Summary
- FSB chair Andrew Bailey says frontier AI could materially alter the speed, scale, and economics of cyber risk.
- Shared technology providers can allow disruption to spread across financial institutions rather than remaining an isolated security incident.
- Regulators are increasingly focusing on recovery, third-party resilience, vulnerability management, and safer model release alongside conventional cyber defence.
Frontier artificial intelligence has moved into the financial-stability agenda, with the Financial Stability Board warning that more capable models could change the speed, scale, and economics of cyber attacks across an industry dependent on common technology providers and interconnected market infrastructure.
Andrew Bailey, FSB chair and governor of the Bank of England, made frontier AI’s potential impact on cyber risk the most immediate financial-system concern in his latest letter to G20 finance ministers and central bank governors. He called for stronger response and recovery capabilities at financial institutions and greater resilience among the critical third parties on which they depend.
The concern reaches beyond whether an individual bank suffers a data breach. Payments, trading, clearing, settlement, telecommunications, cloud infrastructure, software, identity systems, and market data are extensively interconnected, allowing a weakness in shared technology to affect several institutions or services at once.
More capable AI can alter that risk by making parts of vulnerability discovery, exploitation, reconnaissance, and attack execution faster or cheaper. The same technology can also support defenders, but the regulatory problem emerges if offensive capability compresses the time available for security teams to detect weaknesses, test fixes, and deploy them safely.
Shared infrastructure creates correlated failures
Financial regulation has treated cyber resilience as an operational issue for years, although frontier AI changes the potential tempo of an incident. A vulnerability that once required sustained human expertise to find and exploit can become more dangerous if increasingly autonomous tools make those capabilities available more quickly or to a wider set of attackers.
That does not require a completely novel form of cyber attack. Existing weaknesses become more serious when exploitation can begin sooner, attacks can be repeated more cheaply, and several targets using the same technology can be probed in parallel.
Financial institutions then face an awkward defensive trade-off. Faster patching reduces the time an attacker has to exploit a vulnerability, but hurried changes to critical systems can themselves cause outages or introduce new weaknesses, particularly in environments where software has to interact reliably with payment, trading, and settlement infrastructure.
The FSB is therefore putting greater emphasis on response and recovery rather than assuming prevention will always succeed. Institutions need to know how critical systems would be rebuilt, how data would be restored, and how essential services would continue if several defences or a widely used supplier failed at the same time.
The supplier issue connects with broader industry concern over AI-enabled cyber attacks. Techopia’s Tech coalition calls for AI cyber-defence surge examined a parallel push from technology, telecoms, finance, and security organisations for more coordinated defensive capability as model performance improves.
Third parties become part of financial supervision
Bank resilience increasingly depends on companies outside the banking sector. Cloud providers, software companies, data suppliers, telecommunications operators, and other technology businesses can support numerous financial institutions simultaneously, creating concentration even where each bank has diversified its own internal systems.
Frontier AI adds two separate exposures to that structure. Models can strengthen attackers targeting financial infrastructure, while the financial industry itself can become more dependent on a relatively small group of companies providing AI models, computing capacity, cloud platforms, and specialist technology services.
Bailey’s letter consequently argues for authorities to support safer and more responsible model release and deployment globally as well as improving resilience inside regulated institutions. National supervision alone has limits when a model can be accessed across borders and the supplier affected by an incident may serve customers in several jurisdictions.
The FSB has separately been developing proposed practices for responsible AI adoption in financial services, including governance, lifecycle controls, cyber risk, information-technology risk, and third-party dependencies. Together, those workstreams show financial regulators treating AI as both something institutions deploy and something that can alter the threat environment around them.
Defence has to accelerate without becoming brittle
Stronger model testing, vulnerability management, recovery exercises, supplier scrutiny, and software patching all increase the operational workload placed on financial institutions. The difficulty lies in accelerating those processes without making systems less reliable through rushed technical change.
AI can support some of the same work by helping defenders analyse code, identify suspicious activity, prioritise weaknesses, and automate parts of incident response. There is therefore no fixed assumption that attackers will maintain a permanent advantage, although institutions cannot plan on defensive improvements arriving faster than offensive ones.
The FSB’s intervention moves the discussion beyond AI governance committees and model inventories. Financial stability depends on services remaining available through periods of severe stress, and increasingly capable cyber tools raise the possibility that technology failures could become more simultaneous, more difficult to contain, and more strongly correlated across institutions.
That shifts the resilience benchmark. Banks and market operators still need to prevent attacks where possible, but supervisors are increasingly asking what happens after prevention fails — whether shared suppliers remain available, whether critical data can be restored, and whether payments, trading, clearing, and settlement can continue while several parts of the technology stack are under pressure at once.












