Your Bank Is the Target - The IMF Just Said It's Inevitable | Full Episode Transcript
- Michael Routhier

- May 13
- 10 min read

The International Monetary Fund just used a word you don't hear from the world's most cautious financial institution very often: inevitable. Not possible. Not likely. Inevitable. AI-powered cyberattacks on the global banking system, they said, will happen. The only question is how bad the damage is when they do.
In this episode, we break down exactly what the IMF's warning means for your savings, your pension, and your daily access to your money; in plain language, without panic, and without pulling any punches about the billion-dollar institutions that created this vulnerability in the first place.
And then there's the bigger question nobody is asking loudly enough; who decided how AI gets used? Because the same technology being used to detect cancer in hospitals is being used to find weaknesses in the software your bank runs on. Same technology. Different intentions. Different consequences.
Your Six-Step Protection Plan:
Know your CDIC coverage — confirm your deposits are structured correctly at cdic.ca
Keep a paper record — account numbers, institution names, phone number on the back of your card, stored somewhere physical
Keep a small amount of cash accessible — enough for a few days of expenses if ATMs go offline
Turn on two-factor authentication — on every banking app, today
Know who to call — the number on your card, CDIC at 1-800-461-2342, your local branch
Be deeply suspicious of any "help" during a crisis — scammers will be faster than the news
Hey, welcome back. I want to start today's episode with a word, just one word, and it's not bird. That word is inevitable.
That's the word the International Monetary Fund used last week when they published a warning about AI-powered cyberattacks on the global banking system. Not possible, not likely, not, well, we should probably keep an eye on this, inevitable was the word. Now, the IMF is not a dramatic organization by any means.
They don't do press releases for fun. They are the most cautious, slow-moving, carefully worded financial institution on the planet. And when they write the word inevitable in a public document, they're not trying to scare you.
They're just managing expectations. And I think you deserve to know what those expectations actually are. So today, that's what we're doing in plain language, no jargon, no panic, just the truth and what you can actually do about it.
But I want to start off with a question. I want to ask you something before we get into the details. When you think about AI, and I know we talk about AI a lot on this show, what comes to mind? A chatbot that writes emails? A tool that helps doctors read x-rays? Maybe something that feels a little too human when you talk to it? Here's the question I keep coming back to, and it's one that shapes everything we're talking about today.
Who decided how AI would be used? Not who invented it. Who decided, and keeps deciding, what it gets pointed at? Because here's the thing, the same AI technology being used to detect cancer in hospitals is being used to find vulnerabilities in the software your bank runs on. Same technology, different intentions, different consequences.
And the people making those decisions are not elected. They are not regulated in any meaningful way, and they are in many cases, moving faster than the laws designed to govern them. That's not a conspiracy theory.
That's just Tuesday. Now let's get into what the IMF actually said right now. Every major bank, every payment processor, every financial institution you interact with, your bank, your pension administrator, your investment platform, runs on a small number of shared software platforms and shared cloud infrastructure.
Think of it like the plumbing in a large apartment building, 50 separate units, but every single one of them connected to the same pipes. Now in the past, a cyber attack hit one target at a time. You breach one bank, cause damage there, and every other bank watches what happened and patches their systems before the same thing hits them.
One lock, one key, one door at a time. But AI has completely changed that equation. An AI-powered attack can scan every institution running the same software, simultaneously find the same vulnerability in all of them at once, and exploit it everywhere, all at the same time.
The IMF has a name for this, has a term for this, it's called correlated failure. I call it terrifying. Think of it this way.
Imagine someone discovered a master key that opens every lock in every bank in every city at the same time, on the same night. That's what we're talking about here today. And now here's the part that should make you set down your coffee.
Anthropic, one of the leading AI companies in the world, recently released a controlled preview of an AI model that can find and exploit vulnerabilities in major operating systems and web browsers without technical expertise. Keep that in mind. You no longer need to be a hacker.
All you need to know is how to have a conversation with AI. Now the IMF cited this specifically as evidence of how fast the threat is escalating. These are their words, not mine, here they are.
Defenses will inevitably be breached, so resilience must also be a priority. That word inevitability, inevitable, it's inevitable, inevitably, is doing a lot of work in that sentence from the start of the show. Now I want to step back for a second because there's a bigger question underneath all of this that I don't think gets asked loudly enough.
We talk a lot about what AI can do. We talk about what AI will do. We almost never talk about what AI should do and who gets to decide that.
There's a concept I come back to often. I think of it as the virtuous machine question. Can a machine be ethical? Can it be moral? Can it make decisions that reflect values, human values, rather than just optimizing for an outcome? And here's where it gets uncomfortable because right now the AI being used to attack financial systems, it doesn't have an agenda, it doesn't hate your bank, it has no malice, it's doing exactly what it was designed to do, but it's being efficient.
The problem isn't the machine, the problem is the human who aimed it. And that brings me back to my earlier question. Who decided how this technology would be used? Who is accountable when it goes wrong? And why are we, us, the ordinary people with savings accounts and pensions and decades of hard work stored in digital form, the last ones to be told about it? Those are not rhetorical questions, by the way.
I genuinely want you to sit with those for a while. Now, why this matters specifically for you listening, and I'll be direct, if you're in your 60s, 70s, or 80s, you are more likely to have accumulated savings, pension income, investment accounts, and fixed assets built over decades of hard work. You have more to lose from a financial system disruption and potentially less time to recover from it.
And that's not a judgment, that's just arithmetic. Now, a large-scale cyber attack does not mean your money evaporates overnight. And I'm talking about Canada because this is where we're at.
