Tech • AI • Robotics • Game

VIDEO
ENFR

The Defender's Window at enterprise scale with Standard Chartered

7/10
AIOpenAISeptember 29, 2026 at 10:01 AM13:01
Audio player
0:00 / 0:00

TL;DR

Standard Chartered is using frontier AI to shorten the gap between vulnerability discovery and exploitation by focusing on what is actually exploitable across applications, architectures and trust boundaries, rather than simply finding more code flaws.

KEY POINTS

Shift from vulnerabilities to exploitability

Standard Chartered says the main security challenge is no longer just identifying code weaknesses, but understanding which weaknesses can actually be exploited by attackers. In practice, attackers target attack paths that span systems, APIs, identities and trust boundaries, while many traditional security programs still focus too narrowly on repositories and asset inventories.

Why the defender window is shrinking

The bank’s security team sees frontier models as accelerating software understanding for both defenders and attackers. That compression of time means large institutions need to determine exploitable risks faster than adversaries, especially at global scale where the number of applications and interconnections is high.

Early use of Daybreak

Standard Chartered has been evaluating Daybreak to test whether AI can surface risks that traditional tools miss. Early results indicate that when the system can reason across architectures, microservices and multiple repositories, it produces more findings with higher relevance to real-world exploitability.

Context matters more than model choice

The bank’s main lesson so far is that context is more important than selecting a particular model. Better results come from supplying architecture diagrams, deployment models, dependency information, connected services and the intended purpose of an application, allowing the system to assess how code behaves inside a live environment rather than in isolation.

Trust requires evidence, not demos

Security leaders said AI-generated findings only gain credibility when they are validated jointly with developers. The bank is using cross-functional teams that combine application security and engineering to check findings against code, deployment architecture and runtime environment before acting on them.

Remediation is part of adoption

Internal buy-in has depended on showing that AI can improve remediation efficiency, not just generate another dashboard or backlog item. The approach emphasizes root-cause analysis so teams can avoid repeating insecure design patterns, and it also uses AI to help fix issues rather than merely flag them.

Security is being repositioned as an enabler

A major organizational goal is to move security away from its historical role as a gatekeeper. The bank is integrating security checks into development pipelines and pushing access to exploitability evidence earlier in the software development lifecycle, allowing developers to test and prioritize issues sooner.

Strong foundations remain essential

The rollout has reinforced a familiar but urgent message: AI amplifies the quality of the environment it is deployed into. That makes reducing technical debt, limiting unnecessary language and technology sprawl, keeping architecture documentation current, and maintaining solid identity and access controls critical prerequisites for effective AI-assisted defense.

Unexpected gaps in software discipline

One surprise has been how often basic engineering context is incomplete, especially outdated architecture records. Those gaps reduce the quality of AI analysis and have become a practical obstacle to adoption, even as the bank says the broader results have generally aligned with expectations rather than uncovering radically new classes of flaws.

Scaling to a connected global estate

With operations across many markets and regulatory regimes, the bank says security tooling must scale beyond one repository at a time. It wants AI to run in sandboxed environments and analyze applications in bulk to map blast radius across interconnected systems, helping defenders understand how a breach in one application could propagate through the wider estate.

CONCLUSION

Standard Chartered is betting that AI-driven security will be most valuable when it maps exploit paths across complex systems and helps developers fix them early. The bank’s experience suggests the decisive advantage will come less from model novelty than from strong engineering foundations, rich architectural context and the ability to operate at scale.

Ask a question

More from AI