LONDON — Artificial intelligence-driven cyber risk has emerged as the most immediate threat to global financial stability, the head of the Financial Stability Board said Monday, warning that increasingly capable AI systems could make cyberattacks faster, cheaper and more disruptive across banks, markets and payment networks.
Andrew Bailey, who chairs the Financial Stability Board and also serves as governor of the Bank of England, delivered the warning in a letter to finance ministers and central bank governors from the Group of 20 major economies ahead of meetings this week.
Bailey said advanced AI could alter the “speed, scale and economics” of cyber risk, enabling attackers to identify weaknesses in computer systems more rapidly and potentially exploit vulnerabilities across widely used financial infrastructure. He also warned that heavy dependence on a small number of technology providers could magnify the damage from a successful attack and undermine confidence across markets.
The warning places AI cybersecurity near the top of the global policy agenda at a moment when banks, insurers, exchanges and payment companies are expanding their use of artificial intelligence. Financial firms are deploying AI to detect fraud, assess risk, automate customer service, manage compliance and analyze vast volumes of market data. But regulators increasingly fear that the same capabilities can give malicious actors more powerful tools to probe networks, create convincing scams, automate software exploits and target common digital suppliers.
The Financial Stability Board, or FSB, was created after the 2008 financial crisis to identify vulnerabilities that could threaten the global financial system. Its members include central banks, finance ministries and financial regulators from major economies. Bailey’s assessment signals that AI-enabled cyberattacks are no longer being treated simply as an information-technology problem for individual firms. Instead, they are increasingly viewed as a potential source of systemic risk.
A threat beyond one bank
Traditional cyberattacks can be severe, but their effects are often contained within a single company, agency or institution. The danger highlighted by Bailey is that advanced AI may increase the odds of attacks that spread across many firms at once.
A cyberattack on a major bank can disrupt customer accounts, delay payments or expose sensitive personal information. An attack on a shared cloud-computing provider, core banking software company, financial messaging service or market-data platform could have a much broader impact. It could simultaneously interrupt operations for multiple institutions, complicate trading and settlement, or shake confidence in the reliability of financial markets.
“Recent developments highlight the importance of ensuring that advances in capability are matched by resilience and preparedness,” Bailey said in the letter, according to Reuters. He called for a global priority on the safe and responsible release of advanced AI models.
The concern is partly rooted in concentration. Financial institutions increasingly rely on a relatively small group of cloud providers, cybersecurity companies, data firms and AI developers. That dependence can lower costs and speed innovation, but it also creates potential single points of failure.
If an attacker finds a flaw in software used throughout the banking system, or compromises a technology provider with thousands of customers, the results could extend far beyond one balance sheet. Banks may be unable to process transactions. Businesses may lose access to payroll or working capital. Investors could struggle to value assets or execute trades. A short operational failure could turn into a confidence crisis if customers and markets fear that the system cannot be restored quickly.
Bailey warned specifically that reliance on a handful of powerful technology providers could weaken “system-wide market confidence.”
That language matters. Financial crises are not caused only by losses. They can accelerate when people lose confidence that institutions, markets or payment systems will continue functioning. In an interconnected financial system, uncertainty itself can become a destabilizing force.
Why AI changes the risk
Cybersecurity experts have long warned that artificial intelligence could improve both defense and offense. Banks can use AI tools to monitor unusual activity, detect potential fraud, identify weaknesses in networks and prioritize security alerts. But attackers can also use similar technologies to analyze code, write malicious software, generate realistic phishing messages and adapt tactics faster than human teams can respond.
Bailey’s warning focuses on the risk that frontier AI models, the most advanced systems with increasingly sophisticated reasoning, coding and autonomous-task capabilities, could materially reduce the time and cost needed to conduct an attack.
A criminal group once needed specialized technical expertise to search for exploitable flaws in software or to craft a convincing phishing campaign aimed at a financial employee. More capable AI systems may allow smaller groups to automate portions of that work, produce more tailored attacks and test multiple methods at scale.
The result could be a sharper mismatch between attackers and defenders. Banks and regulators typically need time to verify a vulnerability, assess which systems are affected, develop a patch, test it and deploy it without disrupting critical services. An AI-enabled attacker may be able to move much faster, scanning for flaws and seeking to exploit them before defenders have completed those steps.
“The technology could change the speed, scale and economics of an attack,” Bailey said.
That does not mean AI automatically creates successful cyberattacks or eliminates the need for human operators. Security controls, network segmentation, multifactor authentication, software updates and well-practiced recovery plans still matter. But AI can increase the volume and sophistication of threats financial institutions must handle.
