Cyber-Financial Contagion and the Rupiah: Common-Mode AI Risk in Payment, FX, and Confidence Infrastructure

Rupiah Stability Watch · 2026-09-10

The mechanism

A cyber or AI incident becomes rupiah-relevant not because an algorithm “moves the currency,” but because people must trust three ordinary things at once: rupiah payments settle, records can be reconstructed, and the authorities can explain what happened while markets are still open.

That is the useful reading of Alex Leytes’s September 2026 arXiv paper, “Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System”. The paper studies a specific mechanism: banks share a small set of AI vendors for fraud screening, credit decisioning, AML triage, analytics, and internal support. If one systemic vendor is compromised, the first damage may look operational — distorted model outputs, delayed fraud review, unavailable services, corrupted telemetry. Only later does it look financial.

For Indonesia, the rupiah channel sits between those two moments. The currency risk is not that a payment outage mechanically depreciates the rupiah. It is that a common-mode operational failure can turn into a confidence test if households, firms, banks, money-market participants, or foreign investors lose confidence in settlement, reconciliation, market data, incident disclosure, or supervisory control.

This extends, rather than repeats, the Rupiah Stability Watch perimeter built in earlier pieces. The September 9 weekly monitor described a calmer rupiah screen sitting beside a busier operating ledger. “Agentic AI Operational Risk and the Rupiah” placed autonomous systems inside the financial-stability perimeter: payment continuity, FX and money-market functioning, vendor concentration, cyber incident response, and data integrity. “When the Log Can Be Spoofed” treated audit-trail trust as a second-order currency risk. “Beyond AI Scores” and “Who Is the Model?” argued that model identity and process evidence matter when many institutions depend on similar systems. Brent above $100 remains only the macro backdrop here: when oil and budget pressure narrow the margin for reassurance, operational confidence matters more.

What the paper supports

The arXiv paper is not an Indonesia study. It is a model of a banking system exposed to shared AI vendors. Its contribution is to make the contagion chain explicit.

Leytes builds a four-layer network: AI vendors, financial institutions, interbank exposures, and customer accounts. The proposed CFC-Prop model combines an epidemic-style process at the vendor layer with an interbank clearing cascade. The CFC-GNN early-warning model then uses vendor telemetry and graph structure to identify vendors whose compromise would create larger downstream cascades. In the paper’s synthetic dataset — 60 vendors, 220 banks, about 2,500 vendor-bank service edges, and 1,400 interbank exposures — the results produce heavy-tailed loss distributions and strong sensitivity to patch latency. The reported early-warning model reaches AUROC 0.82 and AUPRC 0.60 against four baselines.

The supported claim is narrower than “AI will cause a banking crisis.” It is this: when many institutions rely on the same AI or security infrastructure, an apparently third-party operational incident can become correlated across institutions by design. Classical bank stress tests often treat shocks as institution-specific, immediately visible, or balance-sheet-first. A compromised shared model service may be none of those. It may degrade fraud triage or credit decision quality for days or weeks before the loss becomes visible.

The paper also makes patch latency a stability variable. That matters for supervisors. If the most connected vendor fixes, validates, and communicates a compromise quickly, the cascade may remain operational. If patching is slow or confidence in the patch is weak, the same event can spread through service dependencies, customer behavior, and interbank caution.

Indonesia’s exposed perimeter

Indonesia already regulates cyber resilience as a payment, money-market, and FX-market issue, not just an internal bank IT issue. Bank Indonesia Regulation No. 2 of 2024 covers information-system security and cyber resilience for payment-system providers, money-market and foreign-exchange-market participants, and other parties regulated and supervised by BI. Its stated rationale is direct: technology use can increase cyber-risk exposure, cause financial losses, and disrupt financial-system stability. It defines a cyber incident as a cyberattack that disrupts business or operational services and requires response or recovery, and it frames resilience around confidentiality, integrity, availability, business continuity, rapid response, and recovery.

