Andrew Bailey, chair of the Financial Stability Board and governor of the Bank of England, warned G20 finance ministers and central bank governors Monday that frontier AI models could exploit cyber weaknesses and transmit disruptions across the global financial system. His letter, sent ahead of the G20 meeting in Asheville, North Carolina, calls on regulators to treat pre-release AI safety controls as a financial stability issue, not a voluntary practice for tech companies.
Bailey's core concern is that AI capabilities are outpacing the safeguards governing their development. Recent models from OpenAI, Anthropic and Meta Platforms have reportedly used the internet to hack outside organizations, demonstrating an ability to discover unknown vulnerabilities and adapt when defenders try to close them.
"The risk landscape has been further complicated by the emergence of frontier AI models," Bailey wrote, citing their growing autonomy, problem-solving capacity and ability to generate threats.
Pushing safety controls upstream
The letter urges regulators to move beyond relying on banks and other users to contain risks after a model is released. Instead, authorities should ensure developers have adequate testing, security and release protocols in place before highly capable systems become widely available. Bailey warned that many jurisdictions lack effective procedures for managing the development, release and deployment of frontier models, increasing risks both within finance and throughout the wider economy.
The financial sector's dependence on shared infrastructure makes the threat systemic. Banks, insurers, payment companies and market operators frequently rely on the same cloud services, software vendors and other technology providers. An AI-enabled attack that compromised a widely used provider could affect multiple institutions and markets at once.
Cross-border exposure and recovery planning
Differences in national laws, cyber defenses and recovery capabilities could compound the danger, Bailey said, allowing an incident originating in one jurisdiction to cause damage elsewhere. That cross-border exposure gives the G20 a particular interest in developing coordinated safeguards.
Financial institutions must also prepare for more severe events involving simultaneous failures across multiple firms or shared technology dependencies, according to the letter. Bailey emphasized the need for strong response and recovery capabilities, including the ability to rebuild critical systems and restore data from "bare metal" after a major cyber incident.
Some regulators are already acting. The European Central Bank has directed eurozone banks to submit plans by Oct. 31 explaining how they will address the heightened threats posed by new AI models.
A crowded agenda in Asheville
AI risk will compete for attention with an unusually difficult economic and geopolitical agenda. The two-day G20 meeting is taking place amid elevated inflation, slowing global growth, rising government borrowing costs and economic disruption from the U.S.-Israeli war with Iran. The conflict has restricted oil flows, lifted global energy prices and further strained supply chains.
IMF Managing Director Kristalina Georgieva identified rising bond yields and stalled disinflation as sources of concern for markets and policymakers. The United States is expected to press other governments to reduce economic ties with Iran, potentially adding sanctions disputes to existing tensions over American tariffs and trade policy.
Why this matters for finance professionals
Bailey's letter signals that AI model safety is shifting from a technology policy debate to a regulatory priority with direct implications for financial institutions. CFOs and risk officers should expect pre-release testing and deployment controls to become formal compliance requirements, not just industry best practices. Finance teams that build AI for Finance expertise now will be better positioned to assess model risk, respond to regulatory inquiries, and evaluate third-party AI dependencies before a major incident forces the issue. For executives responsible for financial stability and technology oversight, an AI Learning Path for CFOs offers structured guidance on governing AI risk across the enterprise.
Your membership also unlocks: