Financial Stability Board Chair Andrew Bailey warned on August 31 that frontier artificial intelligence could materially change the speed, scale and economics of cyberattacks against the financial system. His letter to G20 finance ministers and central bank governors identifies cyber risk as the most immediate concern arising from advanced models.
The FSB coordinates international financial standards but does not directly regulate banks or technology companies. Its warning is therefore a policy signal, not a new binding rule. National supervisors, legislatures and financial institutions would need to convert recommendations into requirements and operational controls.
Bailey called for safe and responsible model release and deployment. He also urged financial firms to strengthen response and recovery capabilities and examine resilience among critical third-party providers. Concentration matters because many institutions may depend on the same cloud, data or model services; a weakness at one provider can spread disruption across markets.
Reuters independently reported the letter and its emphasis on AI-enabled cyber activity. Advanced models can help defenders find vulnerabilities and automate monitoring. The same capabilities can help attackers discover flaws, write malicious code, imitate trusted communications or coordinate campaigns at lower cost. The balance changes as models become more capable and autonomous.
Financial stability risk is broader than a single data breach. A successful attack could interrupt payments, compromise market data, block customer access or undermine confidence in settlement systems. Rapid recovery, verified backups, network segmentation and practiced incident response therefore matter alongside prevention.
The letter also notes possible market risks from enthusiasm and leverage tied to AI investment. Falling valuations do not automatically create systemic instability; the danger grows when losses are concentrated, financed with debt or connected to institutions providing critical services. Supervisors need data on exposures rather than assumptions based on technology branding.
Responsible deployment is not the same as stopping development. Model evaluations, access controls, logging, disclosure channels and staged releases can reduce risk while preserving legitimate research and defensive use. Financial firms should also test vendor claims and maintain alternatives for essential functions.
The verified development is an FSB chair's warning and a call for coordinated resilience measures. The letter does not report that the global financial system has failed or that a specific model caused a market crisis. The next authoritative evidence will be FSB follow-up work, national supervisory guidance and disclosed stress-testing results. Those records can show whether institutions are closing the gap between rapidly improving AI capabilities and slower operational defenses.