AI-Driven Cyberattacks Become Major Global Financial Concern as Watchdog Warns of System-Wide Risks
Introduction
Artificial intelligence is creating a new challenge for the global financial system: cyberattacks that can potentially identify vulnerabilities, exploit systems and spread disruption at speeds difficult for traditional security teams to match.
Andrew Bailey, chair of the Financial Stability Board (FSB) and Governor of the Bank of England, has warned G20 finance ministers and central bank governors that the impact of AI on cyber risk has become an immediate financial-stability concern.
The warning does not mean that an AI-triggered global financial crisis has occurred. Instead, regulators are highlighting the possibility that increasingly capable AI systems could dramatically increase the speed, scale and economics of cyberattacks — potentially turning incidents affecting individual institutions into wider financial-system disruptions.
FSB Sounds Alarm Over Frontier AI and Cyber Risk
In a letter to G20 finance ministers and central bank governors, Bailey highlighted the rapidly evolving capabilities of advanced or “frontier” artificial intelligence models.
He warned:
“Frontier AI may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers.”
The concern centres on the ability of advanced AI systems to perform increasingly complicated cyber-related tasks.
Financial institutions have spent years strengthening cybersecurity, but the rapid development of AI means both attackers and defenders can potentially automate work that previously required substantial human expertise and time.
Why Financial Institutions Face Particular Risk
Banks, payment systems, insurers, exchanges and other financial institutions operate through deeply interconnected digital networks.
That connectivity makes modern finance efficient, but it can also create concentrated vulnerabilities.
A cyber incident does not necessarily remain isolated within the institution initially targeted. Problems involving widely used cloud infrastructure, software or another shared technology provider could potentially affect several financial institutions simultaneously.
This interconnectedness is one reason regulators are treating AI-powered cyber capabilities as a financial-stability issue rather than simply an information-technology problem.
IMF Warns AI Could Amplify Existing Cyber Threats
The International Monetary Fund has also examined the relationship between artificial intelligence, cybersecurity and financial stability.
Its June 2026 analysis concluded that the central concern is not necessarily the creation of entirely new forms of cyberattack.
Instead, AI could significantly increase the speed, frequency and breadth with which existing vulnerabilities are discovered and exploited.
That distinction matters.
A vulnerability that previously required substantial time and specialist expertise to discover could potentially be identified more quickly with increasingly capable AI systems.
If attackers can operate at machine speed while organisations remain dependent on slower human-led responses, the window available to identify and patch vulnerabilities could shrink dramatically.
Frontier AI Can Perform Longer and More Complex Cyber Tasks
Evidence cited by the Bank of England demonstrates how quickly these capabilities have progressed.
According to its July 2026 Financial Stability Report, frontier AI models have advanced from performing relatively short and isolated cyber tasks to completing multi-stage attacks against vulnerable systems with limited human input.
The Bank cited testing by the UK's AI Security Institute showing that advanced models could perform tasks that would otherwise take skilled professionals hours.
In one advanced reverse-engineering test, GPT-5.5 completed a task in 10 minutes and 22 seconds, compared with approximately 12 hours for a human expert.
These were controlled tests rather than attacks on real financial institutions, but regulators view the results as evidence of how rapidly AI's technical capabilities are developing.
Shared Technology Providers Could Amplify Disruption
Another major concern is concentration.
Modern banks and financial companies often depend on common cloud platforms, software providers, cybersecurity systems and other third-party technology infrastructure.
This means multiple institutions can share exposure to the same underlying technology.
If an AI-assisted attacker discovered a vulnerability affecting a widely deployed system, the consequences could potentially extend beyond a single company.
Such correlated disruption could interfere with payments, trading, customer access or other critical financial services and, in a sufficiently severe scenario, damage confidence in markets.
Financial Industry Already Recognises the Threat
Cybersecurity is already influencing spending decisions across the financial industry.
PwC's 2026 cybersecurity outlook reported that 76% of financial institutions surveyed planned to increase their cybersecurity budgets during 2026.
Financial companies are confronting several interconnected risks, including cloud vulnerabilities, third-party failures, AI-powered malware and attacks involving broader technology supply chains.
A separate 2026 global study from the Cambridge Centre for Alternative Finance found that adversarial AI-related cyber threats were considered a significant concern by both financial institutions and regulators.
The challenge is therefore two-sided: institutions increasingly want AI because of the productivity and security advantages it can provide, while simultaneously preparing for attackers to use similar capabilities.
AI Is Also Becoming a Cyber Defence Tool
The risks surrounding artificial intelligence do not mean AI is inherently harmful to financial cybersecurity.
Banks and cybersecurity teams are also deploying AI to identify suspicious activity, analyse vulnerabilities, detect abnormal behaviour and automate defensive responses.
The future cybersecurity environment may therefore increasingly involve AI systems operating on both sides.
Defensive AI could identify and patch weaknesses faster, while offensive AI could search for new vulnerabilities and exploit them more efficiently.
Which side gains the advantage could become an important factor in determining the financial consequences of increasingly capable AI.
Regulators Face a Cross-Border Challenge
Cyber threats do not respect national borders.
A vulnerability affecting a global technology provider could potentially impact financial institutions operating across multiple jurisdictions.
At the same time, countries differ considerably in their cybersecurity capabilities, financial regulation and preparedness for advanced AI systems.
That makes international coordination increasingly important.
The IMF has called for stronger governance, technical safeguards, effective containment of cyber breaches, improved recovery capabilities and greater international cooperation.
The FSB is similarly examining how regulators can strengthen financial-system resilience while allowing institutions to benefit from AI innovation.
The Bigger Financial Stability Question
The most serious concern is not necessarily an isolated case of cyber fraud or a single compromised bank.
The systemic question is whether AI could allow cyber incidents to spread quickly enough — and across enough interconnected institutions — to disrupt essential financial services or undermine confidence in markets.
That is why AI cybersecurity has moved beyond the domain of corporate IT departments.
Central banks, financial regulators and international organisations are increasingly treating the issue as part of the broader architecture of global financial stability.
The technology could deliver substantial benefits to banking, investment and financial infrastructure. But the same capabilities that allow AI to analyse complex systems can potentially be used to identify weaknesses within them.
The emerging policy challenge will be ensuring that defensive capabilities, regulation and recovery systems evolve quickly enough to keep pace.






