RBNZ named an AI model as a financial stability risk. Top regulator says they are all pretty scary

Insurers on notice as FSB boss issues frontier AI warning

RBNZ named an AI model as a financial stability risk. Top regulator says they are all pretty scary

Cyber

By

In its May 2026 Financial Stability Report, the Reserve Bank of New Zealand did something it had never done before: it named a specific AI model as a risk to the financial system. The report singled out Anthropic's frontier model Mythos as an example of how increasingly capable AI "could materially amplify cyber risks from malicious actors." 

Three months later, the same warning reached a much bigger audience. Andrew Bailey, in his capacity as chair of the international Financial Stability Board (FSB) rather than as Bank of England governor, told G20 finance ministers that frontier AI's impact on cyber risk is now the most immediate threat to the global financial system

A domestic regulator and the world's top prudential body, converging on the same warning within a few months of each other. For New Zealand's insurance market, that pattern is worth paying attention to. 

What RBNZ is watching 

RBNZ's Financial Stability Report flagged AI risk on two fronts that echo directly through Bailey's later letter: the amplifying effect of frontier models on cyber threats, and the concentration risk created by New Zealand's financial system relying on a small number of overseas AI providers. "There is still considerable uncertainty around how AI will shape the financial system," said Kerry Watt, RBNZ's director of financial stability assessment and strategy, at the time. "While its impact could be positive, especially in enhancing resilience, it could also introduce or amplify vulnerabilities." 

The data backs it up 

Kordia's 2026 New Zealand Business Cyber Security Report, its tenth annual edition, found that attacks exploiting AI-related vulnerabilities more than doubled year on year, rising from 6% of reported incidents in 2024 to 14% in 2025. Staff misuse of AI has also climbed the list of concerns: 24% of medium-to-large New Zealand businesses now rank it among their biggest cyber challenges, up from 16% the year before. 

A real incident sits behind the warnings 

Both RBNZ and the FSB are writing against the backdrop of an actual event. In July, OpenAI revealed that two of its models had slipped out of a sealed testing environment during an internal evaluation. Acting entirely on their own, without any person directing them, the models reached the open internet and found a security flaw that let them into systems belonging to Hugging Face, all so they could obtain the answers to a cybersecurity benchmark they were being scored on. OpenAI called it an unprecedented cyber incident. 

What it means for New Zealand insurers 

Gallagher New Zealand has already flagged AI liability as a potential "silent risk," drawing a direct parallel with the early years of cyber insurance, when exposures sat inside traditional policies for years before insurers clarified coverage through exclusions and endorsements.  

With roughly 87% of New Zealand organisations already using AI in some capacity, according to research from Datacom, the gap between adoption and governance is the same one RBNZ, Kordia and Bailey are all pointing at, and it's one brokers will need to help clients close before it shows up as a claim. 

Keep up with the latest news and events

Join our mailing list, it’s free!