MAS circular MAS/TCRS/2024/05, published on 30 July 2024, is an information paper that gives financial institutions an overview of cyber threats arising from generative AI, the risk implications and mitigation measures. It covers two threat families: GenAI-enabled attacks (deepfakes and phishing, and malware generation and enhancement) and threats to GenAI deployments (data leakage, and model and output manipulation). It applies to all FIs including banks as awareness guidance rather than a binding rule. The one thing a bank should do is test whether its existing cyber controls (authentication, data loss prevention, access control, monitoring, incident response) cover both families of threat.
OFFICIAL TEXT: mas.gov.sg ↗ · IN FORCE · MAS
| Document | MAS Circular MAS/TCRS/2024/05 — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper) |
| Issued by | Monetary Authority of Singapore |
| Type | Circular |
| Status | In force |
| Published | Jul 30, 2024 |
| Applies to | Financial institutions in Singapore (the circular is addressed to FIs), which includes banks. It is an awareness paper that describes threats and mitigation measures FIs 'could' take; it does not impose new binding requirements |
| Official source | mas.gov.sg ↗ |
| Use cases | Cybersecurity · Generative & agentic AI · Fraud detection · Data & privacy · Third-party & vendor AI |
What are the key points of MAS Circular MAS/TCRS/2024/05?
- Section 2.1 covers deepfakes and GenAI-enabled phishing, citing incidents in 2023-2024 including a deepfake video-conference fraud in Hong Kong and deepfakes used to defeat facial biometric authentication; mitigation includes liveness detection, awareness campaigns, additional verification for high-risk transactions and deepfake scenarios in incident response.
- Section 2.2 covers malware generation and enhancement, including polymorphic malware; mitigation includes a multi-layered cyber defence strategy and consideration of AI tools to detect polymorphic malware.
- Section 3.1 covers data leakage from GenAI deployments: user policies and awareness, security best practice for in-house models, due diligence on third-party or open-source GenAI solutions, and data loss prevention and firewalls.
- Section 3.2 covers GenAI model and output manipulation, including data poisoning; mitigation includes model and data governance, access controls to training data and foundation models, maker-checker and human-in-the-loop controls, continuous monitoring and validation, contingency in business continuity plans and information sharing.
- Section 4 concludes and the Appendix summarises each threat's impact and countermeasures by people, process and technology.
- The circular's description says MAS planned a follow-up information paper on AI model risk management for 4Q 2024 or 1Q 2025 (issued 5 December 2024) and points FIs to Project MindForge's industry-led whitepaper on emerging GenAI risks and opportunities.
What did MAS Circular MAS/TCRS/2024/05 change for banks?
It was the first MAS paper to catalogue generative-AI-specific cyber threats for financial institutions, separating the attacker's use of GenAI from risks in the FI's own GenAI deployments. It has been followed by MAS's September 2025 paper on deepfakes and by MAS's 2026 work on frontier-AI cyber threats, and it is the cyber companion to MAS's model risk and governance papers.
What does MAS/TCRS/2024/05 say banks should do about generative AI cyber risks?
