-
UK FCA findings on frontier AI and cyber resilience
2 September 2026The UK Financial Conduct Authority (FCA) has published its findings from a multi-firm review examining how firms are using, testing and preparing for frontier AI models with cyber capabilities. The FCA notes that while these models can help firms identify and analyse cyber vulnerabilities more quickly, they can also, if used maliciously, amplify cyber threats to firms' safety and soundness, customers, market integrity and financial stability. The publication does not introduce new rules, guidance or regulatory expectations but summarises observations reported by firms during the FCA's engagement.
The review identified five key themes:
- Vulnerability discovery is accelerating faster than firms' ability to respond, increasing pressure on remediation processes.
- Frontier AI is becoming a test of organisational resilience, not just a tool, with organisational readiness identified as the primary challenge.
- The value of frontier AI depends on the firm's operating environment, including its governance, tooling, controls and human oversight.
- Frontier AI is making cyber and operational resilience more important as it exposes weaknesses in vulnerability management practices, access management controls, dependency mapping and remediation processes.
- Effective governance and human judgement remain critical, with senior leaders needing greater visibility of how AI affects remediation capacity, operational resilience and risk.
The FCA expects firms to consider whether: (i) their use of frontier AI is supported by clear ownership, appropriate guardrails, access to system information and specialist review; (ii) their vulnerability management and change processes are effective if the volume and speed of model-driven discovery increases; and (iii) their people, systems and processes can operate under greater pressure.
Blog
