The most advanced AI models are accelerating the identification of cyber vulnerabilities at financial services firms. Following a multi-firm review, the Financial Conduct Authority has warned that these frontier AI models may expose weaknesses in firms’ existing arrangements. Firms should consider the insights shared by the FCA as part of their preparations for AI-enabled cyber threats.
A test of organisational resilience
Earlier this year the FCA, Bank of England and HM Treasury described frontier AI as a step-change in capability, with significant implications for cybersecurity and operational resilience. Since then, the FCA has engaged with firms on how they are responding to AI-enhanced cyber threats and now shares insights from its review for other firms to learn from.
The FCA has found that:
the value of testing frontier AI models depends on the firm’s operating environment,
identifying more vulnerabilities may cause bottlenecks, and
effective cyber and operational resilience arrangements remain critical.
Guardrails and governance
Firms report that frontier AI is most effective when supported by specialist tooling, robust validation processes, operational guardrails, such as human approval for higher-risk actions, and human expertise. Without these, models generate large numbers of findings that are technically possible but hard to validate, prioritise or act on.
As capabilities develop, governance forums, risk committees and senior leaders may need clearer visibility of how frontier AI affects vulnerability registers, remediation, supplier dependencies, risk and operational resilience.
Preparing for a vulnerability wave
Several firms observed that the benefits of autonomous discovery can be limited if processes cannot keep pace with the volume of output. Firms report considerable pressure on remediation teams, engineering resources and change management processes.
Frontier AI can also chain lower-rated flaws into alternative attack paths. This is encouraging firms to take a broader, risk-based approach to cyber risk that looks past severity ratings alone and weighs factors such as exploitability and business service impact.
Foundations and supply chain
Several firms described frontier AI as a stress test of their existing cyber resilience capabilities. It has reinforced the importance of defence in depth and treating cyber resilience as the combined effectiveness of multiple processes rather than the strength of individual controls.
Firms also highlighted the importance of supplier preparedness, cloud dependencies, software supply chain visibility and shared infrastructure.
What this means for firms
The FCA encourages firms to consider their use of frontier AI in response to its findings.
Boards should be able to show who owns frontier AI-enabled cyber activity, what guardrails apply, and how important risks are escalated. Firms should anticipate likely bottlenecks in validation, patch testing and remediation, and prioritise appropriately. Firms should also engage with key suppliers about how they are responding to AI-enabled threats.
Supervisors in the EU, including the European Central Bank and European Supervisory Authorities, have recently issued similar guidance for the firms they oversee. Like the FCA’s latest review, these interventions do not introduce new rules or regulatory expectations but they preview questions supervisors are likely to ask firms.

/Passle/60746e77e5416b13f482811b/SearchServiceImages/2025-12-17-11-07-01-724-69428ed55657195f590ed8d2.jpg)
/Passle/60746e77e5416b13f482811b/SearchServiceImages/2026-09-08-21-25-53-579-6aa07d61414b094d694b4f29.jpg)
/Passle/60746e77e5416b13f482811b/SearchServiceImages/2026-09-08-21-22-14-113-6aa07c86c35f33cd33023d55.jpg)
/Passle/60746e77e5416b13f482811b/SearchServiceImages/2026-08-26-13-37-42-870-6a8eec269e6a1c98055ae275.jpg)