Models & Research

Bank of England’s Bailey warns G20 that frontier AI leads cyber risks

Andrew Bailey has told G20 finance ministers and central bank governors that frontier AI models now belong on the financial stability risk list. Writing as chair of the Financial Stability Board, he said the most immediate concern for the financial system is what those models do to cyber risk. The FSB published the letter on 31 August 2026, ahead of the group’s meeting in Asheville, North Carolina.

Bailey is Governor of the Bank of England, and the FSB coordinates national financial authorities across 24 countries and jurisdictions. That matters because his letter isn’t a domestic warning. It lands with the people who set bank rules across most of the world’s largest economies.

The mechanism he describes is speed. In the letter itself, dated 28 August, Bailey argues that capable models change the economics of attacking a system, not only the difficulty of it.

Frontier AI may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers.

Andrew Bailey, Chair, Financial Stability Board

That last clause carries the weight. The letter says cyber disruption spreads across jurisdictions through common technology providers, shared infrastructure and cross-border financial activity. So a breach at one heavily used supplier reaches many banks at once, which is why Bailey asks firms to prepare for simultaneous disruption rather than a single incident.

His recovery test is deliberately blunt. Firms should be able to restore critical systems and data from “bare metal” after a significant cyber incident, meaning from machines carrying no operating system, as SiliconANGLE noted. The letter also warns that a faster patching pace could create problems of its own if change, testing and recovery processes can’t adapt safely.

Then comes the governance gap, which is the sharpest line in the document.

Many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond.

Andrew Bailey, FSB Chair, in his letter to the G20

We’ve watched that gap play out at the lab level already, when Z.ai delayed the open weights for GLM-5.3 over cyber risk with no external rulebook telling it to. Bailey wants safe and responsible model release and deployment treated as a global priority.

VulnerabilityWhat the letter points to
Sovereign debt marketsElevated issuance, shortening maturities, more leverage by some market participants
Private creditInterconnectedness with the rest of the system, liquidity mismatch, opacity
Asset valuationsStretched, particularly AI-related investments
Equity market leverageLeveraged ETFs, momentum-driven strategies including retail, hedge funds also exposed to sovereign debt
Frontier AISpeed, scale and economics of cyber risk, concentrated third-party providers
Source: FSB Chair’s letter to G20 Finance Ministers and Central Bank Governors, dated 28 August 2026.

The market half of the letter is about leverage meeting concentration. Bailey singles out the increasing cross-investment between AI companies and hyperscalers, and says leverage interacting with high valuations could amplify a future correction. That reading fits what the AI balance sheets already show, including Nvidia listing $33.5B of debt as a risk factor.

He isn’t alone on the timing. Days earlier, OpenAI, Anthropic, Google, Microsoft and dozens of other signatories, among them CrowdStrike, Citi and Capital One, published an open letter saying there’s a “limited window” to strengthen cyber defences, CBS News reported. A CrowdStrike report cited in that story found AI-enabled attacks rose 89% in 2025 against 2024.

Bailey’s framing isn’t one-sided, though. He writes that frontier AI offers significant opportunities to strengthen cyber defence, and that the real question is whether resilience and preparedness keep pace with capability. The FSB says it’s exploring the safe deployment of frontier models for cyber defence by financial services firms.

What’s missing is a rule. The FSB makes recommendations to national authorities rather than binding them, as CNBC noted, so nothing in Asheville changes a bank’s obligations this week. The thing worth watching is whether the FSB’s frontier AI work turns into a published standard, because that’s the point where a cyber programme has to change.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Leave a Reply

Your email address will not be published. Required fields are marked *