From the journal

FCA, Bank of England and HM Treasury Warn Firms on Frontier AI Cyber Risks, May 2026

On May 15, 2026, the FCA, Bank of England, and HM Treasury issued a joint statement identifying frontier AI cyber capabilities as an active systemic risk to financial services firms. The statement sets out supervisory expectations for governance, vulnerability management, automated defence deployment, and incident recovery under existing rules. No new regulations were issued; the authorities indicated that current obligations apply to frontier AI-driven threats immediately.

2 min read

The FCA, Bank of England, and HM Treasury issued a joint statement on May 15, 2026, addressing frontier AI models and cyber resilience in financial services. The statement is addressed to regulated financial services firms and constitutes a supervisory communication, not new rules. The three authorities treat frontier AI cyber risk as a live and material concern requiring firms to act under existing obligations.

The statement draws authority from existing regulatory obligations, including FCA Principle 3 on management and control systems, PRA Fundamental Rule 7 on operational resilience, and the Bank of England and FCA operational resilience rules effective March 2022. It identifies frontier AI cyber capabilities as exceeding what a skilled practitioner can achieve in speed and scale. Adversaries using those capabilities can identify and exploit technology estate vulnerabilities across multiple firms simultaneously, at a rate that conventional security controls cannot match.

Regulated firms, including FCA-authorised firms, PRA-supervised institutions, and payment service providers, must act in four areas. Boards and senior management must demonstrate adequate understanding of frontier AI risks. Firms must continuously identify and manage technology estate vulnerabilities. Firms must deploy AI-enabled defensive controls that can operate at the speed of AI-driven attacks. Firms must maintain response and recovery capabilities sufficient to address disruption quickly. The FCA and Bank of England will monitor progress through existing supervisory channels, including the Cross Market Operational Resilience Group (CMORG).

The statement does not set a compliance deadline. The language 'firms should be taking active steps' signals that supervisory challenge is available now. The three authorities will update their expectations as frontier AI capabilities develop and will continue industry engagement through CMORG and the National Cyber Security Centre.

Licentium advises financial services firms on AI governance and regulatory compliance across UK and EU regulatory requirements. We support clients on operational resilience program design and board-level AI risk reporting. Work we undertake includes AI governance reviews, UK operational resilience gap assessments, frontier AI risk advisory, and FCA and PRA regulatory advisory.

Source: FCA, Bank of England, and HM Treasury, Joint Statement on Frontier AI Models and Cyber Resilience, 15 May 2026

AI Regulatory

More from the journal

See all

Colorado Enacts Automated Decision-Making Technology Law, Replacing 2024 AI Act, May 2026

Colorado Governor Jared Polis signed SB 26-189 into law on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205). The new law regulates automated decision-making technology in consequential decisions, requiring deployers to conduct impact assessments, disclose ADMT use to affected individuals, and provide opt-out rights. The Act takes effect July 1, 2026.

European Commission Publishes Draft High-Risk AI Classification Guidelines Under AI Act, May 2026

On May 19, 2026, the European Commission published draft guidelines interpreting Article 6 of Regulation (EU) 2024/1689 on classifying high-risk AI systems. The guidelines provide worked examples by Annex III sector and are open for targeted consultation until June 23, 2026. Though not legally binding, they will guide national market surveillance authorities and shape enforcement practice across EU member states.

OCC Grants Preliminary Conditional Approval to Augustus Bank for Stablecoin Charter, May 2026

The Office of the Comptroller of the Currency granted Augustus Bank, N.A. a preliminary conditional approval to charter a national bank with a stablecoin-issuing subsidiary in Dallas, Texas. The approval references the GENIUS Act (12 U.S.C. § 5901 et seq.) and attaches conditions on capital, governance, and stablecoin reserve management before the bank may open. The OCC retains the right to rescind the approval.

Ready to launch legally?

Book a 30-minute consultation. We'll map your licensing path and tell you exactly what's required, in plain language.