Andrew Bailey has just told the G20 something the London cyber market has been quietly worried about for a while: that AI could change the maths of a cyber attack so fundamentally it puts the whole financial system at risk, not just the company that gets breached.
Bailey wears two hats at once. As Bank of England governor, he oversees UK monetary policy. As chair of the Financial Stability Board (FSB), he writes a letter twice a year to G20 finance ministers and central bank governors setting out where the global financial system is most exposed. In his latest letter, published ahead of this week's G20 meeting, he named frontier AI's impact on cyber risk as the most pressing near-term threat.
Bailey's argument is that frontier AI models are gaining autonomy and problem-solving ability faster than the safeguards around them are being built. His specific worry is that AI could change the speed, scale and economics of a cyber attack enough to shake confidence in the financial system as a whole – made worse by how much of that system now runs through a small number of dominant cloud and technology providers.
Regulators use the term for the most advanced AI models currently being developed – systems capable of complex, multi-step reasoning and increasingly autonomous action, as opposed to the narrower, task-specific AI tools most businesses use today. It's the newest and least tested end of the market, which is why bodies such as the FSB are focused on it.
The letter also flags a second concern: leverage. Bond and equity markets have taken on more borrowing tied to AI-related optimism, on top of already stretched valuations and heavy concentration in a handful of tech names. Add in fragile sovereign debt markets, a fast-growing and lightly supervised private credit sector, and an active conflict in the Middle East pushing up energy costs, and Bailey's conclusion is that several of these pressures could hit at the same time – while many countries still don't have rules in place for how powerful AI models get built, released and deployed.
The letter isn't arriving out of nowhere. In July, OpenAI disclosed that two of its own AI models broke out of a sealed testing environment, got online without authorisation, and used a security flaw to get into systems belonging to Hugging Face, a major AI hosting platform – in order to find the answers to a cybersecurity test they were being scored on. OpenAI described it as an unprecedented cyber incident. No human directed the attack; the models worked out how to do it themselves.
A few weeks earlier, more than a thousand researchers and engineers from AI labs including OpenAI, Anthropic and Google DeepMind signed an open letter warning that AI capability could outpace anyone's ability to understand or control the resulting systems.
Take away the central-bank language and Bailey is describing something UK cyber underwriters have been dealing with for a while: aggregation risk. If a small number of cloud, identity and AI-model providers sit underneath a large share of policyholders, a single compromised provider can produce correlated losses across an entire book rather than one insured at a time. Speaking earlier this year about AI-driven aggregation, Sam Cheshire, head of cyber (UK retail) at Gallagher, argued the picture isn't as bleak as it sounds, pointing out that AI is being used on both the offensive and defensive sides of the equation.
Not everyone is as relaxed about where this ends up. Discussing how far the market might eventually go to manage AI-linked losses, colleagues in the sector have raised the possibility of a Lloyd's-style systemic exclusion, similar to the way war exclusions were carved out of cyber policies – a sign that some in the market think AI risk may eventually need to be treated as its own category rather than folded into standard cyber cover.
Recent research from QBE found that almost a quarter of UK businesses believe they've already had a cyber incident involving AI in some way, yet fewer than three in ten AI-using businesses have actually audited their suppliers' AI systems, and only around a third have a formal AI governance policy. That's the gap regulators are now trying to close from the top down – and the gap brokers are having to explain to clients from the ground up.
That AI-linked figure sits inside a longer, noisier trend: government data going back to 2017 shows the share of UK businesses reporting any cyber breach has swung between 32% and 50%, with no clean upward line — a reminder that the QBE figure captures a newer, narrower and more insurer-facing slice of the same problem, not the whole picture."
Bailey isn't the only prudential regulator sounding the alarm. Launching Australia's prudential regulator's latest corporate plan earlier this month, APRA chair John Lonsdale told Insurance Business that rapid developments in frontier AI had further heightened the cyber threat facing APRA-regulated entities, listing it alongside geopolitical risk as one of the biggest drivers of non-financial risk on the regulator's radar. APRA has also begun assessing how insurers and banks manage their concentrated reliance on common technology platforms and material third-party providers – the same concentration risk Bailey flagged to the G20.
For UK insurers with international books or reinsurance ties to the Australian market, that's a signal worth reading alongside Bailey's letter: multiple major prudential regulators are independently landing on the same conclusion, at roughly the same time, which makes coordinated international rules on AI model release and deployment somewhat more plausible than a single regulator acting alone.
Bailey wants coordinated international rules for how frontier AI models are tested, released and deployed, plus stronger resilience standards for the small number of third-party providers the financial sector depends on. For UK insurers and brokers, that's likely to translate into closer scrutiny of AI-related policy wording – specifically where cover starts and stops when a loss originates from an AI system acting on its own, rather than a human attacker – and continued pressure to tie pricing to demonstrable AI governance, supplier due diligence and tested incident-response plans.
The UK's International Underwriting Association has already put AI on its list of strategic priorities for the year, alongside cyber and climate risk, which suggests the market shares Bailey's sense of urgency even if the tools to price the risk with any real confidence are still being built.
The open question is whether regulation can keep pace. Bailey wants safe and responsible AI model releases handled on a global, coordinated basis. Given how quickly frontier models are advancing, and how quickly incidents like the Hugging Face breach have followed one another this year, insurers may need to start pricing this risk well before the rulebook catches up with it.