Now, Canada's deposit insurance system, the CDIC, protects deposits up to $100,000 per depositor per category at member institutions. Your money has real protection. And this should be in other places such as the US and Europe as well, so please keep that in mind.
But here's the practical risk nobody talks about. In the immediate aftermath of a significant attack, that's what they're not talking about, what happens? Access could be disrupted, ATMs could go offline, online banking portals could be inaccessible. In that window, those few days between an attack and full system recovery is exactly where two things happen.
People make bad decisions out of panic and scammers rush in with help. Now, the money isn't gone. The chaos is the weapon.
And this is the part that no one is saying out loud because I've been doing this long enough to recognize when an institution is telling you something important between the lines. Okay? The IMF does not do drama, as we talked about earlier. So when they write the word inevitable, what they are actually saying to banks, to governments and to regulators is stop treating this as a future problem.
They are also quietly saying the same thing to the rest of us. Now Marcus Aurelius wrote, confine yourself to the present. Not to paralyze yourself with worry about what might happen someday, but to deal with what is real right now before the moment of crisis removes your ability to choose calmly.
The IMF's warning is a present moment. It's telling us to prepare while preparing is still a measured act, not a panicked one. And what is actually in your control? Now I want to be honest with you about something.
You cannot prevent a large scale AI cyber attack. Nobody listening to this podcast can do that. That is not defeatism.
That is clarity about where your energy is useful and where it isn't. Now Epictetus built his entire philosophy on this one distinction. Some things are in your control, some things are not.
Now wisdom, real wisdom is knowing the difference and acting accordingly. So here's what is genuinely in your control right now, today. Number one, know your CDIC coverage.
Now again, this is for Canada, but there are, you know, the FDIC, I believe in the U.S. and some other organizations within Europe, but the Canada Deposit Insurance Corporation protects deposits up to $100,000 per category. That'll be checking, savings, RRSPs, RRIFs, TFSAs at member institutions. Go to cdic.ca and confirm your deposits are covered and structured correctly.
If you have more than $100,000 in a single category at a single bank, have a conversation with your financial advisor about how to structure it properly. Now number two, now this is for everybody, keep a paper record of your accounts. Account numbers, institution names, the phone number on the back of your card, written down somewhere physical, not only on your phone, because if digital systems are disrupted, you want to be able to make calls and give real information to real people.
Now number three, keep a small amount of physical cash accessible, not a fortune, enough to cover a few days of expenses of ATMs and card systems are temporarily down. This applies to power outages, storms, and even cyber attacks equally. Basic emergency preparedness.
Number four, turn on two-factor authentication on your banking apps, and you should have this on anyhow. Every major Canadian bank offers this. Turn it on.
It is the single most effective thing you can do to protect your individual account from unauthorized access, and I strongly urge it. Now number five, know who to call, and again, check in your locality or your country to find out who it is you would call. So for here, the number on the back of your bank card is one.
You can also call the CDIC, this is Canada, at 1-800-461-2342, or your local branch, your local bank branch. Have these numbers written down or saved in your phone before you ever need them. And number six, I really want you to be deeply suspicious of any quote-unquote help that arrives during a crisis.
If there ever is a major banking disruption, scammers will be ready within hours. And I mean that whole, I can't stress that. Calls, texts, emails claiming to be from your bank, offering to secure your account, these are going to go out like wildfire.
They will be faster than the news coverage. They will sound official, calm, and helpful. Hang up the phone.
Call the number on your card directly, every time, no exceptions. And there's one more thing I need to say. The financial system's vulnerability to AI-powered attacks is not primarily a technology problem.
It's a structural one. Banks and financial institutions have known for years, years, that running on shared infrastructure creates shared risk. The consolidation that makes the system efficient also makes it fragile.
The same drive for profit that closed your local branch and moved everything online also created the single point of failure that an AI can now exploit at scale. That was a choice made by people with power and resources and full knowledge of the trade-off they were making. Now Seneca wrote, it is not that I dare too little, it is that I aim too low.
The institutions managing our financial infrastructure have, for years, aimed at efficiency, aimed at profit. They aimed too low at resilience, too low at protection, and too low at being honest with the people whose life savings they were entrusted with. Now the IMF's warning is an acknowledgment of that, a belated one, but a real one.
And you know what? We deserve better from billion-dollar institutions that have been collecting our deposits, charging us fees, and closing our branches for decades, and apparently spending that time building a system fragile enough that one well-aimed AI can knock it sideways. That is unacceptable, but it is the reality, and knowing it is, how you protect yourself from it, that's the reality of this. But before I go, before I let you go, I want to ask you a few questions, and I mean this genuinely.
I want to hear what you think. Do you trust that your bank is taking this seriously? Do you think the companies building AI should be held legally responsible when their technology is used to cause financial harm to ordinary people? And here's the big one. If an AI, a machine with no malice, no agenda, just pure efficiency, causes a financial collapse that wipes out someone's entire retirement savings, who's responsible? The machine? The programmer? The company? Oh, the regulator who didn't act? These are not abstract questions.
They are the questions that are going to define the next decade of your digital life. Now the links to everything we talked about today are in the show notes and in the full post at techforgrownups.com. So this is Tech 4 Grown-Ups. Subscribe wherever you're listening from, and I will talk with you in the next one.
Stay sharp.
📚 Referenced in This Episode
🇨🇦 Canada Deposit Insurance Corporation (CDIC): cdic.ca | 1-800-461-2342
🌐 IMF Global Financial Stability Report — AI and Cyber Risk: imf.org/en/Publications/GFSR
📖 Companion blog post: [Your Bank Is the Target — What the IMF's AI Warning Actually Means for Your Money]



Comments