20 July 2026
In brief
The Bangko Sentral ng Pilipinas (BSP) has issued M-2026-034, providing recommendations for managing cybersecurity risks arising from frontier artificial intelligence (AI) systems. The memorandum highlights that such systems may enable increasingly sophisticated and scalable cyberattacks and underscores the need for robust cybersecurity, technology risk management, and cyber hygiene practices. It also encourages BSP-supervised institutions (BSIs) to adopt AI-enabled defensive tools and to develop an AI governance framework aligned with existing regulatory principles.
Key takeaways
- BSIs should review and enhance cybersecurity and technology risk management frameworks to address AI-enabled threats.
- Institutions are encouraged to strengthen asset visibility, foundational controls, and attack surface management practices.
- The BSP recommends stronger authentication measures, including hardware-based multi-factor authentication and discontinuing weaker methods for privileged access.
- BSIs should leverage AI-enabled cybersecurity capabilities to support threat detection, patching, and response.
- Institutions are recommended to develop an AI governance framework proportionate to their operations and risk profile.
In more detail
The BSP, through M-2026-034, outlines recommendations aimed at helping BSIs manage the emerging cybersecurity risks associated with frontier AI systems. These systems are described as capable of identifying vulnerabilities, generating exploit pathways, and executing multi-stage cyberattacks with minimal human intervention, signaling a shift toward more adaptive threats. In this context, the memorandum emphasizes the importance of maintaining resilient cybersecurity frameworks and practices as AI-driven threats evolve. In particular, the BSP provides the following recommendations:
Scope and context
The memorandum applies to all BSIs and situates its recommendations within the existing risk-based regulatory framework for information technology and cybersecurity risk management under the Manual of Regulations for Banks (MORB) and the Manual of Regulations for Non-Bank Financial Institutions (MORNBFI). These recommendations are intended to complement existing controls and ensure that emerging risks are effectively identified, assessed, and mitigated.
Enhancing attack surface visibility and security controls
BSIs are recommended to improve visibility across their attack surface by maintaining accurate and up-to-date inventories of assets, cloud services, identities, and software dependencies, including third-party components. The memorandum also calls for strengthening foundational security controls, including credential hygiene, use of multi-factor authentication (MFA), and enforcement of least-privilege access.
Strengthening authentication
The BSP recommends proactive measures to reduce exposure, such as adopting micro-segmentation, zero trust security controls, timely patching, and limiting unnecessary internet exposure of systems. It further encourages stronger authentication mechanisms, including hardware-backed MFA (e.g., FIDO2/WebAuthn keys, smart cards, or certificate-based authentication), and recommends discontinuing knowledge-based or communication-based authentication methods for administrative and privileged access.
Adopting AI-enabled defensive measures
The memorandum highlights the use of AI-enabled cybersecurity tools for patch management, threat hunting, exposure management, and security orchestration. It also recommends deploying virtual patching controls to block exploit pathways before updating underlying systems, particularly for critical assets.
Enhancing readiness and governance
BSIs are advised to review and enhance their business continuity management frameworks and plans to ensure preparedness for AI-enabled threats. In addition, institutions are recommended to develop an AI governance framework proportionate to their operational complexity and risk profile, guided by BSP Memorandum No. M-2026-031 dated 24 June 2026.
How this affects your business
BSIs should consider reviewing their existing cybersecurity, technology risk management, and governance frameworks to assess alignment with the recommendations set out in BSP Memorandum No. M-2026-034. In particular, institutions may wish to evaluate whether appropriate controls are in place across their IT environment, including asset visibility, access controls, vulnerability management, security monitoring, and incident response, and whether measures to reduce exposure, including timely patching and network segmentation, are consistently implemented. Institutions that rely on third-party providers should also ensure that relevant oversight and risk management arrangements adequately address AI-enabled cybersecurity risks.
Organizations may take this opportunity to strengthen their defensive capabilities, including the adoption of AI-enabled cybersecurity tools and more robust authentication mechanisms for privileged access. BSIs are likewise encouraged to consider developing or enhancing their AI governance frameworks in line with BSP guidance, ensuring consistency with existing regulatory requirements. For further information on how this development may affect your organization, please feel free to reach out to our team in Quisumbing Torres, and we will be pleased to assist.