issued by | Financial Services Agency of Japan (with the Bank of Japan on frontier AI cyber measures) |
| Type | Letter |
| Status | In force |
| Published | May 22, 2026 |
| Applies to | Financial institutions and related entities (the letter is addressed to the representatives of the relevant firms), including banks; issued by the Financial Services Agency with a Bank of Japan director. It asks, rather than orders, with management involvement including top management |
| Official source | fsa.go.jp ↗ |
| Use cases | Cybersecurity · Third-party & vendor AI · AI governance (general) · Generative & agentic AI |
What are the key points of Japan FSA/BOJ frontier AI request?
- The letter explains that on 24 April 2026 the FSA held a public-private meeting on strengthening financial-sector cybersecurity against AI threats, and a first practitioner-level working group met on 14 May 2026, which produced the attached short-term response document.
- It asks each institution to act under the direct involvement of management, including top management, on the measures in the attachment.
- Measure 1: treat frontier AI as a management issue with cross-department coordination and involvement of the CIO and CISO.
- Measure 2: identify priority services and IT systems, such as externally exposed systems supporting critical services like internet banking, and allocate resources on a risk basis.
- Measures 3-5: eliminate technical debt on those assets (closing unnecessary ports, removing privileged IDs, updating end-of-support products), add human resources for patching, and check that maintenance contracts with vendors cover patching, with SLAs and SLOs honoured at times of simultaneous demand.
- Measure 6: make patch prioritisation risk-based, considering likely impact and attack likelihood rather than relying only on CVSS scores, and consider reasonable reductions of pre-patch testing.
- Measures 7-9: strengthen non-patch defences (virtual patching with WAF, network separation, MFA for privileged IDs, EDR), prepare for the possible proactive shutdown of priority services or systems, and maintain external coordination through financial ISACs and authorities.
- Footnote 3 of the attachment expects institutions to proceed over roughly one month, taking account of AI model developers' activities; the letter says the request reflects the current situation and measures should be reviewed as AI developments change, and notes that the UK AISI evaluation indicates frontier AI cannot at present compromise well-defended IT systems, so basic measures under the FSA's cybersecurity guidelines remain important.
What did Japan FSA/BOJ frontier AI request change for banks?
It is Japan's regulator-level response to the 2026 frontier-AI cyber threat, paralleling advisories from Singapore, Hong Kong and New York. It reframes AI as an attacker's capability, makes patching, vendor contracts and shutdown readiness board-level topics for banks, and links to the national government's Project YATA-Shield package of 18 May 2026.
What did the Japan FSA and Bank of Japan ask financial institutions to do about frontier AI threats?
On 22 May 2026 the FSA and the Bank of Japan asked financial institutions to take nine short-term measures under direct management involvement, including the top executive: treat frontier AI as a management issue; identify priority services and IT systems; eliminate technical debt on them; add patching resources; confirm vendor maintenance contracts and SLAs cover surges in patching; make patch prioritisation risk-based rather than CVSS-only; strengthen non-patch defences such as virtual patching, network separation, MFA and EDR; prepare for the proactive shutdown of priority systems; and keep up external coordination through financial ISACs. The attachment expects action over about one month. It is a request that builds on the FSA's cybersecurity guidelines and applies to banks, not a binding rule.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Measure 1 — Management issue | Japan FSA | Treat frontier AI response as a company-wide management issue with the top executive, CIO and CISO directly involved. | Requested from 22 May 2026; about one month |
| Measure 2 — Priority services and systems | Japan FSA | Identify priority services and IT systems, especially externally exposed systems supporting critical services such as internet banking, and focus resources on them. | Requested from 22 May 2026; about one month |
| Measures 3-4 — Technical debt and patching resources | Japan FSA | Be able to identify patch targets immediately, close unnecessary ports, remove privileged IDs, replace unsupported products and add patching staff, including at vendors. | Requested from 22 May 2026; about one month |
| Measure 5 — Vendor maintenance contracts | Japan FSA | Confirm contracts cover patching, roles and out-of-hours work, check vendor resources for simultaneous surges, and obtain SLA and SLO reporting for shared and cloud systems. | Requested from 22 May 2026; about one month |
| Measure 6 — Risk-based patching | Japan FSA | Prioritise patches by likely impact and attack likelihood rather than CVSS Base score alone and consider reasonable reductions of pre-patch testing. | Requested from 22 May 2026; about one month |
| Measure 7 — Non-patch defences | Japan FSA | Use virtual patching (WAF), bot countermeasures, network separation, MFA for privileged IDs and EDR where patching is hard, with formal risk acceptance for residual risk. | Requested from 22 May 2026; about one month |
| Measure 8 — Shutdown readiness | Japan FSA | Prepare for IT outages and for deciding to shut down priority services proactively, with tested business continuity plans, stakeholder communication and clear criteria. | Requested from 22 May 2026; about one month |
| Measure 9 — External coordination | Japan FSA | Use and contribute to financial ISACs, industry bodies and authorities for information on frontier AI. | Requested from 22 May 2026; ongoing |
The letter ties the measures to existing supervision: it says the basic measures under the FSA's Guidelines on cybersecurity in the financial sector remain important and should be carried out faster and more steadily, and the FSA will proceed in line with the national government package published on 18 May 2026 by the National Cybersecurity Office. It stresses that the measures are emergency steps and that, in the medium to long term, institutions need to move toward automating vulnerability response.
The attachment says the threats extend to third-party software and open-source components as well as in-house systems, which makes vendor contracts and cloud and shared-system SLAs central to bank compliance. Together with the SFC's June 2026 circular and MAS's April 2026 advisory it forms part of a coordinated regulatory response in Asia to frontier-AI cyber risk.
WHAT THIS MEANS IN PRACTICE
- Brief the board and name an executive owner for frontier-AI cyber readiness.
- Rank internet-facing and critical systems and confirm software and network configuration data allows instant identification of patch targets.
- Review vendor maintenance contracts for patching coverage, after-hours response and SLA reporting for cloud and shared systems.
- Document a risk-based patch prioritisation that goes beyond CVSS Base scores and a risk acceptance process.
- Define criteria and procedures for proactively shutting down priority services and test continuity plans.
Does the Japan FSA and BOJ frontier AI request apply to banks?
Yes. It is addressed to the representatives of financial institutions and related entities and concerns measures such as protecting internet banking systems. It is a request issued by the FSA and the Bank of Japan rather than a new legal rule.
When must firms act under the FSA and BOJ frontier AI request?
The attachment expects institutions to proceed over roughly one month, taking account of AI model developers' activities, and says measures should be reviewed as circumstances change. The request is dated 22 May 2026.
Is the request binding?
It is a request ('要請') that asks institutions to act under direct management involvement. It builds on the FSA's existing cybersecurity guidelines for the financial sector and sets no penalties.
How does this compare with the SFC and MAS frontier AI cyber guidance?
All three address faster vulnerability discovery and exploitation and stress patching speed, asset inventories and incident response. The Japanese request is the most specific about timing (about one month) and calls explicitly for readiness to shut down priority services.
| Date | Document | Status |
|---|---|---|
| Mar 3, 2026 | Japan FSA AI Discussion Paper v1.1 — AI Discussion Paper (Version 1.1): Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial Sector | Final |
| Mar 4, 2025 | Japan FSA AI Discussion Paper v1.0 — AI Discussion Paper (Version 1.0): Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial Sector | Superseded |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 2, 2026 | FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber Resilience | In force |
| Aug 31, 2026 | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models | Final |
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning