Andrew Bailey, Governor of the Bank of England, has penned a letter to the Daily Mail, directly addressing escalating public concern over the intersection of frontier artificial intelligence (AI) and the threat of cyber-attacks. The Governor’s intervention follows a recent article by Connor Axiotes, which raised alarms about humanity's control over advanced AI and its potential to exacerbate cyber threats. While acknowledging the gravity of the issue, Mr Bailey firmly refuted any suggestion that the Bank of England's own cyber defences are lacking in sophistication, describing such assertions as “totally wrong, unfounded and dangerous.”
In his letter, Mr Bailey assured readers that the Bank possesses the necessary investment, expertise, and capabilities to protect its systems. He also highlighted its close collaboration with expert partners, including the National Cyber Security Centre (NCSC). However, the Governor shifted the focus to a broader concern: the wider risk that frontier AI poses to the entire financial sector and its customers. He warned that advanced AI could make cyber-attacks faster and easier to execute, lead to more disruptive outages, and enable criminals to perpetrate more convincing scams.
The Bank of England, in its regulatory capacity, has consistently urged financial firms to enhance their detection and response mechanisms. This includes patching vulnerabilities more rapidly and ensuring robust recovery capabilities in the event of a breach. Mr Bailey stated that the Bank actively requires firms to demonstrate these capabilities through rigorous stress tests and penetration testing, providing a layer of assurance for the financial system's resilience.
Recognising that cyber risks transcend national borders, the Governor reiterated the Bank's call for stronger international coordination regarding the testing of frontier AI models before their widespread deployment. He noted that the UK is well-positioned to address these challenges, citing the work of the AI Security Institute and the NCSC. The Bank is working at speed with these organisations and international partners to bolster the cyber resilience of the banks and firms it supervises, underscoring a proactive approach to a rapidly evolving threat landscape.
This emphasis on collaboration and stringent testing reflects a growing understanding among regulators that the pace of AI development necessitates a united front. For UK businesses, this means continued pressure to invest in their cyber infrastructure and training, while consumers should remain vigilant against increasingly sophisticated AI-driven scams. The UK's regulatory framework, including the ICO's guidance on AI and the upcoming influence of the EU AI Act, will shape how these technologies are adopted and secured, aiming to balance innovation with critical security considerations.