# Treasury AI cybersecurity risks report (Mar 2024): Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector

Source: https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-cybersecurity-risks-report-2024
Last updated: Aug 26, 2026

On March 27, 2024 the Treasury released 'Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector', written under Executive Order 14110 and led by its Office of Cybersecurity and Critical Infrastructure Protection. Based on 42 in-depth interviews conducted in late 2023, it found a widening AI capability gap between large and small institutions and a 'fraud data divide' that leaves smaller banks without enough data to train anti-fraud models. Its recommended next steps — a financial-sector expansion of the NIST AI RMF, data 'nutrition labels' for vendor AI, explainability research, and an AI information-sharing forum — became the workplan for the AIEOG resources published in February 2026.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [U.S. Treasury](https://www.bankingnewsai.com/ai-regulation/treasury) |
| Type | Report |
| Status | Final |
| Published | Mar 27, 2024 |
| Applies to | U.S. financial institutions of all sizes, their AI and data vendors, and financial regulators (recommendations are non-binding) |
| Official text | https://home.treasury.gov/news/press-releases/jy2212 |

## Key points

- Mandated by EO 14110 (Oct 2023); Treasury's OCCIP led the work as Sector Risk Management Agency for financial services
- Findings drawn from 42 interviews with financial institutions, IT firms, data providers, and anti-fraud/AML companies in late 2023
- Identifies a growing capability gap: large institutions build in-house AI, smaller ones lack the data and expertise; cloud-migrated firms have an advantage
- Identifies a 'fraud data divide': insufficient cross-firm fraud-data sharing disadvantages smaller institutions building anti-fraud models
- Warns of regulatory fragmentation as state, federal, and international regulators consider AI rules
- Recommends expanding the NIST AI Risk Management Framework with financial-services-specific governance content
- Calls for data supply-chain mapping best practices and standardized 'nutrition labels' disclosing what data trained a vendor model and how customer inputs are used
- Flags explainability of black-box and generative AI, and the need for shared AI-specific cyber threat information

## What changed for banks

This was the first federal report to treat AI as a distinct cybersecurity and fraud risk vector for the financial sector, covering both banks' defensive use of AI and attackers' use of generative AI for fraud. It did not impose obligations, but it set the agenda that Treasury has since executed through the AIEOG public-private partnership: the 2026 AI Lexicon, the FS AI RMF, and the explainability, data-labeling, and fraud workstreams all trace directly to this report's next-steps list.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## FAQ

### What did the Treasury's 2024 AI cybersecurity report recommend banks do?

Map their business lines and data supply chains for AI use, apply existing risk frameworks such as the NIST AI RMF to AI systems, seek 'nutrition label' disclosures from AI and data vendors, and participate in sector information sharing on AI-enabled fraud and cyber threats.

### Is the March 2024 Treasury AI report binding?

No. It is a report with recommendations and next steps; it created no rules. Its recommendations were later turned into voluntary AIEOG resources in 2026.

## Related documents

- [FSOC AI Innovation Series (Mar–May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fsoc-ai-innovation-series-2026) — Artificial Intelligence Innovation Series — FSOC and Treasury AI Transformation Office roundtables (Jun 24, 2026)
- [Treasury FS AI RMF and AI Lexicon (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fs-ai-rmf-and-ai-lexicon-2026) — Financial Services AI Risk Management Framework (FS AI RMF) and Artificial Intelligence Lexicon (Feb 19, 2026)
- [FSOC 2025 Annual Report](https://www.bankingnewsai.com/ai-regulation/documents/fsoc-annual-report-2025) — Financial Stability Oversight Council 2025 Annual Report — Section 3.4, Harnessing Artificial Intelligence to Promote Financial Stability (Dec 11, 2025)
- [Treasury AI in Financial Services report (Dec 2024)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-financial-services-report-2024) — Artificial Intelligence in Financial Services — Report on the Uses, Opportunities, and Risks of AI in the Financial Services Sector (Dec 19, 2024)
- [FSOC 2024 Annual Report](https://www.bankingnewsai.com/ai-regulation/documents/fsoc-annual-report-2024) — Financial Stability Oversight Council 2024 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services (Dec 6, 2024)
- [Treasury $4B AI fraud-prevention announcement (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-ml-fraud-prevention-fy2024) — Treasury Announces Enhanced Fraud Detection Processes, Including Machine Learning AI, Prevented and Recovered Over $4 Billion in Fiscal Year 2024 (Oct 17, 2024)
- [Treasury AI RFI (June 2024)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-financial-services-rfi-2024) — Request for Information on Uses, Opportunities, and Risks of Artificial Intelligence in the Financial Services Sector (Jun 12, 2024)
- [FSOC 2023 Annual Report](https://www.bankingnewsai.com/ai-regulation/documents/fsoc-annual-report-2023) — Financial Stability Oversight Council 2023 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services (Dec 14, 2023)

Last reviewed Aug 26, 2026. Cite the official text (https://home.treasury.gov/news/press-releases/jy2212) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-cybersecurity-risks-report-2024
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
