FSB Calls Frontier AI the Most Immediate Cyber Threat to Finance

The Financial Stability Board says frontier AI can make cyberattacks faster, cheaper and more scalable, while stretched valuations and leverage could amplify a market correction.

By Emilia Varga • • Fintech

A glowing geometric AI core sends signals through a dark financial network protected by glass shields.

The Financial Stability Board has placed frontier artificial intelligence at the top of its near-term cyber-risk agenda. It warned that the most capable models can make attacks on financial institutions faster, cheaper and easier to scale. The assessment came in a letter from FSB Chair Andrew Bailey to Group of 20 finance ministers and central bank governors ahead of their September meeting.

Bailey, who is also governor of the Bank of England, described malicious use of frontier models as the FSB's "most immediate concern" among AI-related financial risks. The point is not that AI has created an entirely new category of cyberattack. It is that advanced models may compress the time, expertise and cost required to identify vulnerabilities, write malicious code, automate social engineering and coordinate campaigns across many targets.

That shift challenges a security model built around human-speed detection and response. A well-resourced institution may be able to absorb one sophisticated attack. A financial system becomes more vulnerable when the same capability can be aimed simultaneously at banks, market infrastructure and shared technology suppliers.

The systemic link runs through common providers

The FSB's warning is directed at more than individual banks. Bailey urged authorities to consider safeguards around the release and deployment of frontier models, and said financial firms need robust response and recovery plans. He also singled out the resilience of critical technology and service providers.

That distinction matters because finance has concentrated more operational activity in cloud platforms, data vendors, identity services and other external infrastructure. Strong controls at a bank do not eliminate the risk that a common supplier becomes a single point of disruption. AI may increase the frequency and sophistication of attacks at the same time that operational dependencies increase the potential reach of one successful breach.

For supervisors, the practical question is how to evaluate an attack capability that changes faster than conventional examination cycles. Model developers can add tools, coding ability and autonomous behavior between regulatory reviews. Controls therefore have to emphasize outcomes: containment, backups, isolation of critical functions, tested recovery and credible communication with customers and authorities.

Stress tests will also have to become less static. A useful exercise would examine simultaneous disruption at a bank and a shared supplier, attempted manipulation of customer communications, and rapid reuse of the same technique across jurisdictions. That approach tests whether institutions can make decisions with incomplete information, preserve payments and market access, and coordinate a response before a model-assisted attack spreads.

The FSB stopped short of prescribing a single global rulebook. Its members span national authorities with different approaches to AI safety, privacy and cyber regulation. The letter instead sets a direction for coordination, including closer attention to how powerful models are released and how financial-sector users manage them.

AI optimism also appears in the market-risk diagnosis

The cyber warning sits inside a broader financial-stability assessment. Bailey said elevated valuations, concentrated equity markets and expectations surrounding AI could combine with leverage in equity and bond markets to intensify a correction. This risk is separate from malicious model use. Both, however, reflect the financial system's growing exposure to a technology whose commercial impact remains uncertain.

The FSB also flagged inflationary pressure linked to Middle East disruption, high sovereign debt and vulnerabilities in private credit. None of these factors establishes that a systemic event is imminent. Together, however, they reduce the room for markets and institutions to absorb a shock. A repricing of AI-linked assets could interact with leveraged strategies, collateral calls or thinner liquidity; a cyber incident could make that adjustment more disorderly.

The warning should not be read as a judgment that AI's benefits to finance are outweighed by its risks. Models can improve fraud detection, compliance review, customer service and software development. The FSB's concern is that adoption and offensive capability may be moving faster than operational resilience and governance.

Why it matters

For banks and market operators, AI risk is becoming a core resilience obligation rather than a specialist technology issue. Boards will need evidence that critical functions can continue when models, vendors or communications channels fail. Insurers and investors will have to reassess whether cyber coverage, capital buffers and vendor contracts reflect attacks that can be generated and repeated at much lower marginal cost.

For model developers, the letter adds financial stability to the case for controlled deployment, safety testing and cooperation with authorities. For regulators, it creates pressure to coordinate across cyber, prudential and AI-policy teams that have often worked separately.

The largest uncertainty is whether defensive adoption can keep pace. Financial institutions can use the same technology to monitor code, detect anomalies and automate response. The balance between offensive and defensive use cannot be assumed. Institutions must measure and test it, then build the results into recovery planning before a major incident supplies the evidence.

Sources