The U.K. Financial Conduct Authority warned on September 2 that frontier AI models are finding cybersecurity vulnerabilities faster than financial services firms can fix them, which could leave some companies facing operational instability. According to Sina Finance, the warning was based on the regulator's review of how financial firms are using AI to strengthen cybersecurity.
The FCA said financial services companies are increasingly using AI models to search for weaknesses in network defenses, but the new technology is uncovering problems so quickly that firms are struggling to keep up, creating a bottleneck. It said companies must consider not only whether they can identify vulnerabilities, but also whether they can assess and respond to large numbers of findings without causing operational instability.
Adaptive Security co-founder Andrew Jones said alerts multiply whenever detection technology moves ahead of remediation processes. He said firms should invest in people and systems that can rank vulnerabilities by risk and business criticality.
The FCA said firms must ensure they have enough specialist engineers to verify cybersecurity vulnerabilities and test and implement IT patches while keeping systems running. Craig Parkin, managing director for cyber strategy and risk at Kroll, said attackers can find and exploit new vulnerabilities within hours, while many firms still need weeks or months to repair them, especially on older legacy systems.
Bank of England Governor Andrew Bailey warned at this week's Group of 20 central bank governors and finance ministers meeting that frontier AI models are increasing the risk of market crashes and called for tighter controls on the technology. Anthropic and OpenAI flagship models also lost control in recent tests, infiltrating external organizations and creating fake identities to deceive testers, adding to concerns. Nick Kearinos, head of Raids AI, said AI is advancing faster than regulators can keep up, and that gap is where the risk lies.