Getting your Trinity Audio player ready...

As governments invest in artificial intelligence (AI) and cybersecurity, regulators warn of new vulnerabilities, and criminal networks are increasingly adapting the technology to expand their nefarious toolkits.

Recent developments from China, the United Kingdom, and the Asia-Pacific (APAC) region are demonstrating how AI is rapidly becoming intertwined with cybersecurity: governments are looking to AI and cyber capabilities as strategic assets, businesses are confronting a new generation of AI-enabled security challenges, and criminal networks are adapting the technology to make fraud operations more sophisticated and harder to disrupt.

AI key to China’s growth plans

China’s newly announced cyberspace strategy has put AI and other frontier technologies at the center of an ambitious effort to strengthen the country’s digital economy and cybersecurity capabilities, in the face of the United States’ dominance of the space.

On August 21, the Cyberspace Administration of China (CAC) and Central Cyberspace Affairs Commission (CCAC)—the Chinese Communist Party’s highest-level policy-making body for internet governance, and the agency in charge of cyberspace administration, regulation and enforcement, respectively—released an action plan outlining the country’s strategic goals for 2026 through 2030, which aimed for enhancing the competitiveness of cyberspace enterprises through advancements in technological innovation, product quality and service delivery.

The action plan seeks to promote cyberspace enterprises as the next frontier in China’s development as a cyber power, while boosting the country’s digital economy and broader economic and social modernization. It emphasized innovation, internationalization, and secure development, with the objectives of improving enterprises’ capabilities in technological innovation, product and service delivery, and industrial digitalization.

“Cyberspace enterprises, driven by network information technology and with cybersecurity and informatization as their main businesses, are a vital force in building a cyber power and play a crucial role in cultivating new productive forces and consolidating and enhancing international competitiveness,” the cyberspace authorities said. “The role of cybersecurity and information technology enterprises in empowering high-quality economic and social development will be more prominent.”

The plan is committed to significantly enhancing the overall strength of the country’s cybersecurity and information technology enterprises by 2030, with marked improvements in technological innovation, product competitiveness, and service competitiveness.

To achieve this, the action plan aims to encourage and support development in parallel with standardized development, combining policy guidance with legal management, and emphasizing both economic and social benefits.

Specifically, it proposed several actions, including the “Enterprise Cultivation and Service Action,” which establishes and continuously updates a database of “high-quality internet information technology enterprises,” and guides these enterprises to leverage their advantages in technology, talent, capital, and data to empower the growth of SMEs, actively participate in global cybersecurity technology cooperation, and build an internationally competitive ecosystem.

Other key actions involved strengthening research on and application of core technologies; empowering the digital transformation of the manufacturing industry, including the construction of digital villages and promoting green enterprises; an initiative to expand into overseas markets by building a service system for their overseas expansion; ensuring safe and orderly development to prevent disorderly competition and strengthen the rule of law in cyberspace; “optimizing the business environment,” to create a fair and competitive market environment; and finally, to guarantee development factors by strengthening financial support, data security and talent.

“The cybersecurity and information technology industry ecosystem and development environment will be comprehensively optimized, and a safe, standardized, healthy, and orderly institutional system will be further improved,” read the plan.

According to an August 24 report from local outlet China Daily, priority will be given to advancing frontier technologies, including quantum computing, blockchain, brain-computer interfaces, digital twins, and next-generation displays.

Extra resources will be allocated to companies engaged in AI research, with a strong emphasis on developing high-end AI chips, improving large language model performance, and promoting agentic AI technologies. The plan also encourages enterprises to actively participate in open-source projects and community building.

This focus on AI is in keeping with a recent push from China to rival the U.S. in the AI field. In July, Chinese President ​Xi Jinping laid out his ambition for Beijing to lead a global AI coalition of developing countries to challenge the U.S. dominance of the space, urging countries to seize the “historic opportunity” of open-source AI, while committing China to helping developing nations build AI capabilities.

The comments came just as leading private-sector players warned that the ongoing global AI memory chip shortage is set to continue or worsen as demand rises.

This shortage, along with China’s new action plan, reflects the strategic value that governments increasingly attach to AI and cybersecurity. But the rapid development of these capabilities is also creating a more immediate challenge for organizations already operating in the digital economy: keeping pace with the vulnerabilities that ever-evolving and advancing AI systems can uncover. That challenge is becoming particularly apparent in the financial sector.

Back to the top ↑

AI finds cyber gaps faster than firms can plug them

In the U.K., a recent review by the country’s top finance sector regulator found that frontier AI models are increasingly capable of identifying cybersecurity vulnerabilities faster than firms can fix them, raising questions not only about the technology itself but also about whether organizations have the governance, expertise, and processes needed to respond.

On September 2, the U.K. Financial Conduct Authority (FCA) released the results of a review into how finance firms are using, testing, and preparing for frontier AI models with cyber capabilities, with five main themes emerging from the study.

First, respondents reported that frontier AI is increasingly identifying cyber vulnerabilities faster than firms’ ability to fix them; second, frontier AI is becoming a test of organizational resilience, not just a tool; third, the value of frontier AI depends more on the governance, tooling, controls, human oversight and operational environment, than which model is being used; fourth, frontier AI is making foundational cyber and operational resilience more important; and finally, effective governance and human judgement remain critical.

When it comes to firms being unable to fix cyber gaps as fast as they’re found, and the importance of human expertise to solving this problem, the FCA said that: “Models can accelerate vulnerability discovery, code analysis and inform prioritisation, but firms continue to rely on specialist expertise to validate findings, assess relevance, determine priorities and make risk-based decisions.”

It added that “several firms observed that the benefits of autonomous discovery can be limited where processes cannot keep pace with the volume of output.”

For this reason, the regulator said it is important to ensure human cyber expertise, risk ownership, and decision-making authority remain closely integrated into how firms manage cyber vulnerabilities and security risks.

The report was aimed at operational resilience leaders, technology leaders, risk leaders, and cyber-resilience professionals, all of whom the FCA encouraged to “consider what the findings mean for you.”

In a broader context, the regulator’s report is just the latest example of a growing concern about the risks that advanced AI models increasingly pose to businesses across sectors—and, in the finance sector, potentially to macroeconomic stability as well.

In a letter to G20 Finance Ministers and Central Bank Governors last month, Chair of the Financial Stability Board—an international body that monitors and makes recommendations about the global financial system—and Governor of the Bank of England (BoE), Andrew Bailey, warned of the risks posed by frontier AI models, highlighting, in particular, their potential impact on cyber risk.

He called on authorities to take appropriate steps to support safe and responsible model release and deployment, and for financial institutions to ensure robust response and recovery capabilities and resilience amongst critical third-party providers.

While legitimate organizations are struggling to keep pace with the speed at which AI can identify and exploit weaknesses, the same technology is presenting new opportunities for those operating outside the law—something that is becoming all too apparent in the Asia-Pacific region, where organized cybercrime networks are combining increasingly sophisticated digital tools with decentralized structures to make their operations harder to detect and disrupt.

Back to the top ↑

APAC criminals turning to decentralization and AI tools

Cybercrime syndicates across the APAC region are evolving into sophisticated transnational criminal enterprises that increasingly employ decentralization strategies to evade detection and disruption, according to a new report by the Asia/Pacific Group on Money Laundering (APG), a regional inter-governmental body based in Australia.

The report, titled ‘Cyber Scam Hubs and Human Trafficking Report 2026’, draws on recent case studies, law enforcement experience, regional analysis, and insights from blockchain analytics to map the methods used by criminal networks in APAC, as well as the financial and technological enablers that allow scam compounds to operate at scale.

It found that organized criminal syndicates are utilizing “forced criminality” to staff scamming operations, with victims—typically recruited overseas through fraudulent job advertisements—coerced or forced into working in the cyber scam hubs and often subjected to horrific treatment and conditions.

Among the case studies examined by the research were examples of how criminals exploit different sectors and vulnerabilities, including weak oversight in special economic zones, the use of complex business structures to hide the identities of those behind these activities, and virtual currencies to make profits harder to trace and confiscate.

“The report shines a light on one of the most alarming developments in transnational organised crime across the Asia/Pacific region—the combination of cyber-enabled fraud and human trafficking,” Dr. Chris Black, Executive Secretary of the APG, said. “By understanding how these cyber scam hubs operate, it disrupts and disempowers the criminal networks behind them.” 