That scope is important. The rupiah confidence perimeter includes the institutions that move payments and the institutions that support money-market and FX-market functioning. BI Regulation No. 2/2024 also names governance, prevention, handling, supervision, and collaboration as the regulatory scope; requires monitoring, early-warning thresholds, vulnerability scanning, analysis of cyber activity logs, and incident escalation; and requires annual and incident-based reporting to BI.

OJK’s 2025 Artificial Intelligence Governance for Indonesian Banks adds the bank-side AI layer. OJK says the governance guide is meant as a minimal benchmark for responsible AI development and implementation in banking, complementing existing OJK digital-transformation, IT implementation, cyber defense, digital maturity, and digital resilience frameworks. That is the right placement: AI governance is not separate from operational resilience; it is one of its newer surfaces.

The payment rail itself is also larger than a back-office concern. BI-FAST was launched as national fast-payment infrastructure, part of the payment-system digitalization reforms alongside QRIS, SNAP, and regulatory reform. Bank Indonesia’s own QRIS page presents QRIS as the national QR payment standard used to facilitate payment transactions in Indonesia. BI’s Q2 2026 monetary policy reporting says retail transaction volume processed through BI-FAST reached 1.529 billion transactions, worth Rp3,777 trillion, in the second quarter of 2026. A rail of that size is not just convenience infrastructure. It is part of the daily evidence that rupiah transactions work.

Five contagion paths to watch

  1. Shared AI or security vendor failure.

The cleanest cyber-financial contagion path is a vendor used by many institutions at once: fraud detection, AML alert triage, endpoint detection, model hosting, feature stores, customer-support agents, or transaction-risk scoring. If the vendor is unavailable, many institutions slow down together. If the vendor is compromised but available, the more dangerous failure is false confidence: banks continue processing on distorted outputs.

Rupiah relevance: customers see failed or delayed payments; banks tighten transaction approvals; supervisors must reassure without knowing whether the vendor failure is contained.

  1. Corrupted payment, market, or reconciliation data.

An integrity failure is worse than a simple outage. If balances, transaction statuses, fraud labels, sanctions flags, or market data are wrong, institutions may not know which records to trust. This is where the earlier “When the Log Can Be Spoofed” perimeter becomes practical. In a currency-relevant incident, the question is not only “is the system back online?” It is “which ledger is true?”

Rupiah relevance: settlement may continue technically while trust in reconciliation weakens. That slows institutional risk-taking and can widen the distance between displayed liquidity and usable liquidity.

  1. Automated incident response causing disruption.

AI-assisted security systems can contain attacks faster than manual teams. They can also over-contain. A common playbook, common detection model, or common response agent could freeze legitimate flows across several banks or payment providers at once: account holds, blocked merchant categories, throttled APIs, revoked credentials, or isolated systems.

Rupiah relevance: the first public signal may look like a payment disruption, a compliance disruption, or a bank-service disruption rather than a cyberattack. The confidence test becomes communication: can BI, OJK, operators, and banks explain what was stopped, why, and how normal service will resume?

  1. Liquidity and FX-market communication failure.

BI’s 2024 cyber regulation explicitly reaches money-market and foreign-exchange-market actors. This matters because currency confidence is partly a communication system. If a cyber incident interrupts trading access, benchmark data, settlement instructions, treasury operations, or the public narrative around reserve/intervention capacity, market participants may step back even if the banking system remains solvent.

Rupiah relevance: thin liquidity can exaggerate price moves. A technical incident becomes a currency incident when participants cannot distinguish “temporary operational noise” from “unobservable balance-sheet or settlement risk.”

  1. Cross-institution model dependency.

Even without one named vendor, many institutions may depend on the same foundation-model provider, MLOps stack, cloud region, open-source model, data vendor, or evaluation benchmark. That creates common-mode behavior: the same false positive, hallucinated instruction, bad update, or security rule appears across institutions that believe they are independently controlled.

Rupiah relevance: independent-looking banks may make correlated operational decisions. That is the quiet systemic risk: no one has to intend a run or a market shock for the system to move together.

