In a joint statement, the Bank of England, FCA and HM Treasury said current frontier AI models' cyber capabilities exceed those of a skilled human practitioner at higher speed, scale and lower cost. Firms are told to act on five fronts: board-level governance, faster and automated vulnerability remediation, third-party and open-source risk, stronger protections including AI-enabled defences, and response and recovery.
Why it matters
UK financial firms now face explicit supervisory expectations to patch at machine speed and treat frontier AI as a live threat to operational resilience.
Line of Thought
Follow this story
Pick any item to keep going. Your path builds up above as a line you can share.
Directly linked
Connections our researchers recorded
- DevelopmentEBA, EIOPA and ESMA tell EU finance to manage frontier AI cyber risk31 Jul 2026 · Statement · EULed to: EU supervisors follow the UK's May statement with parallel expectations
- DevelopmentBank of England flags AI debt boom, circular financing and AI cyber threat7 Jul 2026 · Report · GBLed to: The FPC repeats the May frontier-AI cyber warning in its formal risk assessment
- DevelopmentBessent and Powell summon bank CEOs over Anthropic Mythos cyber risk7 Apr 2026 · Statement · US, GBResponds to: Formal UK supervisory response to the April Mythos alarm
What led here
Earlier developments on the same thread
- DevelopmentWashington law says only a licensed clinician can deny prior-authorisation requests23 Mar 2026 · Rule change · US-WA, US
- DevelopmentUS Treasury releases AI lexicon and finance-specific AI risk framework19 Feb 2026 · Policy · US
- DevelopmentSenate Democrats ask Treasury and FSOC to probe AI-sector debt risks22 Jan 2026 · Statement · US
- DevelopmentAnthropic discloses largely AI-run espionage campaign by Chinese state group13 Nov 2025 · Incident · US, CN
What happened next
Later developments on the same thread
- DevelopmentUS export-control order forces global shutdown of Claude Fable 5 and Mythos 512 Jun 2026 · Enforcement or ruling · US
- DevelopmentRBI drafts model risk rules covering AI/ML for all regulated lenders24 Jun 2026 · Rule change · IN
- DevelopmentOpenAI says its models escaped an eval sandbox and breached Hugging Face21 Jul 2026 · Incident · US, INTL
- DevelopmentOpenAI pauses frontier RL training over cyber risk after Hugging Face breach18 Aug 2026 · Statement · US
Same story elsewhere
What other countries and bodies did on this
- DevelopmentHalf of Fed survey contacts now name AI as a salient financial-stability risk8 May 2026 · Report · US
- DevelopmentAnthropic withholds Claude Mythos Preview, gives it to defenders via Project Glasswing7 Apr 2026 · Model release · US
- DevelopmentOpenAI ties large reasoning-distillation campaign to people linked to Moonshot AI30 Sep 2026 · Incident · US, CN
- DevelopmentOpenAI launches GPT-6 Astra, first model it rates 'Critical' for cyber capability3 Sep 2026 · Model release · US
Rules in play
Laws and guidance this touches
- RuleGreat American AI ActUS · Proposed · 4 Jun 2026
- RuleEO 14409 (covered frontier models)US · In force · 2 Jun 2026
- RuleSB 813 / AB 1405US-CA · Enacted, not yet in force · 9 Sep 2026
- RuleIllinois AI Safety Measures ActUS-IL · Enacted, not yet in force · 6 Jul 2026
- RuleGPAI Code of PracticeEU · In force · 10 Jul 2025
Threads by topic: Cybersecurity Frontier models Financial risk