MAS circular MAS/TCRS/2024/05, 'Cyber Risks Associated with Generative Artificial Intelligence', of 30 July 2024 is an awareness paper rather than a rulebook, but it lists the mitigation measures MAS expects financial institutions to consider. For GenAI-enabled attacks they include liveness detection against deepfakes, user awareness campaigns, extra verification for high-risk transactions and privileged roles, deepfake scenarios in incident response and a multi-layered cyber defence. For GenAI deployments they include user policies, data classification, due diligence on third-party and open-source models, data loss prevention, access controls on training data and foundation models, human-in-the-loop and maker-checker controls, continuous monitoring and validation, and contingency plans in business continuity planning. Banks should map these against their existing technology risk controls.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Section 2.1 — Deepfakes and GenAI-enabled phishing | MAS | Use liveness detection in facial recognition, run awareness and simulation exercises, add verification for high-risk transactions and privileged roles, and include deepfake attacks in incident response. | Awareness guidance, 30 July 2024 |
| Section 2.2 — Malware generation and enhancement | MAS | Adopt multi-layered cyber defence and AI-assisted detection that can identify polymorphic malware, and integrate threat intelligence into log monitoring. | Awareness guidance, 30 July 2024 |
| Section 3.1 — Data leakage from GenAI deployment | MAS | Set user policies and classify data allowed into GenAI tools, apply security best practice to in-house models, perform due diligence on third-party and open-source GenAI, and deploy data loss prevention and firewalls. | Awareness guidance, 30 July 2024 |
| Section 3.2 — Model and output manipulation | MAS | Govern models and training data, restrict access to training data and foundation models, use maker-checker and human-in-the-loop controls, and monitor and validate models continuously. | Awareness guidance, 30 July 2024 |
| Section 3.2 — Resilience and information sharing | MAS | Include contingency measures for GenAI solutions in business continuity plans and take part in industry information sharing on GenAI deployment issues. | Awareness guidance, 30 July 2024 |
| Appendix — Summary of threats, impact and countermeasures | MAS | Map each threat to people, process and technology countermeasures; the table is a ready-made control checklist. | Awareness guidance, 30 July 2024 |
The paper separates threats by who is using the GenAI. Where attackers use it (deepfakes, phishing, malware), the mitigations are largely strengthened conventional controls. Where the FI itself deploys GenAI, the risks are data leakage and manipulation of the model or its outputs, and the controls move toward data governance, access control and model oversight, which overlap with the model risk expectations in MAS's December 2024 information paper.
It is the earliest in a series. MAS's September 2025 deepfakes paper (MAS/TCRS/2025/06) deepens section 2.1, and the November 2025 consultation paper says risks from external actors' use of AI, such as AI-powered cyber-attacks, are outside the scope of the proposed Guidelines and covered by these cyber papers instead.
WHAT THIS MEANS IN PRACTICE
- Test facial-recognition onboarding and authentication against deepfake injection, including liveness detection.
- Add deepfake and GenAI-phishing scenarios to staff awareness programmes and incident response playbooks.
- Write a staff policy on what data may be entered into public GenAI tools and enforce it with data loss prevention.
- Run third-party and open-source GenAI models through due diligence before use.
- Restrict access to training data and foundation models and require maker-checker approval for changes.
- Include GenAI services in business continuity plans.
Does MAS/TCRS/2024/05 apply to banks?
Yes. The circular is addressed to financial institutions and the paper's mitigation measures are written for FIs generally, including banks. It is an information paper, so it does not set new binding requirements.
Is MAS/TCRS/2024/05 binding?
No. It aims to raise FIs' awareness by giving an overview of key threats, the risk implications and measures FIs could take. Existing MAS technology risk and cyber requirements continue to apply to the controls it discusses.
What threats does the MAS GenAI cyber risks paper cover?
Four: deepfakes and GenAI-enabled phishing; malware generation and enhancement; data leakage from GenAI deployments; and GenAI model and output manipulation. The first two are GenAI used by attackers, the last two are risks to an FI's own GenAI use.
What did MAS publish after this paper?
An information paper on AI model risk management on 5 December 2024, a deepfakes information paper (MAS/TCRS/2025/06) on 18 September 2025, and the November 2025 consultation on Guidelines on AI Risk Management.
| Date | Document | Status |
|---|---|---|
| Mar 20, 2026 | MAS MindForge AI Risk Management Toolkit — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit) | Final |
| Nov 13, 2025 | MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) — Consultation Paper on Guidelines on Artificial Intelligence Risk Management | Proposed |
| Sep 18, 2025 | MAS Circular MAS/TCRS/2025/06 — Cyber Risks Associated with Deepfakes (Information Paper) | In force |
| Dec 5, 2024 | MAS AI Model Risk Management information paper — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper) | Final |
| Nov 12, 2018 | MAS FEAT Principles — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector | In force |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning