Bank of England, FCA and Treasury Raise Alarm Over Frontier AI
Bank of England, FCA and Treasury Raise Alarm Over Frontier AI
https://www.infosecurity-magazine.com/news/bank-england-fca-treasury-alarm/
Publish Date: 2026-05-18 05:00:00
Source Domain: www.infosecurity-magazine.com
The UK’s financial services firms must take active steps to manage the cybersecurity risks stemming from frontier AI, the UK government, the UK’s Financial Conduct Authority (FCA) and Bank of England have said.
A missive from the trio on May 15 was intended to clarify and reinforce their message “as the operating environment becomes more complex”.
It warned that the sector must put in place “effective protective, detective, threat containment and cyber-response capabilities” in order to mitigate cyber risks posed by the rapidly advancing technology.
Read more on frontier AI: What Fronter AI Models Like Mythos and GPT-Cyber Mean for Modern Cybersecurity.
“The cyber capabilities of current frontier AI models are already exceeding what a skilled practitioner could achieve, and at a significantly higher speed, greater scale, and lower cost,” it noted.
“These capabilities, if used maliciously, amplify cyber threats to firms’ safety and soundness, customers, market integrity and financial stability. As more advanced models become available, these risks are expected to increase. Firms that have underinvested in core cybersecurity fundamentals are likely to become progressively more exposed.”
Time to Take Action
The statement urges action across several domains:
- Governance and strategy: boards and senior management must have “sufficient understanding” of frontier AI risks and make investment decisions that reflect the increased threat. This includes protecting unsupported systems and taking out cyber insurance
- Vulnerability management: Firms should be able to “triage, prioritize, risk assess and remediate vulnerabilities” rapidly and at scale – using automation where necessary while mitigating any operational risks
- Third-party risk: Firms should effectively manage frontier AI cyber risks from supply chains, including open source software. They should be able to remediate vulnerabilities identified by third parties at…