FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
Tag: S-2026-05-15-fca-boe-treasury-frontier-ai-cyber Type: article (joint statement) Author(s): Financial Conduct Authority, Bank of England, HM Treasury Date of source: 2026-05-15 Date ingested: 2026-05-29 Authority weight: high — joint UK-tripartite statement of supervisory expectations Raw file: S-2026-05-15-fca-boe-treasury-frontier-ai-cyber
What it claims
The FCA, Bank of England and HM Treasury have issued a joint statement on the cyber-resilience implications of frontier AI models for UK regulated firms and financial market infrastructures (FMIs). The statement opens by characterising frontier AI as a step-change in capability whose cyber capabilities already exceed what a skilled practitioner could achieve, at higher speed, greater scale and lower cost — amplifying threats to firms’ safety and soundness, customers, market integrity and financial stability.
The authorities frame the statement as a reinforcement of existing operational-resilience rules and expectations, not new requirements. Firms are expected to take active steps across five domains: (i) governance and strategy — boards and senior management must have sufficient understanding of frontier-AI risks; investment, resourcing and insurance posture must reflect the emerging threat, including exposure from end-of-life systems; (ii) identification and risk management of vulnerabilities — firms must triage, prioritise, risk-assess and remediate vulnerabilities more quickly, more frequently and at scale, including through automation, while mitigating operational risks from automation itself; (iii) managing risks from third parties — firms must be able to identify, monitor and manage external applications, libraries and services integrated into their networks, including open-source software, and be prepared to remediate at scale; (iv) protection — effective access management, network security and data protection should reduce the attack surface, with consideration of AI-enabled defences to operate at comparable speed to AI-driven attacks; (v) response and recovery — firms should read and apply the effective practices on cyber resilience published by the Bank, PRA and FCA in October 2025.
The authorities will continue to monitor frontier-AI developments and engage industry through the Cross Market Operational Resilience Group (CMORG). Firms are directed to CMORG’s Frontier AI Risk Mitigation Webinar (14 May 2026) and NCSC guidance for further support.
Notable quotes
“The cyber capabilities of current frontier AI models are already exceeding what a skilled practitioner could achieve, and at a significantly higher speed, greater scale, and lower cost.”
“In line with our operational resilience rules and expectations, regulated firms and financial market infrastructures (FMIs) (referred to as ‘firms’), need to take action to plan for and mitigate cybersecurity risks posed by frontier AI.”
“This note is not intended to introduce new expectations; it brings together and reinforces existing messages to support firms as the operating environment becomes more complex.”
What’s speculative vs. asserted
- Asserted: the five expectation domains; the framing that this reinforces (not introduces) existing operational-resilience expectations; engagement via CMORG.
- Speculative / claim-based: the assertion that current frontier-AI cyber capabilities already exceed a skilled practitioner is presented as the authorities’ judgement; the warning that under-investment will progressively expose firms is forward-looking practitioner framing rather than data-supported claim.
Topics this feeds
- FCA approach to AI — UK supervisory frame for AI.
- Operational Resilience and Third Party Risk — cyber resilience and frontier AI third-party / supply-chain risk.
- Three Lines of Defence for AI — board / senior-management expectations on AI risk understanding.
- Model Risk Management and Agentic AI — frontier model exposure overlaps with model-risk surface.
Open questions raised
- What specific evidence of board / senior-management understanding will UK supervisors expect at inspection?
- How will the joint statement interact with the FCA AI Lab good/poor-practice publications expected later in 2026?
- Whether the “not new expectations” framing will hold once the statement is operationalised through CMORG and supervisory dialogue.
- How firms should evidence “AI-enabled defences operating at comparable speed to AI-driven attacks” without amplifying operational risk from automation.