FSB chair flags frontier AI as a cyber-risk channel
In a 28 August letter to G20 finance ministers and central bank governors, FSB Chair Andrew Bailey wrote that frontier AI's most immediate concern for the financial system is its impact on cyber risk. It is a letter ahead of the meetings, not a new rule, and it also flags AI-hyperscaler cross-investment leverage.

Andrew Bailey, writing as chair of the Financial Stability Board, sent a letter dated 28 August to G20 finance ministers and central bank governors ahead of their meetings on 31 August and 1 September. Read it for what it is: a chair's letter and a set of asks, not a Bank of England rate decision, a PRA rule, or a new FSB standard. Bailey holds both the Bank of England governorship and the FSB chair, and this document is the FSB one.
The sentence the wires bury
The letter runs on two tracks, and flattening them into "AI could crash markets" loses the argument. The first track is market vulnerability: Bailey warns the system is still absorbing the Middle East supply shock and could be exposed to a disorderly correction, citing sovereign-debt fragilities, private-credit opacity, stretched valuations "particularly artificial intelligence-related investments," and rising equity-market leverage interacting with "the increasing cross-investment between artificial intelligence (AI) companies and hyper scalers." The second track is frontier AI itself, and here Bailey is precise about the channel: "For the financial system, the most immediate concern is the potential impact of frontier AI on cyber risk." He writes that frontier AI "may have the ability materially to alter the speed, scale and economics of cyber risk," made worse by highly concentrated third-party providers. That is a cyber-resilience warning, not a call that an AI bubble breaks this week; outlets that led with a coming downturn stretched the letter past what Bailey actually pinned down.
The asks are operational
The letter does not stop at a warning; it hands supervisors and firms concrete work. Bailey expects a higher volume of vulnerabilities and a faster patching pace, and notes that pace can itself stress change, testing and recovery processes. He calls for the ability to restore critical systems and data "from bare metal" after a significant cyber incident, and for resilience among the critical third-party technology providers the system leans on. He flags that the FSB is exploring the safe deployment of frontier models for cyber defense by financial firms, so this is not only about the threat side. And he warns that many jurisdictions "do not have the protocols in place" to manage the development, release and deployment of advanced frontier models, adding that "safe and responsible model release and deployment on a global basis should in my view be a priority."
The takeaway
Treat this as an operational-resilience prompt, not a headline. If you run a bank or a financial-market infrastructure, the actionable line is bare metal: rehearse a full rebuild of a critical system from clean media, then map how many of your peers depend on the same handful of third-party providers, because concentration is the amplifier Bailey names. The model-release protocol gap is a policy signal to watch at the G20, not a rule you must meet yet, but the recovery drill is one you can schedule this quarter. For context on how supervisors are framing AI and financial stability, see the New York Fed on stablecoins, the Treasury's GENIUS Act stablecoin rules, and the OpenAI collective cyber-defense letter.
Finpresso: daily AI & finance brief
Free daily newsletter, read in 5 minutes.
Subscribe free