On October 16, 2024, the New York State Department of Financial Services (NYDFS) issued a significant communication to entities it oversees, highlighting pressing concerns over the cybersecurity risks posed by artificial intelligence (AI). This advisory letter, while not mandating new requirements, serves to underscore potential vulnerabilities associated with AI in relation to nonpublic information (NPI). It also delineates how elements of NYDFS's Part 500 regulations can be leveraged to mitigate these emerging risks.
The NYDFS is no stranger to AI discourse, having previously addressed its implications in areas such as insurance underwriting. This focus aligns with wider initiatives within New York, including those championed by Governor Kathy Hochul, aiming to ensure responsible governance and deployment of AI technologies.
Unveiling AI-Enabled Risks
The NYDFS letter outlines four primary risk areas concerning AI, dividing these into threats posed by external actors and internal deployments by entities themselves.
Threat Actors Harnessing AI:
AI-Powered Social Engineering: Advancements in AI have facilitated the creation of hyper-realistic deepfakes. These can be dangerously used to mimic individuals convincingly through video, audio, or text, leading to potential financial fraud or business email compromises.
AI-Powered Cybersecurity Attacks: The letter emphasizes how threat actors can deploy AI across all phases of a cyberattack— from crafting sophisticated malware to circumventing security defenses. This capability drastically enhances the potential scale and efficiency of cyberattacks.
Covered Entities’ Utilisation of AI:
Data Utilisation Including NPI: Developing AI systems requires vast amounts of data, which often includes nonpublic information. This necessity makes these systems prime targets for cybercriminals seeking to exploit or exfiltrate sensitive information.
Third-Party Data Breach Risks: Many companies rely on external providers for managing large datasets essential for AI training. As such, these third-party vendors become increased targets for cyberattacks, potentially impacting the entities reliant on their services.
Strategic Recommendations
To address these concerns, the NYDFS suggests leveraging the existing framework of Part 500 in five key areas:
Annual Risk Assessments: Entities are advised to include AI-related threats in their annual cybersecurity risk assessments. Such evaluations should provide insights into AI’s impact on the business and identify vulnerabilities, thereby guiding subsequent cybersecurity strategies and actions.
Third-Party Due Diligence: It is crucial for entities to strengthen their protocols when engaging with third-party vendors. This includes incorporating specific assessments related to the secure handling of NPI, potentially mandating robust cybersecurity practices in their contracts.
Multifactor Authentication (MFA): Enhanced access controls, particularly through MFA, are strongly recommended. Entities are urged to consider how AI technologies, such as deepfakes, might compromise traditional biometric authentication, requiring adaptations in security protocols.
Cybersecurity Training Updates: Organisations should expand their cybersecurity training programs to incorporate AI threats, emphasizing the exclusion of NPI in AI-related tasks and ensuring that all employees are aware of these emerging risks.
Comprehensive Data Inventory Maintenance: Though not obligatory until November 2026, maintaining an updated inventory of data and AI systems is highlighted. Such an inventory is critical to identifying potential areas of vulnerability and implementing appropriate mitigation strategies.
The integration of AI-centric considerations into the existing Part 500 guidance will undoubtedly require substantial effort from covered entities. Yet, these proactive measures are positioned as essential steps in fortifying cybersecurity frameworks against evolving AI threats.
Source: Noah Wire Services