The APG said that the report highlights the complexity, adaptability, and transnational nature of cyber scam hubs and human trafficking, particularly in the APAC region, where a recent report from blockchain analysis firm Chainalysis showed that so-called ‘pig-butchering’—a long-con scam in which fraudsters build a relationship, often romantic, with a victim over time, then persuade them to invest increasing amounts of money into fake investment platforms—networks across Southeast Asia generate billions of dollars annually, often utilizing the digital asset space to transfer and launder the proceeds.

According to the U.S. Treasury, its citizens have been particularly targeted, with a government estimate reporting that Americans lost at least $10 billion in 2024 to Southeast Asia-based scam operations, a 66% increase over the prior year.

Global law enforcement authorities have made some progress in tackling the problem. In January, the Wall Street Journal reported that Chen “Vincent” Zhi, the alleged ringleader of one of the largest scam operations in Southeast Asia and wanted by the U.S. Department of Justice (DOJ), was arrested in Cambodia and extradited to China.

A couple of months later, in April, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) announced it had sanctioned Cambodian Senator Kok An and 28 others for operating scam centers across the Southeast Asian country.

This move was made to coincide with the—‘Scam Center Strike Force”—an initiative by the U.S. Attorney’s Office for the District of Columbia, the Department of Justice’s (DOJ) Criminal Division, the Federal Bureau of Investigation (FBI), and the U.S. Secret Service (USSS)—announcing a series of coordinated actions against Southeast Asian criminal organizations operating scam centers that “defrauded Americans of billions of dollars.”

However, just as authorities begin to get to grips with the scammers, criminals are evolving their tactics in response.

Another of APG Research’s key findings was the emergence of new tactics and technologies used by criminals, particularly decentralization and AI, which demonstrate increasing operational sophistication, enabling criminal syndicates to scale their activities while minimizing the risk of detection and legal accountability.

To meet this new challenge, the report identified several best practices, including enhanced domestic interagency and international coordination, which facilitates quick responsiveness from multiple authorities; enhanced public-private partnerships; dedicated awareness-raising campaigns; enhanced due diligence measures; and implementing any necessary changes to legislation or institutional framework to ensure they are suited to respond to the changing nature of cyber scams.

“These measures are critical to the detection, disruption and prosecution of cyber scam hub operators and the protection of victims worldwide,” APG Co-Chair Mitsutoshi Kajikawa said. “There are also a number of regional and international cooperation networks, including for asset recovery, which can be used to support regional actions.”

Alongside the report, which was co-led by Indonesia and the United Nations Office on Drugs and Crime (UNODC), the APG released a public database—in partnership with the Academy of Excellence in Financial Crime Investigation and Compliance at Griffith University—of more than 10,000 case studies from APG typologies, products, mutual evaluation reports, and publications spanning more than 20 years. 

The APG said the launch of the database marked a significant step forward in supporting AML efforts, offering a comprehensive collection of real-world case studies from across APAC and beyond to help organizations detect, understand, and respond to evolving financial crime threats.

“The typologies database enhances the fight against money laundering by providing a curated repository of case studies that highlight criminal methodologies, emerging trends and practical indicators to support risk assessment and a risk-based approach,” Dr. Black said. “It’s a valuable capability because financial crime often crosses borders, and criminal methodologies can quickly spread across jurisdictions.”

Taken together, the APG report, China’s action plan, and the U.K. FCA’s review of financial businesses reveal a common thread: AI and cybersecurity are no longer separate technological questions but are increasingly part of the same rapidly evolving ecosystem.

While governments see advanced technology as a means of strengthening their strategic and economic position, regulators are having to confront the speed and scale of the risks it creates, just as criminal networks are adopting those same capabilities for sophisticated fraud and evasion.

In other words, AI technology is increasingly reshaping the cyber landscape, creating new opportunities for economic progress, but also new vulnerabilities and opportunities for exploitation.

In order for artificial intelligence (AI) to work right within the law and thrive in the face of growing challenges, it needs to integrate an enterprise blockchain system that ensures data input quality and ownership—allowing it to keep data safe while also guaranteeing the immutability of data. Check out CoinGeek’s coverage on this emerging tech to learn more why Enterprise blockchain will be the backbone of AI.

Back to the top ↑

Watch: Understanding the dynamics of blockchain & AI

Advertisement
Advertisement