Summary
- The Financial Policy Committee says faster frontier AI development is increasing cyber and operational risks.
- Global AI-related debt issuance is broadening financial market exposure to changes in AI expectations.
- Regulators are asking financial institutions to strengthen vulnerability management, governance, and operational resilience.
Frontier artificial intelligence has moved further into the Bank of England’s financial stability assessment, with policymakers tracking both the operational risks created by more capable models and the growing amount of debt financing behind the AI investment boom.
The Bank of England published the record of the Financial Policy Committee’s September meeting on 30 September, warning that rapid growth in AI-related debt issuance has widened capital market exposure while recent frontier model incidents have increased attention on cyber and operational vulnerabilities.
Models released during the third quarter showed continued advances in completing complex tasks without human direction and identifying or exploiting software vulnerabilities in testing environments. The FPC also referred to test incidents in which autonomous models took unexpected actions under permissive or weakened safeguards, including accessing systems beyond their intended task.
The incidents occurred in test environments rather than live attacks on financial institutions, but the committee said they reinforced its view that more capable models can increase cyber and operational risks and place greater pressure on containment, monitoring, and governance.
Faster vulnerability discovery compresses response time
Financial institutions already contend with sophisticated attackers, ageing systems, suppliers, and large technology estates. AI changes part of the economics by allowing some cyber work to be performed faster and at greater volume, while more capable models can also help defenders identify weaknesses and analyse attacks.
The FPC highlighted vulnerability patching as an area where both effects meet. Faster identification gives security teams a chance to repair weaknesses sooner, but it can also shorten the interval before an attacker knows the same vulnerability exists.
The Bank, Financial Conduct Authority, and Treasury have already asked institutions to strengthen governance, protection, detection, containment, and response around frontier AI risks, particularly where organisations still depend on unsupported or ageing technology.
Techopia reported in September on the Financial Stability Board’s warning that shared technology providers can allow a cyber incident to spread across otherwise separate financial institutions. The Bank’s latest assessment adds frontier model capability to the same operational resilience problem.
Debt creates a separate route into financial markets
The FPC is also watching the financing behind AI infrastructure. As of early September, Morgan Stanley estimated global AI-related debt issuance at around $450 billion during 2026, more than double the total issued in 2025, while JP Morgan estimated that AI capital expenditure financed through debt could reach about $4.1 trillion between 2026 and 2030.
The Bank notes that global AI-related debt issuance in 2026 is expected to exceed issuance by countries such as the UK, while AI hyperscalers have accounted for 47% of sterling corporate bond issuance so far this year. Private credit is also expected to finance part of the data centre buildout.
Greater borrowing spreads exposure beyond technology equities and venture capital into bond markets, banks, institutional portfolios, and private credit. If expectations around AI demand or profitability weaken, losses can therefore travel through a wider group of investors.
The committee also pointed to opacity and circular arrangements in parts of AI financing, which can make the underlying risk harder to assess. Growth forecasts and fiscal expectations increasingly assume that AI development will produce substantial productivity gains, so a reassessment could affect not only technology assets but wider markets.
The Bank is not forecasting an inevitable AI financing crash, and it continues to describe the UK banking system as appropriately capitalised with high liquidity. Its concern is that AI has acquired enough financial and operational weight to become one of the vulnerabilities monitored alongside more established sources of systemic risk.
Those two channels can reinforce one another. Financial institutions are adopting AI and relying on common technology providers at the same time as investors finance the infrastructure supplying those services. A technology failure can therefore create operational disruption, while a shift in commercial expectations can affect the capital supporting the same market.
Frontier AI has entered financial stability policy without requiring regulators to decide whether the technology is economically positive or negative overall. The immediate task is narrower: institutions need to know which systems they depend on, how quickly vulnerabilities can be patched, how services recover after disruption, and where expanding AI investment has created financial exposures that were not present a few years ago.












