Frontier AI fuels security bottlenecks at financial firms
The UK Financial Conduct Authority warned frontier AI is finding software, system and infrastructure vulnerabilities faster than firms can patch, creating “vulnerability bottlenecks.”
The UK Financial Conduct Authority published a review on Sept. 3, 2026, warning that frontier artificial intelligence is surfacing software, system and infrastructure vulnerabilities faster than many financial firms can remediate them, creating what the regulator called “vulnerability bottlenecks.” The FCA said the volume of AI findings, even after human triage, is placing considerable pressure on engineering resources, remediation teams and change-management processes.
The review examined how banks, insurers and other financial firms are using, testing and preparing for advanced AI models. It found that the speed and scale of AI-driven discovery often outpaces firms’ ability to assess and fix problems, producing a continuous flow of findings that firms struggle to process.
The FCA described a technique known as vulnerability chaining, where AI links multiple low-rated flaws to create end-to-end attack paths that traditional scanners and tests can miss. Several firms reported they are moving away from judging risk by single-vulnerability scores and instead assessing the likely disruption from a combined attack path.
Andrew Bailey, chair of the Financial Stability Board, warned G20 finance ministers and central bank governors in an open letter that “Frontier AI may have the ability to materially alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers.” The regulator advised firms and policymakers to prepare for higher volumes of vulnerabilities and faster patching cycles, which could create operational and resilience challenges.
The review said AI is uncovering not only technical flaws but also gaps in staff capacity, processes and system dependency mapping. Firms told the FCA they find it difficult to keep up with the continuous output of AI tools and need ways to accelerate remediation without creating operational instability.
While AI can automate discovery, assist code analysis and inform prioritisation, the FCA noted that specialist human oversight remains necessary to validate findings and make risk-based decisions. The regulator observed that “the benefits of autonomous discovery can be limited where processes cannot keep pace with the volume of output.”
Several firms reported steps they are taking in response. They said they are mapping IT systems more thoroughly, cataloguing dependencies to identify alternative compromise routes, adopting defence-in-depth approaches and engaging suppliers to understand how third parties use AI for vulnerability discovery, validate AI-generated findings and notify customers about risks.
The FCA’s review follows an earlier report in July on AI’s impact in retail financial services, which highlighted that AI will change how retail firms operate and how consumers make financial decisions while potentially amplifying risks such as fraud, cyber security issues, consumer harm and market concentration.
The FCA’s findings record the challenges firms described and the practices they reported adopting to manage rising volumes of AI-driven vulnerability findings and related operational pressures.








