AI & Money

Andrew Bailey Warns AI Could Shake Global Finance Through Cyber Risk

Andrew Bailey speaks at a finance conference as a looming digital AI devil reaches down with claws behind him.
Bank of England Governor Andrew Bailey has warned that AI-enabled cyber threats could destabilise the global financial system.

AI cyber risk could shake global finance by making attacks faster, cheaper and harder to contain across borders, Financial Stability Board chair Andrew Bailey has warned. In a letter submitted to G20 finance ministers and central bank governors, he called frontier AI’s potential impact on cyber risk the financial system’s most immediate AI concern.

The FSB published the intervention on 31 August 2026, ahead of G20 meetings taking place that day and on 1 September. Bailey said frontier models may alter the speed, scale and economics of cyber risk, potentially undermining market confidence across the system.

Why AI Cyber Risk Could Spread Through Finance

A cyberattack becomes a financial-stability problem when disruption moves beyond one company and impairs services on which many institutions, businesses and customers depend. Modern finance is connected through payment systems, market infrastructure, cloud providers, software components and cross-border activity. An incident at a shared dependency can therefore reach several organisations at once.

Bailey’s three-page letter to the G20 emphasises that these risks will not respect national borders. Different countries have different legal frameworks, defensive capabilities and recovery capacity. A disruption that begins in one jurisdiction can travel through common providers and financial links into places less able to contain it.

Frontier AI could compress the time between discovering a vulnerability and exploiting it. It may help attackers examine more systems, generate or adapt malicious code and run more operations simultaneously. The same capabilities can assist defenders, but defence has an asymmetry: an attacker needs one useful opening, while a bank must understand and protect a large collection of systems and suppliers.

The warning does not say an AI-driven financial shock has already happened. It describes a risk path that authorities believe has become credible enough to demand preparation. That boundary matters. The G20 was not presented with evidence of a current system-wide failure, but with an argument that existing cyber assumptions may no longer provide enough time or resilience.

The Bank of England Had Already Modelled the Threat

The G20 letter builds on the Bank of England’s July 2026 Financial Stability Report. Its Financial Policy Committee examined three scenarios for frontier AI and cyber risk, ranging from defenders retaining an advantage to a sharp rise in known but unpatched weaknesses and a materially greater risk of a system-wide event.

Even the more favourable scenario carried costs. Faster discovery would require more frequent patching, placing sustained pressure on change, testing and recovery processes. Rushed fixes can themselves cause outages, particularly when institutions rely on legacy systems or complex applications that cannot be altered safely at machine speed.

A more severe scenario involved correlated disruption through shared providers, common software and critical infrastructure such as energy and telecommunications. The report said firms relying on the same components could be affected together, allowing an operational problem to spread even if each institution had improved its own internal defences.

That is why concentration matters. The FSB’s earlier monitoring work on AI in finance highlighted dependence on a small number of hardware, cloud and pre-trained-model suppliers. The same provider may support defensive tools at many institutions, creating efficiency while also creating a shared point of exposure.

What This Means for Banks and Their Customers

For financial firms, the practical message is that prevention alone is not enough. Bailey called for stronger vulnerability management, response and recovery, including the ability to restore critical systems and data from bare metal after a serious incident. Firms also need to understand which external providers and software components their important services depend upon.

For customers, the most likely consequences of a severe cyber incident would not begin as an abstract market event. They could appear as inaccessible accounts, delayed payments, unavailable merchant services, convincing scams or uncertainty about whether records remain reliable. Bailey separately warned in a public Bank of England letter that frontier AI may make attacks easier, outages more disruptive and criminal scams more convincing.

Individual precautions remain useful, particularly strong authentication, independent verification of urgent payment requests and scepticism towards unexpected messages. LiveAIWire’s reporting on the rise of AI-assisted phishing shows how generative tools can improve the polish and scale of fraud. However, customers cannot personally solve a failure at a bank’s cloud or infrastructure provider.

The system-level response therefore belongs with boards, regulators, technology providers and public authorities. Financial institutions need severe but plausible recovery exercises that include simultaneous disruption across several firms. Regulators need to test whether payment and market services can continue when a shared dependency becomes unavailable.

AI Helps Defenders as Well as Attackers

The outlook is not one-sided. Frontier models can help defenders identify vulnerabilities, prioritise patches and analyse attacks. If trusted organisations deploy these capabilities effectively, they may close weaknesses faster than malicious actors can exploit them.

The difficulty is that access to a strong model does not repair the surrounding process. A finding must be checked, mapped to the affected service, assigned to the right team, fixed, tested and deployed. Automating discovery without improving those steps could create a growing queue of urgent work and encourage unsafe changes.

This speed contest is already moving from theory into operational warnings. LiveAIWire’s coverage of the Five Eyes cyber agencies’ frontier AI warning described the same compression from months or years towards much shorter response windows. A later AI-assisted campaign against Taiwanese government systems illustrated how automated tools can map conventional weaknesses and connect them into an attack path.

Those cases do not prove that banks face identical attacks or that autonomous systems can reliably breach well-defended financial infrastructure. They do show why ordinary security failures, exposed interfaces, weak credentials and unpatched components become more consequential when software can search and combine them at greater speed.

Why the Warning Went to the G20

National regulation cannot fully address infrastructure shared across jurisdictions. A model may be developed in one country, hosted in another and used to target institutions in several more. The resulting disruption can then move through globally connected markets and payment networks.

Bailey urged authorities to support safe and responsible frontier-model release and deployment globally. The wording points towards shared testing expectations, cross-border exercises and better coordination between financial supervisors, cyber agencies and AI-safety institutions. It does not propose a single new prohibition or claim that current rules have become irrelevant.

The FSB has been building this argument for several years. Its 2024 assessment of AI and financial stability identified cyber risk, market correlations, model governance and third-party concentration as channels that could amplify systemic vulnerabilities. The latest letter elevates frontier AI’s cyber impact within that wider agenda.

The warning also arrived alongside concerns about sovereign debt, private credit, leverage and elevated asset valuations. Bailey’s central point was not that AI replaces those risks. It was that a sufficiently large shock, or several shocks occurring together, could activate multiple vulnerabilities at once.

A Warning to Prepare, Not a Prediction of Collapse

The distinction between warning and prediction is essential. No regulator can know exactly how quickly offensive and defensive capabilities will develop, how widely dangerous tools will spread, or whether firms will adapt in time. The Bank’s scenarios are designed to test resilience under uncertainty, not forecast a particular incident.

What has changed is the level at which the concern is being expressed. Bailey placed frontier AI cyber risk before the world’s major finance ministries and central banks as an issue with potential system-wide consequences. That moves it beyond a technical discussion confined to security teams.

The forward-looking test is whether institutions can recover as quickly as threats evolve. If many banks depend on the same services, individual compliance will not be enough. Authorities will need to understand the network, rehearse correlated failures and ensure critical financial functions can continue while compromised systems are rebuilt.

AI cyber risk could shake global finance, but the official record does not say that outcome is inevitable. It says the speed, scale and interconnectedness of the threat are changing. Bailey’s message to the G20 was that resilience must change with them, before a fast-moving incident turns technical disruption into lost confidence across the financial system.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.