From the journal

UK Regulators Issue Joint Statement on Frontier AI Cyber Resilience, 15 May 2026

On 15 May 2026, the Financial Conduct Authority, Bank of England, and HM Treasury issued a joint statement identifying frontier AI models as a material cybersecurity threat requiring immediate action from regulated financial firms and financial market infrastructures. The statement does not introduce new rules but carries supervisory weight, placing frontier AI risk within existing operational resilience obligations and calling on boards to demonstrate active oversight.

3 min read

On 15 May 2026, the Financial Conduct Authority, Bank of England, and HM Treasury issued a joint statement on frontier AI models and cyber resilience. The statement is not a rule or binding obligation, but constitutes a coordinated supervisory expectation from three peak UK financial regulators. Frontier AI models already exceed skilled human practitioners in identifying and exploiting cybersecurity vulnerabilities, operating at materially higher speed, scale, and lower cost. Regulated firms and financial market infrastructures must take active steps to address these risks now.

The statement situates frontier AI risk within existing operational resilience obligations. For FCA-authorised enhanced firms, those obligations appear in SYSC 15A of the FCA Handbook, effective from 31 March 2022 under Policy Statement PS21/3. For Bank of England and PRA-supervised firms, the equivalent source is Supervisory Statement SS1/21 on operational resilience. Both instruments require boards to set impact tolerances and ensure the ability to continue operations through severe disruptions. The statement adds frontier AI as a live risk category within these existing requirements, without creating new statutory provisions. Firms should also monitor publications from the Cross Market Operational Resilience Group and the National Cyber Security Centre.

Deposit-takers, investment firms, payment service providers, insurers, and financial market infrastructures regulated by the FCA or Bank of England must now incorporate frontier AI-driven cyberattack scenarios into their operational resilience assessments. Boards and senior management must demonstrate sufficient understanding of frontier AI risk to direct investment and oversight. Firms should review access management, network segmentation, and data protection controls for gaps that a frontier AI model could exploit. Deploying automated and AI-enabled defensive capabilities capable of matching the speed and scale of AI-driven attacks is a specific expectation in the statement.

The statement provides no formal implementation deadline or transitional period. The government and regulators will continue monitoring frontier AI developments and engaging with industry through the Cross Market Operational Resilience Group. Firms should treat this statement as live supervisory guidance rather than a consultation document awaiting a formal response period. The CMORG Frontier AI Risk Mitigation Webinar, held on 14 May 2026, provides supplementary technical context for compliance planning.

Licentium advises regulated financial institutions on AI governance, operational resilience, and cybersecurity compliance across UK and EU regulatory regimes. Our partner network includes specialists in FCA and PRA supervisory engagement and board-level risk governance. Work we undertake includes: AI governance review, operational resilience program assessment, FCA cybersecurity supervisory response, senior manager accountability analysis under SMCR, and board reporting on AI-related cyber risk.

Source: FCA, Bank of England and HM Treasury, Joint Statement on Frontier AI Models and Cyber Resilience, 15 May 2026

AI Regulatory

More from the journal

See all

European Commission Publishes Draft Guidelines Classifying High-Risk AI Systems Under Article 6, May 2026

On May 19, 2026, the European Commission published draft guidelines on the classification of high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (EU AI Act), open for consultation until June 23, 2026. The guidelines interpret key classification concepts and provide worked examples across eight Annex III sectors. The Commission has also postponed Article 6(2) compliance from August 2026 to December 2027 and Article 6(1) from August 2027 to August 2028.

Connecticut Enacts Sweeping AI Law Covering Employment, Healthcare, and Online Safety in June 2026

Connecticut Governor Ned Lamont signed Senate Bill 5 on June 2, 2026, enacting the Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act, Public Act 26-15). The law creates disclosure obligations for employers using AI in hiring and layoff decisions, safety protocols for chatbot operators, and content-provenance requirements for large-scale generative AI systems. Compliance deadlines run from October 2026 through January 2028.

New Zealand Online Casino Gambling Regulations 2026 Released, Effective July 2026

New Zealand released the Online Casino Gambling Regulations 2026 in June 2026, made under the Online Casino Gambling Act 2026 (Public Act 2026 No 14). The prohibition on unlicensed online casino gambling applies from 1 July 2026. The Act establishes a three-stage licensing regime for up to 15 operators, administered by the Secretary for Internal Affairs, with age-verification, harm-minimisation, and problem-gambler exclusion obligations.

Ready to launch without the regulatory guesswork?

Book a 30-minute consultation. We'll map your AI or licensing path and tell you exactly what's required, in plain language.