LONDON, Aug. 31, 2026 — The world’s most advanced artificial intelligence systems are no longer being viewed simply as a technology challenge for banks. One of the world’s most influential financial watchdogs is warning they could become a threat to the stability of the financial system itself.
Financial Stability Board Chair Andrew Bailey has identified the effect of frontier AI on cyber risk as the financial system’s “most immediate concern” arising from the rapidly advancing technology.
In a letter sent to G20 finance ministers and central bank governors ahead of meetings on Aug. 31 and Sept. 1, Bailey warned that frontier AI models are developing increasingly powerful autonomous, problem-solving and potentially offensive capabilities.
The danger is not merely that AI could help hackers launch better attacks.
It is that advanced models could fundamentally alter the speed, scale and economics of cybercrime, allowing attackers to identify weaknesses and potentially exploit them far more rapidly than traditional cyber defenses were designed to handle.
Why the Warning Has Suddenly Become More Serious
Bailey, who is also governor of the Bank of England, said regulators must ensure that improvements in AI capability are matched by improvements in resilience and preparedness.
That concern has been building throughout 2026.
The Bank of England warned in its July Financial Stability Report that rapid progress in frontier AI could materially increase risks arising from both cyber threats and operational vulnerabilities.
The Bank has been studying AI-related financial risk through several channels, including its use in banks and insurers, its growing role in financial markets, reliance on AI service providers and the changing external cyber-threat environment.
Bailey had already sounded a similar alarm in July, arguing that cutting-edge models capable of discovering vulnerabilities in computer systems represent a major challenge not just to individual companies but potentially to financial stability.
His central argument is straightforward: AI can strengthen both sides of the cybersecurity battle.
Banks can use increasingly sophisticated models to find weaknesses before criminals exploit them. But attackers may eventually gain access to similar capabilities.
That makes the race increasingly about which side can identify and fix vulnerabilities first.
One Weakness Could Hit More Than One Bank
The problem becomes more serious because modern finance is deeply interconnected.
Banks, payment systems, insurers and investment firms often rely on the same cloud infrastructure, software platforms, telecommunications networks and outside technology providers.
That creates what regulators fear could become a concentration problem.
A vulnerability affecting one widely used provider may not remain isolated to a single financial institution.
It could potentially affect multiple companies at approximately the same time.
The FSB specifically warned about the importance of resilience among critical third-party providers, while Bailey cautioned that heavy dependence on a relatively small number of technology companies could turn a technology failure or cyberattack into a broader confidence problem.
The International Monetary Fund has raised the same systemic concern.
In May, IMF officials warned that AI could dramatically reduce the time and cost required to discover and exploit vulnerabilities in widely used systems.
In an extreme scenario, the IMF said major cyber incidents could cause funding pressure, raise concerns about institutional solvency and disrupt financial markets.
Because banks share so much digital infrastructure, a cyberattack could become less like a conventional breach at one company and more like a correlated financial shock affecting multiple institutions simultaneously.
The Threat Is Not Theoretical for Regulators
Financial authorities have been examining the issue increasingly closely as the capabilities of advanced AI systems accelerate.
Earlier this year, Anthropic was preparing to brief the FSB about vulnerabilities that its advanced AI technology had identified within financial infrastructure, according to Reuters, after Bailey requested discussions with the watchdog.
Cybersecurity specialists warned that highly capable models could be especially significant for banks still dependent on older technology systems.
The FSB has meanwhile moved beyond simply identifying the problem.
In June, the organization released a consultation outlining 12 proposed sound practices for responsible AI adoption by financial institutions.
The recommendations cover organization-wide AI governance and the way financial firms manage AI systems throughout their development and deployment lifecycle.
The aim is to allow banks and other financial companies to capture AI’s benefits without introducing risks capable of spreading through the wider financial system.
But Cyberattacks Are Only Half of Bailey’s Warning
Buried alongside the cyber-risk warning is another issue that could matter just as much to investors.
The FSB remains concerned that global markets are vulnerable to a disorderly correction.
Bailey pointed to stretched asset valuations, vulnerabilities in sovereign debt and private-credit markets and growing leverage in equity markets.
The dangerous combination, according to the FSB, is that increasing leverage is interacting with high valuations, concentrated markets and intense investor optimism surrounding AI.
That could amplify losses if sentiment toward the AI sector suddenly reverses.
In other words, artificial intelligence is appearing on both sides of the global financial-stability equation.
AI enthusiasm has helped fuel investment and expectations of enormous future economic gains.
But the same technology is producing new operational and cybersecurity risks, while highly valued AI-related assets could themselves become part of a future market correction.
Why This Matters Beyond Wall Street
A major cyberattack against the financial sector does not have to steal money directly to become economically damaging.
An attack that interrupts payment processing, disables access to banking services or forces several institutions offline could create uncertainty about whether transactions will settle and whether customers can access funds.
Confidence is particularly important in finance.
Once institutions begin doubting whether counterparties, payment systems or critical technology providers are operating normally, a technical disruption can evolve into a liquidity or market problem.
That is why regulators increasingly emphasize recovery, not merely prevention.
The assumption is no longer that every attack can be stopped.
Financial institutions must instead demonstrate that essential services can continue—or be restored quickly—even after defenses are breached.
Bailey has said banks need stronger detection, faster vulnerability patching and credible recovery capabilities. The Bank of England already uses stress tests and penetration testing to examine whether regulated institutions can withstand serious disruption.
AI Is Also Part of the Defense
There is an important counterpoint.
The regulators are not arguing that banks should stop using artificial intelligence.
AI could also significantly improve cybersecurity.
Financial institutions can use advanced models to detect fraud, identify unusual network behavior, locate software vulnerabilities and respond to threats considerably faster than human cybersecurity teams working alone.
The IMF has argued that when attackers operate at machine speed, defenders will increasingly have to do the same.
That means the policy challenge is less about stopping AI adoption than ensuring institutions deploy it with adequate governance, human oversight, cyber testing, continuity planning and recovery systems.
The Next Battle Will Be Global
Perhaps the hardest problem is that neither financial markets nor cyberattacks respect national borders.
A vulnerability discovered in software used internationally could affect banks in multiple countries.
A disruption involving a major cloud or technology provider could cross jurisdictions almost instantly.
And an advanced AI model released in one country can ultimately influence cybersecurity conditions elsewhere.
That is why Bailey is calling for international coordination around the testing, release and deployment of frontier AI.
The FSB said authorities should support the safe and responsible release of advanced AI models globally, while financial institutions need credible response and recovery plans for increasingly sophisticated attacks.
The debate therefore is shifting.
For years, financial regulators primarily asked how banks would use AI.
Now they are confronting a much harder question:
What happens when increasingly powerful AI systems begin changing the environment in which the entire financial system must survive?
And if advanced AI really can make cyberattacks faster, cheaper and massively scalable, the next financial crisis may not begin with a collapsing bank or a plunging stock market.
It could begin with a vulnerability discovered in seconds—and exploited before the financial system has time to react.

Leave a Reply