Andrew Bailey’s warning changes the scale of the AI security debate: the issue is no longer simply protecting an individual company from attacks, but addressing the possibility that technology vulnerabilities could affect confidence and stability across the financial system.
Andrew Bailey’s warning puts AI at the center of financial risk
The key warning is that artificial intelligence could turn cyber risk into a faster, more scalable and harder-to-manage threat for the financial system. The assessment was presented by Andrew Bailey, Governor of the Bank of England and Chair of the Financial Stability Board (FSB), in a letter sent to G20 finance ministers and central bank governors.
The FSB is an international body focused on identifying and addressing vulnerabilities that could undermine global financial stability. That gives Bailey’s warning a different significance from a conventional corporate cybersecurity alert.
The central issue is not simply whether criminals can use AI in attacks. The FSB’s concern is that advanced models could change the speed, scale and economics of cyberattacks, increasing pressure on financial institutions and the authorities responsible for supervising them.
Why the warning matters now
The message comes as frontier AI models demonstrate increasingly advanced capabilities in autonomy, problem-solving and task execution. For Bailey, those advances need to be accompanied by security mechanisms capable of dealing with their new capabilities.
What changes in the risk assessment
The discussion is moving from individual protection toward systemic resilience. A major failure at one institution can have much broader consequences when banks, technology providers and financial services share infrastructure and critical suppliers.
How AI could change the scale of attacks against banks

AI could increase the speed and scale of cyber operations, putting greater pressure on financial institutions’ defenses.
The difference lies in the ability to accelerate operations that previously required more time, resources and human intervention. The FSB believes advanced AI models could significantly change how cyber risk manifests across the financial system.
For a bank, this means defenses may have to deal with more than increasingly sophisticated attacks. Institutions may also need to respond to operations capable of adapting strategies, processing information and carrying out certain tasks at a speed that exceeds traditional attack methods.
The concern is connected to recent developments involving AI systems that have demonstrated unexpected capabilities during security evaluations. One example is the growing concern around increasingly autonomous AI systems, including the case covered in OpenAI slowed down Astra after identifying cybersecurity risks.
The issue, therefore, is not a prediction that a specific model will bring down banks, but the fact that offensive and defensive capabilities are evolving at the same time.
Speed is part of the problem
When an attack can be automated or accelerated, the window available for detection and response becomes smaller. For financial institutions, minutes or hours can matter when stopping an operation, protecting data and preventing an incident from spreading.
Scale increases potential impact
The second dimension is scale. A system capable of supporting operations against multiple targets could increase the number of institutions exposed at the same time. This does not mean an attack will necessarily hit several banks, but it makes containment and recovery mechanisms more important.
Why a problem at one bank could become systemic
Financial risk depends not only on the size of a bank but also on the connections between institutions, markets and technology providers. This interdependence makes cyber risk different from an isolated incident.
Banks rely on external providers for infrastructure, computing, security, processing and other essential services. When multiple institutions depend on a small number of critical providers, a significant disruption can create simultaneous effects across several market participants.
The FSB is specifically highlighting the need to strengthen the resilience of critical technology providers and shared services. The question is no longer only how an individual institution responds to an attack, but also how the wider financial ecosystem reacts when a common dependency is compromised.
The risk of technology concentration
Dependence on a small number of providers can create shared points of vulnerability. If an essential service fails or becomes the target of a significant attack, several institutions could experience related problems at the same time.
Confidence is also part of the equation
The impact does not have to be purely operational. A significant incident can affect the confidence of customers, investors and market participants. That is why the FSB treats AI-driven cyber risk as part of a broader discussion about financial stability.
Banks will need to treat AI as a resilience issue

For financial institutions, the challenge increasingly involves prevention, response and recovery from AI-powered attacks.
Responding to the new risk will not simply mean buying more security tools, but increasing an institution’s ability to withstand, respond to and recover from incidents. This is one of the main practical implications of Bailey’s warning for the financial sector.
The FSB argues that financial institutions need strong response and recovery capabilities. That means security must be treated as part of operational continuity rather than simply as a technical layer added to existing systems.
The warning also increases the importance of supplier governance. An institution may have strong internal controls and still remain vulnerable if it relies on external services that lack an equivalent ability to respond to incidents.
Security is no longer only an IT issue
The evolution of AI models brings cybersecurity, risk management, governance and business continuity closer together. For financial executives, this means AI adoption decisions must also account for the new risk vectors created by the technology itself.
Resilience must keep pace with adoption
The FSB is not questioning the expansion of AI across financial services. The challenge is ensuring that the speed of adoption does not exceed the ability of institutions and authorities to manage emerging risks.
The warning comes as AI capabilities reshape the cyber threat landscape
The FSB’s warning comes as technology companies are already seeing increasingly capable AI systems being used in cyber operations. That helps explain why the issue is no longer being treated solely as a distant possibility.
The AI ecosystem has already recorded incidents and security tests in which models demonstrated capabilities relevant to offensive tasks. This broader concern has also been highlighted in the Notícia Tech analysis OpenAI, Anthropic and Microsoft warn that AI-powered attacks could grow in the coming months.
This context matters because the security debate is not limited to hypothetical scenarios involving extremely advanced models. Companies developing these technologies are already dealing with situations in which AI agents demonstrate behaviors that can bypass controls or perform operations that were not anticipated.
From tools to agents
More autonomous models can execute sequences of tasks rather than simply respond to individual commands. This expands their usefulness but also increases the need to limit permissions, monitor actions and establish mechanisms that can interrupt operations.
The financial sector has less room for error
An incident at a technology company can be serious. In financial services, however, interdependence between institutions creates an additional layer of risk. The same technological advance can therefore require higher standards of resilience.
The G20 must now address not only AI adoption, but AI security

Andrew Bailey’s warning brings the AI security debate to the level of authorities responsible for international financial stability.
The most important shift is institutional: the security of advanced AI models is increasingly being treated as a financial stability issue. The FSB is calling on authorities to support the safe and responsible development and deployment of these models.
For the market, this could mean a change in how technology risks are incorporated into governance frameworks. The discussion is expanding beyond privacy, information security and compliance to include the possibility that certain technology risks could produce effects beyond a single organization.
The development also reinforces a broader regulatory trend: the greater the operational capabilities of AI systems, the greater the need for controls that match those capabilities. For financial institutions, this could influence procurement processes, supplier assessments, model governance and business continuity planning.
What the market should watch
The next step will be to see how financial authorities and institutions translate the warning into concrete measures. The FSB is already emphasizing resilience, recovery and security in the deployment of AI models, but implementation will depend on individual jurisdictions and institutions.
The issue is no longer purely technological
The most important point in Bailey’s warning is the change in scale. AI remains a technology with significant potential for productivity and innovation across financial services, but its capabilities can also change the nature of the risks the system must manage.
For banks and financial companies, the message is direct: AI adoption cannot advance separately from the ability to control its risks. If models can increase the speed and scale of an operation, security and recovery infrastructure must evolve in the same direction. That imbalance is what the G20 will have to monitor through the next stages of financial regulation and supervision.

Comentários
Os comentários utilizam autenticação via GitHub para manter um ambiente mais qualificado, seguro e livre de spam.
Entrar ou criar conta no GitHub