Frontier AI models are identifying security vulnerabilities faster than financial firms can patch them, creating what the UK's Financial Conduct Authority (FCA) calls "vulnerability bottlenecks." The warning, issued yesterday, signals that even with human triage, the volume of AI-discovered flaws is straining remediation teams, engineering resources, and change management processes across the sector.
The FCA's alert follows a review of how financial firms are using, testing, and preparing for frontier AI systems. The regulator found that these models expose weaknesses not just in software and infrastructure, but in the people and processes firms rely on to fix them.
System-wide risk and market confidence
Andrew Bailey, chair of the Financial Stability Board, reinforced the concern in an open letter to G20 finance ministers and central bank governors this week. "Frontier AI may have the ability to materially alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers," he said.
Bailey warned that financial firms and regulators should prepare for higher volumes of vulnerabilities and a faster rate of patching. The resulting pressure could "create operational and resilience challenges," he said, particularly when remediation teams cannot keep pace with AI-driven discovery.
Vulnerability chaining and shifting priorities
One finding from the FCA review is that frontier AI models can chain together multiple low-rated security flaws. This creates attack paths that traditional scanning and testing often miss. Several firms told the regulator they now base remediation decisions on the potential disruption an attack path could cause, rather than on the risk rating of any single vulnerability.
The shift has reinforced the need for defence in depth. Firms are increasingly viewing cyber resilience as the combined effectiveness of multiple overlapping processes, not the strength of individual controls. Some are also pressing suppliers on how they use AI for vulnerability discovery, how they validate findings, and whether they can remediate problems quickly.
Where human oversight fits
Despite the push toward automation, the FCA stressed that human oversight remains critical. AI can accelerate vulnerability discovery, code analysis, and patching prioritization. But firms still depend on specialist expertise to validate findings, make risk-based decisions, and manage the operational impact of rapid fixes.
"Several firms observed that the benefits of autonomous discovery can be limited where processes cannot keep pace with the volume of output," the FCA said. The bottleneck, in other words, is not just about finding flaws - it is about the capacity to assess and respond to a continuous flow of them without introducing instability.
For professionals working in financial services, the implications extend beyond technology. A separate FCA review published in July warned that AI could amplify risks tied to fraud, cyber security, consumer harm, and market concentration. As the tools for discovering weaknesses grow faster, the systems for fixing them face a widening gap.
Why this matters for finance professionals
The FCA's findings make one thing clear: vulnerability management is becoming a capacity problem, not just a technical one. Finance teams responsible for risk, operations, and compliance need to map where their remediation pipelines will break under higher volumes. The regulator's suggested questions are a practical starting point - identifying likely bottlenecks in validation, patch testing, and change implementation, and reordering priorities based on business service impact rather than individual severity scores. Firms that treat this as a pure IT issue will find their processes cannot absorb the speed AI now demands. For those building or overseeing cyber resilience strategies, targeted upskilling in AI-driven security workflows - such as through an AI for Cybersecurity Analysts learning path - can help bridge the gap between discovery velocity and operational capacity. Similarly, broader AI for Finance knowledge is becoming essential as these tools reshape risk, fraud detection, and regulatory expectations across the sector.
Your membership also unlocks: