Global financial stability is at risk from artificial intelligence-amplified cyberattacks, the Financial Stability Board warned. FSB Chair Andrew Bailey, who is also Governor of the Bank of England, wrote to G20 finance ministers and central bank governors ahead of meetings on August 31 and September 1, 2026, urging urgent attention to the ways advanced AI is changing the cyber threat landscape.
Bailey said frontier AI models are gaining autonomy and problem solving ability, and that their growing offensive capabilities present new hazards. The board highlighted a concentration risk, where the sector’s reliance on a small set of technology vendors and shared infrastructure increases the likelihood of broad, simultaneous disruption, and could erode confidence across markets if failures cascade.
The FSB urged financial firms to tighten vulnerability management and to upgrade response and recovery practices. It demanded assurances that critical third-party technology suppliers and other common service providers can withstand severe shocks, and called for planning against scenarios that would produce concurrent outages across multiple institutions because of shared dependencies.
The board’s analysis recorded a sharp rise in financial harm from cybercrime, with reported losses rising from $192 million in 2024 to $484 million in 2025. It flagged a trend of criminals using AI to scale fraud and attacks, increasing speed, sophistication and reach, and said AI now drives most cybercrime in Africa as losses reached $484 million.
National regulators are already responding. Nigeria’s National Information Technology Development Agency is strengthening the country’s cybersecurity framework with proposals that include minimum cybersecurity spending thresholds, mandatory timelines for reporting data breaches, threat-intelligence sharing, and coordinated responses to major cyber incidents.
Bailey’s letter places these concerns on the G20 agenda for the August 31 and September 1, 2026 meetings, signalling intensified scrutiny of both financial firms and the concentrated technology providers that underpin them. The immediate implication for markets is clearer regulatory pressure and a renewed focus on third-party resilience, with firms expected to demonstrate that they can manage, contain and recover from AI-enabled attacks.
