2026-09-03
UK’s FCA warns finance firms on frontier AI and cyber risk in new guidance
On September 2, the UK’s Financial Conduct Authority (FCA) published new online guidance outlining how “frontier AI” systems could affect cyber resilience, governance and vulnerability management in financial firms. The regulator cautions that large, cutting‑edge models can introduce fresh attack surfaces and operational risks for banks, brokers and fintech platforms.
The FCA stresses the importance of what it calls “harness engineering” – the surrounding controls, infrastructure and processes that make AI outputs safe and reliable. Examples include robust testing before and after model updates, managing risks in the AI supply chain, and keeping detailed audit logs of model outputs and human overrides. Senior management, the FCA notes, must ultimately take responsibility for understanding and mitigating these risks.
While the UK still lacks a comprehensive horizontal AI law, supervisors are tightening expectations within existing cyber and operational‑resilience rules for finance. The FCA’s move sits alongside the EU’s AI Act and various US agency frameworks, offering another glimpse of how regulators are zeroing in on AI risks in critical sectors even without passing entirely new AI‑specific statutes.