Andrew Bailey Warns AI Could Become a New Threat to Financial Stability

0
7

1 September 2026 — EBM Newsdesk Analysis. Anthony Gill

Artificial intelligence is rapidly moving from being a technology story to a financial stability story. Andrew Bailey, Governor of the Bank of England and chair of the Financial Stability Board, has warned G20 finance ministers and central bank governors that increasingly capable AI models could create new pathways for cyber attacks, market disruption and ultimately a disorderly financial shock. His intervention marks a significant shift in the regulatory debate: AI is no longer simply a question of productivity, innovation and competitiveness, but increasingly one of whether the financial system can remain resilient as machines become capable of finding and exploiting vulnerabilities at unprecedented speed.

Bailey’s warning came in a letter to G20 finance ministers and central bank governors ahead of their meetings in Asheville, North Carolina. He argued that frontier AI could materially change the speed, scale and economics of cyber risk, creating the possibility of simultaneous disruption across multiple financial institutions or shared technology providers. That matters because modern finance is deeply interconnected. Banks, insurers, exchanges and payment systems may have strong individual defences while still depending on common cloud infrastructure, software, data providers and other critical technology. A vulnerability in one widely used component could therefore become a systemic problem rather than an isolated corporate incident.

Join The European Business Briefing

New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.

Subscribe

The Bank of England has been warning about this trajectory for some time. Its latest Financial Stability Report says frontier AI capabilities have advanced faster than many experts expected, with the most capable models increasingly able to complete long, complex software tasks with limited human intervention. The Bank’s analysis found that recent models can carry out multi-stage cyber tasks and identify and exploit vulnerabilities with little human input, raising the possibility that attackers could eventually operate at machine speed and scale.

For Europe’s financial institutions, this creates a particularly difficult challenge. Banks are already operating under intense pressure to modernise ageing technology while meeting increasingly demanding regulatory requirements. As explored in EBM’s analysis of the European banking sector, lenders are simultaneously dealing with changing interest rates, digital disruption, tighter capital rules and the emergence of private credit. AI adds another layer: the same technology that could lower costs and improve risk management may also increase the speed and sophistication of attacks against the infrastructure on which those banks depend.

The risk extends beyond cyber security. AI is becoming increasingly important in financial markets, where institutions are using models for research, surveillance, coding, portfolio analysis and decision-making. If similar systems are adopted widely, they could potentially produce more correlated behaviour among market participants. That could make markets move faster during periods of stress, particularly if investors are simultaneously exposed to the same technology companies and the same assumptions about AI-driven economic growth.

That concentration is already visible in equity markets. Bailey’s warning comes as investors have poured enormous amounts of capital into companies expected to benefit from artificial intelligence, while valuations have risen on expectations of substantial future productivity gains. EBM’s coverage of European stocks has tracked the continent’s increasingly complicated relationship with the global technology boom: European markets are benefiting from capital rotation, but remain exposed to any sharp reversal in global risk appetite.

The danger is therefore potentially circular. AI investment can raise expectations of productivity and profits, supporting equity valuations and encouraging further investment. But if the expected economic gains fail to materialise quickly enough, markets could reprice sharply. If that happens alongside high investor leverage, fragile sovereign debt markets or vulnerabilities in private credit, the resulting shock could spread much more quickly than a conventional technology-sector correction.

Bailey is also concerned about the operational consequences of an AI-enabled attack. The FSB has urged financial institutions to prepare for scenarios involving simultaneous disruption across firms or shared technology dependencies. Bailey has suggested that more financial groups should maintain so-called “bare metal” backup systems — systems kept completely separate from their main networks — so that critical operations can be restored after a major cyber attack. The underlying principle is increasingly important: financial resilience cannot depend on the assumption that every cyber attack will be successfully prevented.

That philosophy is already becoming part of the wider European regulatory agenda. AI governance is moving beyond questions of transparency and consumer protection towards the resilience of the financial infrastructure itself. EBM’s recent coverage of the EU AI Act and banking highlights the growing importance of auditability, data governance and human oversight as banks begin deploying increasingly autonomous systems. The challenge is that the regulatory framework is being developed while the technology itself continues to change rapidly.

There is also an international dimension that Bailey is deliberately emphasising. AI does not respect national borders, while regulatory regimes remain largely national. A model developed in one country can be accessed by users elsewhere, while an attack on a shared technology provider can cross several financial systems almost instantaneously. Bailey therefore wants stronger international co-ordination around testing frontier models before widespread release and deployment. The Financial Stability Board is now examining how AI can be deployed safely by financial institutions while strengthening their resilience to AI-enabled cyber threats.

For policymakers, the problem is finding the balance. Excessively restrictive rules could slow the productivity gains that AI promises, while insufficient oversight could allow vulnerabilities to become embedded before regulators understand them. The Bank of England has argued that firms should be able to identify, prioritise and remediate vulnerabilities much faster, while also recognising that rushed security changes can themselves create operational risks.

The Bigger Picture

Bailey’s warning matters because it changes the definition of AI risk. The debate is no longer simply about whether banks will use artificial intelligence effectively or whether workers will be displaced by automation. It is about whether increasingly autonomous machines can interact with an interconnected financial system in ways that humans cannot fully anticipate.

For banks, insurers, exchanges and asset managers, that makes AI a strategic resilience issue as much as a technology investment. The winners may ultimately be the institutions that adopt AI most aggressively — but only if they build the cyber security, operational redundancy and governance systems capable of surviving the technology’s darker side.

The financial system has spent decades building defences against traditional forms of systemic risk. Bailey’s warning is that the next generation of risk may move at machine speed. Europe and the wider G20 therefore face a race not simply to regulate AI, but to make sure that financial infrastructure can withstand whatever the technology becomes next.

LEAVE A REPLY

Please enter your comment!
Please enter your name here