What the evidence does not support

There is no evidence in the sources reviewed here that Indonesia is currently experiencing cyber-financial contagion of this kind. This piece should not be read as a prediction of a rupiah break, a claim about a live BI-FAST or QRIS failure, or an allegation against any named bank, vendor, or regulator.

The arXiv paper is also synthetic. Its model is useful because it clarifies mechanisms: vendor concentration, bank AI dependency, interbank exposure, patch latency, and early-warning telemetry. It does not estimate Indonesia-specific loss distributions. It does not prove that a real vendor compromise would produce the same cascade size in Indonesia. It does not replace supervisory exposure data.

The most useful claim is perimeter risk. Indonesia’s digital payment scale, BI’s explicit inclusion of payment, money-market, and FX-market cyber resilience, and OJK’s bank AI governance all point in the same direction: the right question is no longer whether cyber and AI incidents belong on the rupiah ledger. They already do. The question is whether the exposure map is good enough before the first common-mode incident tests it.

The least-harm supervisory path

The proportional path is not to slow payment digitalization or treat every AI tool as a currency threat. That would create its own harm. The least-harm path is to make dependency visible before stress.

First, map vendor concentration across payment providers, banks, money-market actors, FX-market actors, and critical support providers. The map should distinguish ordinary outsourcing from systemic common-mode dependency: model hosting, fraud scoring, transaction monitoring, cloud regions, endpoint/security operations, identity systems, and reconciliation tooling.

Second, require scenario testing that treats integrity failure as seriously as availability failure. A payment rail can be “up” while its risk scores, logs, customer messages, or reconciliation data are wrong. The test should ask how institutions reconstruct truth under pressure.

Third, set patch-cycle and communication expectations for systemic vendors. Leytes’s model highlights patch latency. BI Regulation No. 2/2024 already requires readiness, detection, response, recovery, reporting, and collaboration. The missing operational edge is often not the rule but the clock: how fast a critical vendor can identify affected clients, validate a fix, preserve evidence, and support public reassurance.

Fourth, keep rupiah communication separate from blame. In the first hours of a cyber incident, the public needs to know what still settles, what is delayed, what records are safe, what fallback channels exist, and when the next update will arrive. Attribution can wait. Confidence cannot wait indefinitely.

Watchlist

Rupiah Stability Watch should treat the following as operating-ledger indicators, not panic signals:

What I am uncertain about

The largest unknown is Indonesia’s actual cross-institution AI and security-vendor dependency graph. Public regulation shows that BI and OJK are attending to cyber resilience and AI governance, but the systemic concentration map is necessarily supervisory rather than public.

The second unknown is how much of Indonesia’s payment and market infrastructure shares common detection, identity, cloud, model, or incident-response tooling. Vendor names matter less than correlated failure modes.

The third unknown is behavioral. A contained cyber incident can still become currency-relevant if communication is slow or contradictory; a technically severe incident can remain contained if records are reconstructable and the authorities communicate clearly.

The practical conclusion is sober: common-mode AI and cyber dependency is now part of the rupiah confidence perimeter. The work is to see it before it becomes a headline.

Sources

  1. Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System — mechanism, model scope, synthetic dataset, results, and limits of the cyber-financial contagion paper
  2. Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System PDF — paper details on four-layer network, patch latency, supervisory framework, and conclusion
  3. Peraturan Bank Indonesia Nomor 2 Tahun 2024 — BI cyber-resilience scope for payment-system providers, money-market and FX-market participants, incident response, monitoring, and reporting
  4. Artificial Intelligence Governance for Indonesian Banks — OJK AI governance guide as a minimal benchmark for responsible AI in Indonesian banking
  5. BI Launches Bank Indonesia Fast Payment — BI-FAST as national fast-payment infrastructure and part of payment-system digitalization reform
  6. Quick Response Code Indonesian Standard (QRIS) — QRIS as Indonesia’s national QR payment standard for payment transactions
  7. Monetary Policy Report - Quarter II 2026 — BI-FAST Q2 2026 transaction volume and value