Skip to content

Can AI Crash the Global Financial System? Andrew Bailey Warns

Bank of England Governor Andrew Bailey warns AI could turn a single cyberattack into a global financial shock. The FSB puts shared tech infrastructure at the…

4 min read How we work

Andrew Bailey, Governor of the Bank of England and Chair of the Financial Stability Board, has issued a stark warning: artificial intelligence could turn a single cyberattack into a systemic shock capable of bringing down the global financial system. The concern centers on a handful of shared technology providers that underpin nearly every major bank, market infrastructure, and fintech platform worldwide. If one falls, the cascade could be swift and wide.

Bailey's Warning: AI as a Systemic Financial Threat

The possibility that frontier AI models could transform a cyberattack into a full-blown financial system shock is real, in Bailey's assessment. As both Governor of the Bank of England and Chair of the Financial Stability Board (FSB), he brings a dual vantage point to the debate: central bank governor and global systemic-risk watchdog. The FSB monitors the stability of international markets and has paid growing attention to crypto-assets and digital finance as systemic actors.

Ahead of the G20 Finance Ministers and Central Bank Governors meeting held in North Carolina on Tuesday and Wednesday, Bailey wrote a formal letter to his counterparts laying out the threat.

Artificial intelligence in UK financial services - 2024
The Bank of England and Financial Conduct Authority conducted a third survey of artificial intelligence and machine learning in UK financial services.

The letter focused on the threat posed by frontier AI models: the most advanced AI systems currently in development, capable of autonomous reasoning, complex problem-solving, and increasingly sophisticated attack behaviors within digital infrastructure. Crucially, these systems can be instructed to launch sustained cyberattacks against financial infrastructure. Unlike human actors, they don't tire. They can probe, test, and re-attempt without pause until a vulnerability is found and exploited.

Bailey's concerns echo a broader chorus of warnings about decentralized finance security. Earlier this summer, Manuel Aráoz, co-founder and former CTO of OpenZeppelin, publicly called DeFi fundamentally insecure, citing AI-assisted coding agents as part of the problem.

Global Finance Under Cyber Threat: Why Concentration Risk Matters

What makes this threat particularly serious is structural. Bailey's letter highlights a vulnerability that predates AI but is dramatically amplified by it: the financial system's dependence on a small number of shared technology providers.

The world's largest banks, market infrastructure operators, and technology companies all rely on the same vendors and platforms. A cyberattack targeting a major shared provider could propagate rapidly across jurisdictions, taking down institutions simultaneously rather than sequentially. This concentration risk transforms what might otherwise be a contained incident into a systemic event.

In his letter, Bailey urged financial institutions not to underestimate the threat and to begin building defenses capable of absorbing simultaneous disruptions across multiple nodes. He expressed particular concern about chains of shared technological dependency linking institutions that might appear operationally independent.

How to Defend: The FSB's Dual-Layer Approach

The Financial Stability Board is actively studying how the same frontier models that constitute the threat might be deployed as defenders. The logic is direct: AI that can identify vulnerabilities and launch attacks can, in principle, be repurposed to find and patch those same vulnerabilities faster than any human team.

The FSB is clear, though, that AI defense alone isn't sufficient. Human response and recovery teams remain essential. The board is pushing for improved vulnerability management, faster incident response capabilities, and above all stronger recovery architecture. Among the specific measures cited is the use of bare-metal physical infrastructure immediately following a serious attack: isolated, hardened systems that serve as genuine fallback environments, independent of the compromised network.

There's a genuine tension here. AI can accelerate both attack and defense. An environment where vulnerabilities are discovered and patched at ever-increasing speed could harden the financial system against cyberattacks over time. But if the speed of AI-driven countermeasures isn't carefully managed, those same systems risk rendering the infrastructure they're protecting inaccessible. Defense mechanisms that move faster than human oversight can follow create their own category of systemic risk.

AI Amplifies Vulnerabilities That Were Already There

Bailey's warning doesn't stop at cybersecurity. In his letter, he argues the global financial system was already fragile before AI arrived on the scene. AI hasn't created the vulnerabilities; it has magnified them.

Equity markets have seen a significant rise in leverage, including through the use of leveraged ETFs and momentum-based investment strategies that concentrate capital in the best-performing assets. Many of those assets are, predictably, shares in AI companies, which have seen strong growth globally and across European markets including Italy. The paradox Bailey is pointing to is uncomfortable: fintech and institutional finance may be actively funding the primary threat to their own stability.

The deeper risk isn't simply that a well-trained AI model could crash the valuations of the companies that build it, though that scenario isn't implausible. The more unsettling possibility is a simultaneous market crisis and cyberattack, both triggered by the same underlying cause, feeding one another in a feedback loop that becomes nearly impossible to contain.

For investors and institutions operating across European and global markets, Bailey's letter represents a signal worth watching. The FSB is expected to publish updated guidance on AI-related systemic risk ahead of the next G20 cycle. Financial firms that have not yet stress-tested their third-party technology dependencies against AI-assisted attack scenarios are now on notice: the regulator that oversees global financial stability considers this a live threat, not a theoretical one.

Consent Preferences