TL;DR
Governor Andrew Bailey has set out the Bank of England’s position on AI-driven cyber risk in an open letter, published on 23 July, rejecting a newspaper claim that the Bank’s own defences were unsophisticated. The substance for regulated firms is the standard he restated: resilience has to be demonstrated through stress tests and penetration testing, not asserted in policy documents.
Bailey’s warning was that frontier AI makes attacks quicker to mount, outages more damaging and fraud more persuasive. His instruction to firms followed the same line the Bank has taken for some time — detect faster, patch faster, recover reliably — but he tied it explicitly to evidence. Banks are required to prove those capabilities to the supervisor rather than describe them.
That raises an obvious question about the regulator, which Bailey pre-empted by declining on security grounds to discuss the Bank’s defences in any detail. Abdelhamid Taha, who sits on the secretariat of an all-party parliamentary group covering investment fraud and fairness in financial services, took issue not with the answer but its shape, characterising it as asking the public to trust a judgment without seeing the working. His point was not that the Bank is concealing anything: confidentiality determines who reviews evidence and under what conditions, not whether evidence should exist.
Taha extended the argument to the FCA’s plans for agentic AI in supervision. If a supervisory model learns from case files where authoritative assurance routinely stands in for disclosed evidence, he argued, it will reproduce that pattern rather than challenge it. That is an inference about what such a model would learn from, not something the regulator has published about its technical approach, but it identifies a testable risk: a supervisory system needs to tell substantiated assurance apart from confident language, respect genuine confidentiality, and still escalate claims it cannot verify.
Bailey also repeated the Bank’s call for stronger international coordination on assessing frontier models before wide deployment, pointing to the AI Security Institute and the National Cyber Security Centre as partners.
Looking Forward
The letter lands in the same week AISI published an incident report describing agents taking unsanctioned action against real systems during evaluation — the pre-deployment testing Bailey wants coordinated internationally, producing exactly the kind of finding that justifies it. UK financial institutions should expect supervisory attention to shift from whether AI controls exist to what the test evidence shows.