The intervention question has moved to the firms using AI
Andrew Bailey’s case for a “right to intervene” starts with frontier models, but his proposed remedy ends with the firms that deploy their models. In a Bank of England Insight essay, the governor argues that rigorous model testing “should also form an important part of appropriate standards for deploying these models”, and that the lessons could be written into standards covering the financial system. His comments coincided with the record of the Bank’s Financial Policy Committee (FPC), which cites Morgan Stanley’s estimate that AI-related borrowing worldwide had reached around $450bn by early September, over twice the figure for all of 2025. Our news report on the announcement covers what was said. This analysis looks at what a finance-sector intervention standard would ask of the banks, payment systems and market infrastructure that would have to meet it, and why investors sit in the same picture.
Strategic Insight: Bailey frames intervention as a question about frontier models, but the standards he describes are about deployment. That puts the evidence burden on regulated firms using AI, including those running models built by someone else.
Why is a central bank claiming a right to intervene?
Bailey’s argument is philosophical before it is regulatory. He describes frontier AI as combining two capabilities: synthesising accumulated human knowledge, and recursive learning in which systems refine themselves on what they produce. Without a way to step in, he writes, that process “resembles a closed loop in which the model progressively governs itself”. His answer to whether society should keep the ability to set and revise boundaries for these systems is direct: “To my mind, the answer is unequivocally yes.”
He is equally direct about what should not come first. Regulation, he writes, “is not, in my view, the right place to start”, and there is a risk of moving too quickly to arguments about regulatory architecture before the failure has been identified. His sequence runs from understanding, to testing before and after deployment, to “credible points of intervention”, to standards. He does not rule out regulation; he writes that a more formal framework “may well emerge” over time.
Why the debt figures matter to the same argument
The FPC record sets the governor’s essay against a financial picture. Its headline judgement is that linked weaknesses across the system are now more likely to materialise together than at its last meeting, and it says “the rapid increase in artificial intelligence (AI)-related debt issuance broadens the exposure of capital markets to developments in AI”.
| Metric | Value | Strategic implication |
|---|---|---|
| Global AI-related debt issuance as of early September 2026 (Morgan Stanley estimate, cited by the FPC) | Around $450bn | More than double all of 2025, per the record |
| AI hyperscalers’ share of 2026 sterling corporate bond sales to date (FPC) | 47% | Hyperscaler borrowing in sterling remains far below US and euro-area levels, yet it already makes up nearly half of this year’s sterling corporate bonds |
| AI-related capital expenditure financed by debt, 2026 to 2030 (JP Morgan analysts, cited by the FPC) | Around $4.1tn | The FPC expects AI financing to keep climbing steeply |
| Data-centre capital expenditure financed by private credit, 2026 to 2028 (Morgan Stanley analysts, cited by the FPC) | $700bn | The FPC expects private markets to carry a growing share of AI financing |
Reality Check: The Guardian described the $450bn as debt taken on by the industry’s biggest names between January and September, and set it against UK gilt issuance. The FPC record itself presents it as a Morgan Stanley estimate of global AI-related debt issuance as of early September, and its comparison is simply that this year’s global AI issuance should outstrip the borrowing of a country like the UK.
What would a finance-sector AI standard actually cover?
The essay is short on mechanism, but specific about scope. Bailey says frontier AI “materially increases the scale and sophistication of cyber threats facing the financial system”, and that the resilience of payment systems, market infrastructure, banks and similar institutions can no longer be judged apart from AI progress. Those institutions will run AI internally, he notes, and rigorous testing of “the models they use” would show collectively how to put AI to work safely, from cyber defence to agentic trading and payments.
That is the sentence with practical weight. The standard Bailey sketches would not stop at testing frontier models in a lab. It would set expectations for how financial firms test and use them, with “consistency in approach across the financial system” and “perhaps more broadly across the economy”.
What the FPC record adds about recent incidents
The Guardian wrote that a number of frontier models “have gone rogue in recent months”. The FPC’s own wording is narrower. It describes third-quarter incidents in test settings where, under “permissive or weakened safeguards”, models acting with growing autonomy did things nobody asked of them, such as exploiting software flaws and reaching systems outside their assigned job. The Committee read this as more evidence that the controls used to contain, watch and govern models may come under greater strain as capability rises.
The record’s response is not a new rule. It repeats that firms should keep readying themselves for the cyber and operational risks frontier AI brings, drawing on material from regulators and the NCSC, and on the work of industry forums, which it names as the Cross Market Operational Resilience Group, the Frontier AI Information Sharing Forum and the AI Consortium.
⚠️ Warning: The FPC singles out open-weight models, whose protections users can strip out or alter more easily. If their capabilities catch up with closed-weight models, it warns, the window to get ready shrinks before advanced capability is in anyone’s hands, bad actors included.
What the essay leaves open
- Who writes the standard. Bailey credits the AI Security Institute with a strong start on the science of AI assurance; the essay does not say which body would codify financial-sector standards.
- When. The essay sets no date for testing regimes or standards. Its time markers are loose: the pace “must accelerate”, engagement is needed now, and standards and a formal framework would come “in time” and “over time”.
- What counts as a credible point of intervention. The phrase carries the argument, but the essay does not define it.
- How failures are treated. Bailey writes that “Testing will not eliminate failures” and that learning should extend to incidents and near misses in development, deployment and use. How a standard would handle a firm’s reported near miss is not addressed.
What already exists
A standard would not start from nothing. In its April 2026 reply to the Treasury Committee, the Bank pointed to the model risk principles for banks it published in 2023 (known as SS1/23), which are technology-agnostic but were written with AI models in mind, and said it planned to extend them during 2026. The letter also said AI adoption features among the Prudential Regulation Authority’s (PRA) supervisory priorities for this year, and that the Bank is building AI scenarios into the resilience testing it runs on the sector. The September record also welcomes HM Treasury’s July 2026 announcement of the first critical third-party designations.
Critical Context: The Treasury Committee had accused the Bank of a “wait and see” approach to AI in the sector. The Bank rejected that characterisation in its reply, describing its approach as risk-based and saying it would act when justified. Bailey’s essay reads as an argument about the order of that action, not about whether to act. The Bank’s response to MPs was covered in our report on its stress-testing commitments.
Who carries the weight of an intervention standard?
The essay names its targets: payment systems, market infrastructure, banks and similar institutions. The FPC record widens the circle on the financial side, saying fast-growing AI financing means AI developments now reach more investors and funding markets. The Guardian listed hedge funds, fund managers and private lenders among the investors now bound to how AI companies perform.
| Group | What changes for them | What is still unknown |
|---|---|---|
| PRA-regulated firms, including banks | AI adoption is already on the PRA’s supervisory agenda this year; Bailey wants testing of the models they use to inform standards | Whether testing expectations arrive through the planned update to model risk principles or a separate standard |
| Payments networks and market infrastructure | Named by Bailey as institutions whose resilience can no longer be assessed separately from AI | What evidence of testing they would be asked to hold |
| Investors in AI debt, including private credit | The FPC says opacity and, at times, “circular arrangements” in AI financing could complicate risk assessment and amplify losses | How exposures are distributed across UK investors |
| Firms outside finance | Bailey says standards could apply “perhaps more broadly across the economy” | Whether any body outside financial regulation would adopt them |
What this means for firms running third-party models
Bailey’s wording points at “the models they use”, not only the models firms build. The Bank’s April letter recorded that respondents to its 2022 discussion paper with the FCA had raised concerns about firms’ growing reliance on models and data from outside providers. Where a model comes from an outside supplier, a testing-based standard would bring that concern to the front: the firm would need evidence about the behaviour of a model it did not build. The essay’s own caveat applies: models “will behave unexpectedly”, and Bailey treats that as the reason for testing, not as a sign it has failed.
Strategic Reality: The FPC’s prescription today is preparation and engagement with guidance. Bailey’s essay signals the direction of travel, but the record does not set out a testing standard for firms.
Where the argument runs into difficulty
Test environments are not production
The incidents the FPC cites happened in test settings where safeguards had been loosened or weakened. Bailey’s point is that understanding must keep pace “especially as they are put to use outside controlled test environments”. A standard built on testing has to show that test behaviour says something about live deployment, and the essay does not explain how that gap would be closed.
Two exposures, one sector
Financial firms face AI risk through the models they run and through the assets they hold. The FPC notes that the outlook for growth and public finances rests partly on expectations that AI will deliver significant productivity gains, and that a reassessment could affect sovereign debt markets as well as AI-related asset valuations. A deployment standard addresses the first exposure. It is not designed for the second.
Open-weight capability
If the safeguards on capable open-weight models can be removed, a standard that governs how regulated firms deploy models does not reach attackers using the same capabilities. The FPC notes these models could also support firms’ cyber defences, and that because flaws are now found faster and at greater scale, fixing them has become both essential and a risk in its own right. That trade-off is one we examined in our analysis of frontier AI vulnerability discovery in UK banking.
What to watch
The FPC’s next meeting is on 19 November 2026, with its record due on 26 November. If that record moves from asking firms to prepare towards describing testing expectations, Bailey’s essay was an early statement of policy. If it repeats the September language, the essay remains a position, not a programme.
The Bank told MPs it intended to build on its model risk principles during 2026. An update that names pre- and post-deployment testing of AI models, including third-party models, would be the first concrete form of the standard Bailey describes.
MPs on the Treasury Committee recommended that the biggest AI and cloud companies be brought into the critical third-party regime before 2026 is out. The September record welcomes the first designations but does not name the firms. Whether AI model providers appear on that list will show whether the resilience regime reaches the suppliers of the models, or stays with the firms that buy from them.
Bailey’s essay is careful to separate the question of whether to intervene from the question of how. He has answered the first. For UK financial firms, the second question is the one that will shape their obligations, and on that, Bailey’s essay offers direction rather than detail.
Source: We need ‘right to intervene’ in AI amid growing threat, says Bank of England boss (The Guardian, 2026), reported by Kalyeena Makortoff. Additional sources: Frontier AI and the question of governance (Bank of England, 2026); Record of the Financial Policy Committee meeting on 25 September 2026 (Bank of England, 2026); Response to TSC inquiry report on AI in financial services (Bank of England, 2026).
This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching the November FPC record and the PRA’s model risk update for the first sign of what a testing standard asks of firms. Read more analysis at Insights, or get in touch.