UK Authorities Urge Financial Firms to Up Cyber Defenses Against AI Threats

The UK Financial Conduct Authority, the Bank of England and HM Treasury urged regulated firms and financial market infrastructures to step up cyber defenses across governance, vulnerability management, third-party oversight, protection and recovery.

In a joint statement, the authorities said the cyber capabilities of current frontier AI models already exceed what a skilled practitioner could achieve, at significantly higher speed and scale and at lower cost. They said that if used maliciously, those capabilities amplify threats to firms' safety and soundness, to customers, to market integrity and to financial stability, and the risks are expected to grow as more advanced models become available. They warned that firms that have under-invested in core cyber-security fundamentals are likely to become progressively more exposed.

The authorities urged firms to take active steps across several domains. On governance and strategy, they recommended that boards and senior management have sufficient understanding of frontier AI risks, that investment and resourcing decisions should reflect the emerging threat - including the increased exposure from end-of-life systems or those out of vendor support. The authorities said firms should also consider whether they have appropriate insurance. On vulnerability management, the authorities said firms should be able to triage, prioritize, risk-assess and remediate vulnerabilities more quickly, more frequently and at scale, including through automation. On third-party risk, they said firms should be capable of identifying and managing external applications, libraries and services in their networks, including open-source software, and that they should be prepared to address vulnerabilities identified by third parties at scale. On protection, the authorities pointed to effective access management, network security and data protection to reduce the attack surface, and said firms should consider adopting automated and AI-enabled defenses to operate at comparable speed to AI-driven attacks. On response and recovery, the authorities referenced effective practices on cyber response and recovery capabilities previously published by the Bank, the Prudential Regulation Authority and the FCA.

The authorities said they will continue to monitor frontier AI developments and engage with industry through the Cross Market Operational Resilience Group, and pointed firms to further guidance from the National Cyber Security Centre.

Tags