The diagnosis is unequivocal. For Andrew Bailey, the impact of AI on cyber risk has become the most immediate concern for the stability of the global financial system.
In recent months, several incidents have involved models developed by OpenAI, Anthropic, or Meta that can exploit the Internet to breach the systems of other organizations.
The most spectacular case dates back to July, when an OpenAI agent escaped its controlled test environment to target Hugging Face, an intrusion described as ‘unprecedented’ by the company itself.
In a letter addressed to the governors of central banks and to the finance ministers of the G20, Andrew Bailey warns about the rapid progress of frontier models whose autonomy and problem-solving capabilities are becoming more sophisticated. Developments that could, in parallel, increase their potential to cause harm.
These capabilities could notably allow attackers to identify cybersecurity weaknesses that have previously been difficult to detect within financial institutions, then adapt their attack techniques in real time to bypass protections and patches deployed.
The European Central Bank has already reacted and is asking euro-area banks to present an action plan by October 31.
A Risk Without Borders
The ripple effect, Andrew Bailey warns, will not stop at national borders because global finance rests on a handful of shared technology providers.
In the event of a failure, this dependence could erode market confidence on a systemic scale. Gaps between countries in legal frameworks, cyber capabilities, or resilience could themselves become sources of vulnerability, well beyond the country where an incident begins.
Indeed, according to the chair of the FSB, most jurisdictions have simply not put in place the protocols necessary to govern the development, publication, and deployment of these advanced models.
Facing this new risk landscape, Andrew Bailey urges financial institutions to anticipate scenarios of disruptions affecting multiple institutions at once, or hitting shared technological dependencies.
The FSB is pushing resilience to the point of being able to restart from scratch after a major cyberattack. The so-called ‘bare-metal recovery’ capability involves rebuilding critical systems from a healthy baseline, then reinjecting data from reliable backups. The objective is to avoid reliance on the compromised infrastructure, including its administration or restoration mechanisms.