CYBER DESK · HONG KONG · WEEKLY

MAS Names Six Banks To Build AI Defences

Singapore's new AI cyber taskforce names six institutions with deliverables attached, while Hong Kong's parallel response still asks banks to review themselves.
KT

Named Members, Named Deliverables

The Monetary Authority of Singapore and the Association of Banks in Singapore announced on July 28, 2026 that they had formed the AI-Driven Cyber and Technology Risk Taskforce (ACT), a standing body with six named institutions on the hook for specific work. MAS assistant managing director for Technology Vincent Loy said the authority 'will work closely with industry partners to strengthen our collective defences.' ABS director Ong-Ang Ai Boon said the sector remains 'vigilant, agile and committed to strengthening cyber and technology resilience.'

The roster is where the taskforce actually differs from an advisory: DBS, OCBC, UOB, the Singapore Exchange, Network for Electronic Transfers and Banking Computer Services, alongside MAS and ABS themselves. The group has been meeting since May 2026; the July 28 announcement made the membership and mandate public. Three workstreams follow from that roster: joint work on AI cybersecurity use cases, proof-of-concept trials to test capability uplift, and drafting the guidance that will eventually cover every bank in Singapore, not just the six that write it. A PoC trial has a deliverable date and a named institution attached to it. A press release commitment to 'strengthen collective defences' does not.

Hong Kong's Circular Instead

Hong Kong's most recent equivalent move was a joint HKMA and Securities and Futures Commission circular issued around May 29, 2026, urging authorised institutions to review their cyber risk management and third-party resilience against AI-enabled threats. That is guidance aimed at every institution generically. Nobody's name is attached to a deliverable, and no proof-of-concept trial reports back to a named forum. The city's Digital Policy Office recorded a 66 percent year-on-year rise in hacking-related data breach notifications in the first half of 2026, and named AI as an enabling factor in that rise.

The institutions absorbing that 66 percent increase, Hong Kong's licensed banks and the authorised institutions the HKMA already supervises, are working from a circular telling them to review their own controls, with no shared PoC pipeline and no named counterpart institution to compare notes with. Kaspersky researchers spent the same window tracking OctLurk and SilkLurk, two new backdoors a suspected Chinese-speaking espionage cluster has run against government targets across Central Asia since January 2025. Dedicated campaigns carry names attached to them; Hong Kong's regulatory response so far has carried only circular numbers.

MAS's Third-Party Risk Management and AI Risk Management guidelines are both still in consultation, a process due to close before either framework becomes binding, which means ACT's proof-of-concept output could end up folded into those rules or stay voluntary industry practice indefinitely. Hong Kong has not signalled which model it prefers. The choice determines whether HKMA-supervised institutions get a seat at that table or read the finished guidance after Singapore's six have already shaped it.

Sources

PREVIOUS COLUMNS, CYBER INTEL DESK
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.