Andrew Bailey, who serves as both the chair of the Financial Stability Board (FSB) and as governor of the Bank of England, has told G20 central bank governors and finance ministers that emerging artificial intelligence models represent a growing threat to the stability of the global financial system.
In a letter distributed on Monday to officials across the Group of 20 economies, Bailey pointed to a string of recent incidents in which new AI models created by companies including OpenAI, Anthropic and Meta Platforms were used to carry out hacks of other organisations via the internet. Those episodes underlie regulators' concern that these advanced systems can uncover previously unknown vulnerabilities in financial institutions' cyber defences and adapt rapidly to circumvent newly implemented fixes.
"The risk landscape has been further complicated by the emergence of frontier AI models, which are showing increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities," Bailey wrote.
Bailey warned that the effects of AI-driven disruptions would not be confined by national boundaries. He noted that the shared technology providers and infrastructure forming the backbone of the global financial system mean an incident in one jurisdiction could have consequences elsewhere. "Differences in legal frameworks, cyber capability, resilience and recovery capacity across jurisdictions could therefore have consequences well beyond the jurisdiction in which an incident originates and may themselves become a source of vulnerability," he wrote.
To reduce the danger of an AI-facilitated cyberattack propagating across the financial system, Bailey said regulators need to place a higher priority on protocols that manage the safe release of new models. He stressed that many jurisdictions lack the necessary processes to oversee the development, release and deployment of advanced frontier AI models, increasing risk to the financial sector and beyond. "Many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond," he wrote.
Bailey also urged banks and other financial firms to ready themselves for more extreme scenarios. He warned of the prospect of "more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies," and said that emergency preparations should include the capacity to rebuild computer systems swiftly after catastrophic damage.
He underscored the operational demands this places on firms and regulators alike, calling for robust response and recovery abilities. "These developments reinforce the importance of robust response and recovery capabilities, including the ability to restore critical systems and data from 'bare metal' following a significant cyber incident," Bailey wrote.
The European Central Bank has already directed eurozone banks to provide an action plan addressing the elevated risks from new AI models by October 31, a specific regulatory step referenced in Bailey's letter.
G20 finance officials were scheduled to convene later on Monday in Asheville, North Carolina, where the need for coordinated oversight of AI-related financial risk is expected to be an item of concern. The FSB serves as the coordinating body for financial regulators across the G20.
Context and implications
Bailey's letter frames frontier AI not merely as a technological innovation but as a source of systemic cyber risk that can cross borders via common service providers and shared infrastructure. His recommendations focus on both regulatory processes for model release and operational resilience at individual firms, reflecting a dual approach: slow or control the deployment of risky models, and strengthen the capacity to recover when incidents occur.