Financial Stability Board Chair Andrew Bailey has identified the effect of advanced artificial intelligence models on cyber risk as the most immediate concern for the global financial system. The FSB published Bailey's letter to G20 finance ministers and central bank governors on August 31, 2026. The warning is based on the possibility that AI could change the speed, scale and economics of cyber threats, allowing disruptions to spread across interconnected financial institutions and national borders.
Cyber resilience is the central warning
Bailey's letter points to the growing autonomy, problem-solving ability and threat capabilities of frontier AI systems. The FSB assessment says such models may accelerate the discovery and exploitation of security weaknesses. Because finance relies on shared infrastructure and a limited number of critical technology providers, one disruption could affect several institutions and jurisdictions. The board therefore emphasizes not only prevention, but also the ability to respond, recover and continue essential services after a serious technology incident.
A call for coordinated G20 action
The FSB chair urged jurisdictions to develop appropriate protocols for safe and responsible release and deployment of advanced models. Reuters reported Bailey's warning that many countries do not yet have systems for managing those processes. Differences in legal frameworks, cyber capabilities and recovery capacity can create shared weaknesses in cross-border finance. The letter consequently argues for a coordinated international approach rather than relying only on separate national controls that may leave gaps between connected markets.
Why critical technology providers matter
Financial institutions depend on cloud services, data processing, network infrastructure and common software vendors. Bailey said concentration among a small number of powerful technology providers could affect confidence across the system. A prolonged failure at one shared provider could disrupt organizations that otherwise appear independent. The FSB's message is that critical third parties need strong continuity, backup and recovery arrangements alongside the institutions they serve. Resilience must cover the supply chain, not just each bank or market firm separately.
The warning does not report a new attack
The FSB statement does not announce a specific new cyberattack against a financial institution. It is a forward-looking policy warning about systemic risks that could follow from rapidly improving AI capabilities. That distinction matters. The board is not reporting a current loss or service outage; it is saying that defensive and recovery systems must advance with the technology. Financial firms are being encouraged to strengthen scenario planning and operational resilience before a disruption becomes broad enough to undermine market confidence.
Market vulnerabilities are also included
Bailey's letter covers more than cybersecurity. The FSB statement lists fragilities in sovereign debt markets, vulnerabilities in private credit, stretched asset valuations and increasing leverage in equity markets. It warns that optimism around AI investment may interact with high valuations and market concentration in a way that amplifies a future correction. The board treats these pressures as connected parts of the same risk environment, where one large shock or several simultaneous shocks could activate multiple vulnerabilities.
What financial firms are expected to prepare
The letter calls for robust response and recovery capabilities at financial firms. This includes maintaining essential services and restoring systems in a controlled manner when an incident cannot be completely prevented. The FSB also stresses resilience among common and critical third-party providers. It did not announce one mandatory technical standard or implementation deadline in the August 31 statement. Instead, the board said it is considering what further steps it can take within its mandate and financial-stability expertise.
The next regulatory stage
The FSB coordinates national financial authorities and international standard-setting bodies. Its August 31 statement does not itself create a binding new regulation, but it places frontier-AI cyber risk prominently on the G20 policy agenda. Later actions could emerge through consultation reports, supervisory expectations or national rules. For now, the confirmed development is that the FSB chair formally told G20 officials that AI-driven cyber risk is the most immediate concern and called for global preparation, responsible deployment and stronger recovery capacity.