The risk is particularly acute where multiple banks use the same systems. A vulnerability in a common cloud service, identity-management provider, cybersecurity platform or payment-processing tool could expose several institutions at the same time. That is the pathway by which a cybersecurity event could become a financial-stability event.
A warning for G20 governments
Bailey’s letter was addressed to G20 finance ministers and central bank governors, putting the issue before officials responsible for economic policy, financial regulation and crisis management in the world’s largest economies.
He said many countries do not yet have systems in place to manage the release and deployment of advanced AI models safely. The warning suggests that regulation and supervision have not kept pace with the rapid evolution of AI capabilities.
The FSB has already begun developing guidance for financial institutions. In June, it released a consultation report on sound practices for the responsible adoption of AI in finance. The organization received responses from banks, technology companies, financial-market groups, insurers, regulators and industry associations, including JPMorgan Chase, Mastercard, Visa, Bloomberg, Binance, the American Bankers Association and the International Institute of Finance. The FSB said it expects to publish its final report in the coming months.
That breadth of participation reflects how widely AI is now embedded in the financial system. The issue is not limited to major Wall Street banks or global technology companies. Regional lenders, insurers, payment platforms, investment managers, exchanges and financial-data providers are all adopting AI tools, often through third-party vendors.
For U.S. policymakers, the warning comes as federal agencies and private companies debate how to improve cyber defenses without slowing AI development. The United States has some of the world’s largest financial institutions and technology providers, making it central to both the benefits and risks of AI adoption.
A successful attack on a major U.S. bank or financial infrastructure provider could have international repercussions because of the dollar’s global role and the cross-border connections of payments, trade finance and capital markets. Conversely, a cyber incident outside the United States could quickly affect U.S. markets if it disrupts a major trading, settlement or cloud-computing link.
The test for financial firms
For banks and other firms, Bailey’s message is likely to reinforce a shift in cyber planning. The question is no longer only whether a company can block an attack. It is whether it can continue operating safely if an attacker penetrates a system, disrupts a third-party supplier or compromises AI-enabled business processes.
That requires institutions to consider operational resilience alongside cybersecurity. They need to know which critical services depend on which vendors, what data and systems would be affected by a failure, and how quickly operations can shift to backups.
Key priorities include:
- Testing recovery plans against severe but plausible cyber scenarios, including simultaneous disruption at multiple service providers.
- Maintaining clear oversight of AI tools used in customer service, fraud detection, credit decisions, trading and internal operations.
- Requiring vendors to disclose material cyber risks, security practices and incident-response procedures.
- Segmenting networks and limiting access privileges so that a breach does not spread unchecked.
- Training employees to recognize increasingly convincing AI-generated fraud, impersonation and social-engineering attempts.
- Establishing clear escalation procedures for incidents that may affect customers, payments, markets or regulators.
The central challenge is speed. Financial institutions may have strong existing cyber controls, but advanced AI could compress the time available to identify and respond to threats. That places greater value on real-time monitoring, rapid patching and recovery systems that have been tested before a crisis begins.
A broader stability debate
Bailey’s letter also warned of other vulnerabilities, including the possibility of a disorderly market correction, elevated AI-related valuations, fragilities in government debt markets and growing use of leverage in equity markets.
Those concerns are separate from cyber risk, but they could interact. A major AI-driven cyberattack occurring during a period of volatile markets or strained government borrowing conditions could make a financial shock harder to contain. Investors may respond not only to the direct cost of an attack but also to uncertainty about whether affected firms can restore operations, meet obligations and protect customer assets.
The FSB chair’s warning therefore carries an important implication: cybersecurity is becoming a core component of financial stability policy. The issue is no longer confined to corporate IT departments or compliance teams. It is moving into boardrooms, central banks and finance ministries.
The financial sector has long been a leading target for criminals because money, data and trust are concentrated in the same systems. AI may now give attackers a more efficient way to exploit that concentration.
For regulators, the challenge will be to encourage innovation while ensuring that financial institutions do not deploy increasingly powerful systems without adequate safeguards, independent testing and contingency plans. For banks and technology providers, the test will be whether resilience improves at the same pace as AI capability.
Bailey’s conclusion is clear: the next major financial shock may not begin with a bank run, a housing collapse or a sudden market sell-off. It could begin with a cyber incident that moves through the world’s digital financial infrastructure faster than institutions are prepared to stop it.