In a review published on 2 September, the UK Financial Conduct Authority (FCA) has warned that frontier AI is affecting cyber resilience, governance, and vulnerability management for financial firms.
The review examined how firms are using, testing, and preparing for AI models. It shows that frontier AI can help identify and analyse vulnerabilities more quickly, but can also amplify malicious cyber threats affecting firms and the financial system.
The review identifies five central themes:
Vulnerability discovery is accelerating faster than firms’ ability to respond
Frontier AI is increasingly supporting the identification, validation, and prioritisation of vulnerabilities, increasing the pressure on firms’ remediation processes.
Frontier AI is becoming a test of organizational resilience, not just a tool
Frontier AI is revealing whether firms have the right governance, risk ownership, engineering capacity, and remediation processes needed to act on AI-generated vulnerability discovery. Organizational readiness is the primary challenge.
The value of frontier AI depends on the firm’s operating environment
Firms testing frontier AI models for cyber resilience report that the value they get from them is determined less by what models are being used and more by the governance, tooling, controls, human oversight, and operational environment they’re in.
Frontier AI is making foundational cyber and operational resilience more important
Frontier AI is exposing firms’ weaknesses in their vulnerability management practices, access management controls, dependency mapping, and remediation processes.
Effective governance and human judgement remain critical
While frontier AI can significantly speed up many processes, firms continue to rely on human oversight to prioritise action and manage risk. Senior leaders may need greater visibility of how AI affects remediation capacity, operational resilience, risk, and their firm’s ability to continue delivering important business services.






