Frontier AI will not break finance. Slow cyber decisions will
Executive Take
Boards can no longer treat patching backlogs and supplier risk registers as routine hygiene items on a committee agenda; they need a named owner and a funded decision for every exposed critical service before, not after, an incident forces the timeline.
Executive Summary
Regulators (Bank of England, FCA, HM Treasury, ESRB, ECB, US executive order) have warned in 2026 that frontier AI models can discover and exploit vulnerabilities faster than firms can patch them, creating systemic risk to financial market infrastructure. The ECB gave significant institutions until 31 October 2026 to deliver action plans on the changed threat environment.
Why It Matters
Technology and cybersecurity leaders at banks and financial infrastructure firms face a hard regulatory deadline (ECB's 31 October 2026 action-plan requirement) and a documented shift in attacker speed, meaning existing patch and third-party-risk processes are being tested against a much faster adversary.