Skip to content

The new dependencies behind AI

AI is reshaping organisations and threat actors alike. Success depends on understanding both its value and new dependencies.

11 September 2026

7 mins

Image of man in front of data centre

This article is featured in Issue 3 of our Transaction Banking: Bankable Insights e-magazine. Download a copy to view this and more insights.

Most discussions about AI focus on what organisations can do with the technology. Broader implications such as fraud, cyber risk, supplier dependencies, regulations and market dynamics are often examined through separate specialist lenses. For finance leaders, however, these factors rarely occur in isolation. Their combined impact may shape costs, risk exposure, investment decisions and the broader operating landscape.

In its Artificial Intelligence in Financial Services report, the World Economic Forum highlights that 32-39 per cent of work across the sector could be highly automatable, while a further 34-37 per cent has strong augmentation potential. Reflecting this momentum, the sector’s investment in AI is expected to reach USD97 billion by 2027.

Yet turning potential into value is rarely straightforward. Greater reliance on AI also introduces new challenges, from cybersecurity threats and operational resilience concerns to supplier concentration and third-party dependencies. How might these factors shape the path ahead?

AI is changing the operating environment for both organisations and threat actors. While it can strengthen security capabilities, it also lowers barriers for attackers.
Chris Fleming
Head of Client and Third-Party Security, Standard Chartered

Why AI creates new dependencies

A common theme running through the risks identified in the World Economic Forum’s latest Global Risks Report is that AI amplifies existing challenges rather than simply creating new ones. The report highlights adverse outcomes of AI technologies among the most significant long-term risks facing society, while also identifying threats such as misinformation, cyber insecurity, inequality and societal polarisation that AI has the potential to intensify. As these risks evolve in speed, scale and complexity, organisations need to operate in an increasingly dynamic and less predictable environment.

Companies will find themselves increasingly exposed to decisions made outside their control, from pricing changes and service availability to regulatory restrictions, technology roadmaps and shifts in vendor strategy.

For financial institutions (FIs), AI is increasingly moving beyond experimentation and into critical business activities. Capabilities that support customer interactions, risk management, fraud detection and operational processes may become integral to how they operate.

Organisations adopting AI often face a choice between relying on models provided by a small number of technology companies or investing in their own infrastructure, expertise and data capabilities. Neither approach is entirely free from risk. Access to advanced models, computing capacity and other critical components remains concentrated among relatively few providers, while building internal capabilities can require significant investment, specialist expertise and resources that are beyond the reach of many organisations.

It raises several important questions: what happens when technologies that began as productivity tools become embedded in critical business processes? How easily could organisations continue to operate if those capabilities became unavailable, materially more expensive or subject to new regulatory restrictions? And how should organisations balance the efficiency gains of AI against the resilience and flexibility they may be giving up in return?

While the future impact of AI remains difficult to predict, one conclusion is already clear: AI is becoming as much a business resilience and dependency issue as a technology one. Even organisations limiting adoption will face opportunities, risks and dependencies created by customers, suppliers, competitors and threat actors.

Success in the AI era will not be determined solely by who adopts the technology fastest. It will be shaped by how effectively organisations balance innovation with resilience, cyber security and long-term control over critical business capabilities.
Chris Fleming
Head of Client and Third-Party Security, Standard Chartered

Beyond AI adoption: Three principles for managing dependency risk

1. Understand what matters most

Not all processes, systems and dependencies carry the same importance.

  • Identify critical dependencies: Understand which data sources, AI models, technology infrastructure and third-party providers support critical business processes, and assess potential concentration risks and single points of failure.
  • Understand the impact of disruption: Evaluate how critical operations would be affected if a key AI capability became unavailable, materially more expensive or subject to new restrictions, and use those insights to inform adoption, contingency planning and investment decisions.

2. Continuously reassess assumptions

Traditional risk assessments often assume a relatively stable environment in which threats evolve gradually. AI is challenging that approach. New capabilities, attack techniques and use cases continue to emerge at a pace that established governance processes may struggle to keep up with. Organisations should therefore regularly evaluate how technological change affects their risk profile and whether existing controls remain effective.

  • Question established trust mechanisms: In a world where AI can convincingly replicate voices, documents, images and even live interactions, assumptions that once supported trust and decision-making become less reliable.
  • Reinforce critical controls: Maintain layered controls that combine automated detection, independent verification and human oversight. Segregation of duties, dual authorisation, callback procedures for high-value transactions, testing against AI-enabled fraud scenarios and stronger oversight of critical third parties can help strengthen resilience. In some situations, introducing additional scrutiny may be more valuable than further reducing friction.

3. Bring diverse perspectives into AI decisions

Decisions about AI are often viewed through a capability and performance lens. However, procurement, risk, finance, cybersecurity, legal and sustainability functions may all see different opportunities and exposures arising from the same decision.

  • Engage stakeholders early: Bring these perspectives together early, ideally when use cases, vendors and operating models are first being considered, and help organisations identify trade-offs before they become embedded. This not only reduces the risk of delays, rework or unexpected costs later in the process, but also supports more informed decisions about where and how AI should be adopted.

The organisations most likely to succeed will be those that understand both the value AI can create and the dependencies it introduces. The most important decisions may not be about the technology itself, but about the assumptions organisations choose to rely on and the risks they are prepared to accept as AI adoption continues to grow.

When AI changes the rules of cybersecurity

AI is accelerating threats while increasing reliance on models, providers and systems beyond direct organisational control.

Cybersecurity provides a visible example of how AI can create new forms of dependency and exposure. Activities that once required specialist expertise, such as vulnerability discovery or malware development, can increasingly be automated or enhanced through AI, lowering the barrier-to-entry for threat actors whilst allowing them to operate faster, target larger groups and launch more damaging attacks.

The scale of this shift is already visible. CrowdStrike reported an 89 per cent year-on-year increase in AI-enabled attacks in 2025, while the average time required for an attacker to move from initial access to high-value assets fell to just 29 minutes, a 65 per cent reduction compared to the previous year.

The financial impact is already being felt. In recent years, organisations have lost billions of dollars to AI-enabled fraud schemes, including increasingly convincing deepfake impersonation attacks.

2026 introduced new concerns around agentic AI and cybersecurity-focused models. These systems can rapidly identify weaknesses, automate security testing, and accelerate the detection and investigation of security incidents. However, the same capabilities that help organisations strengthen their defences can also empower threat actors.

Researchers recently reported one of the first documented examples of agentic ransomware, where an AI-driven system conducted a cyber-attack with limited human intervention, adapting its approach as the attack progressed.

The challenge extends beyond malicious use. In July 2026, both OpenAI and Anthropic disclosed incidents in which advanced AI models gained access to real-world systems while participating in cybersecurity evaluations. Although the models were attempting to complete assigned tasks rather than acting maliciously, the incidents have highlighted how difficult it can be to ensure autonomous AI systems remain within intended operational boundaries.

An image of digital lock

Want to better understand how today’s cyber threats could affect your organisation?

Standard Chartered’s Client & Third-Party Security function works with clients to share timely threat insights, practical guidance and resilience-building perspectives. Contact your Relationship Manager to explore how these insights can support your organisation’s cyber readiness.

Read about how Standard Chartered approaches AI and innovation, and visit our Cyber Security and Fraud Safety Hub for practical insights on emerging cyber threats, fraud trends and resilience.

Related insights