Bailey's letter to G20 finance ministers names cyber as the most immediate financial stability risk from frontier AI, and warns of a confidence break before regulators can coordinate.
Bank of England governor Andrew Bailey, writing in his capacity as chair of the Financial Stability Board, told G20 finance ministers this week that the most advanced AI systems could destabilize global finance not by being smart, but by being weaponized against the handful of shared technology vendors that thousands of banks depend on.
In a two-page letter to G20 finance ministers and central bank governors on Monday, Bailey named cyber risk as "the most immediate concern" the financial system faces from so-called frontier AI. He defined frontier AI as the most capable models now in development, distinguished from earlier generations by what the FSB chair called "increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities."
Bailey's mechanism is concrete. Frontier AI, he warned, may "materially alter the speed, scale and economics of cyber risk" and "undermine market confidence system-wide, especially due to highly concentrated third-party service providers." That concentration is the chokepoint, and it existed before today's AI models. A small number of shared cloud, software, and security vendors serve thousands of banks for core operations. Frontier AI is the amplifier, not the cause.
"The concern is that as these models grow more capable, they will be used to develop or execute cyberattacks against financial institutions faster, more cheaply, and at greater scale than the existing threat picture allows," the FSB chair's letter said. "A successful attack on a concentrated provider could cascade through the system before supervisors can coordinate a response."
The letter lands at the US-hosted G20 finance ministers meeting this week in North Carolina, reported by The Guardian, and follows recent high-profile incidents in which flagship models tested by Anthropic and OpenAI breached testing safeguards. Bailey flagged that backdrop explicitly, and warned that "many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond."
The FSB has tracked AI vulnerabilities in finance since its 2025 monitoring report and closed a sound-practices consultation on AI in finance earlier this year. The Bank of England's July 2026 Financial Stability Report separately flagged cyber as a top-tier risk and AI-related investment concentration as a vulnerability. The new letter is the first time the FSB chair has put the cyber-amplifier argument on the same page as two other named market fragilities: stress in sovereign debt markets, and the growing use of borrowed money to fund stock-market bets. Bailey also flagged stretched asset valuations, particularly in AI-related investments, as a concern.
The honest counterweight: Bailey is one regulator, writing in his FSB chair capacity, and the letter is a warning, not a finding. The FSB has not formally elevated frontier-AI cyber risk above the companion concerns in the letter, and no specific AI-driven cyberattack on a financial institution is named. The mechanism, AI amplifying cyber risk through a shared-vendor chokepoint, is the FSB chair's argument rather than an independent assessment. The G20 finance ministers meet behind closed doors this week. Whether they adopt the framing, and whether the FSB moves from monitoring to a coordinated supervisory expectation, is the next concrete question.