Summary
- FSB chair Andrew Bailey says frontier AI could change the speed, scale, and economics of cyber risk.
- The warning links model capability with financial-system confidence, recovery, and resilience rather than treating AI security as an isolated technology issue.
- Critical third-party providers and responsible model deployment are central to the FSB's response.
The Financial Stability Board has identified cyber risk as the most immediate threat that frontier artificial intelligence could pose to the financial system, warning that increasingly capable models may change the economics and scale of attacks quickly enough to create broader stability concerns.
FSB chair Andrew Bailey set out the warning in a letter to G20 finance ministers and central bank governors ahead of meetings on 31 August and 1 September. The letter places frontier AI alongside existing vulnerabilities in markets, private credit, sovereign debt, and high asset valuations, but singles out cyber risk as the most immediate AI-related concern.
The FSB’s concern is not that a frontier model has already caused a systemic financial cyber incident. Rather, it is that models showing greater autonomy, problem-solving capability, and offensive cyber competence could alter how quickly attacks can be developed and scaled, lowering costs for attackers while increasing the number of systems that can be tested or targeted in parallel.
That creates a different kind of financial-stability question from the conventional use of AI inside banks. Much of the regulatory discussion around artificial intelligence has concentrated on model risk, consumer outcomes, explainability, data governance, and the effect of automated decisions. The FSB is now putting the security capability of the models themselves into the same resilience conversation.
Bailey’s letter says frontier AI could materially affect the speed, scale, and economics of cyber risk and, in a sufficiently severe scenario, undermine market confidence. The FSB is calling for authorities to support safe and responsible model release and deployment, while financial institutions maintain strong response and recovery capabilities.
Critical third-party providers are another part of the warning. Financial institutions increasingly depend on infrastructure and technology operated outside their direct control, including cloud platforms, software suppliers, data services, and, increasingly, AI providers. A vulnerability or disruption affecting a sufficiently concentrated supplier can therefore become a resilience issue across multiple institutions at once.
That concern already sits at the centre of European operational-resilience regulation. The EU’s Digital Operational Resilience Act has pushed financial entities towards greater scrutiny of ICT dependencies, incident response, testing, contractual controls, and critical third parties. Frontier AI adds a new variable because it can affect both sides of that dependency: financial institutions may deploy the technology operationally while adversaries use similar capabilities to accelerate attacks.
The risk is also unlikely to be distributed evenly. Large banks and infrastructure operators can invest in monitoring, testing, threat intelligence, and recovery at a scale that smaller institutions cannot easily replicate. At the same time, widespread use of common technology providers can create correlated exposure even among institutions with otherwise mature internal controls.
The FSB’s framing therefore shifts the discussion away from whether individual AI-generated attacks appear novel. A system-level concern emerges when capability improvements alter attacker productivity, when the same models or techniques can be applied across many targets, and when financial services depend on a limited number of technology providers whose disruption could propagate across borders.
There are still substantial uncertainties around how quickly those capabilities will progress and how reliably frontier models can conduct complex cyber operations without human support. The FSB’s warning is consequently prospective rather than a declaration that financial cyber defences have already been overtaken.
It nevertheless places model-release decisions, supplier resilience, and recovery capability firmly within financial-stability policy. Security testing of increasingly autonomous models is no longer only a question for AI developers, while financial institutions cannot treat adoption solely as an internal productivity or model-governance programme.
The FSB is effectively asking regulators and financial institutions to plan for a threat environment in which advances in AI capability change the volume and tempo of hostile activity before there is definitive evidence of a systemic event. How authorities translate that warning into supervision, third-party oversight, and expectations around frontier-model deployment will determine whether it remains a risk assessment or develops into a new layer of financial-sector regulation.




