Bank of England governor Andrew Bailey warns against weakening AI regulation

Bank of England governor Andrew Bailey warns against weakening AI regulation

Bailey calls for rigorous testing of frontier AI models, flagging cyber risks to global financial stability as an immediate concern.

The governor of the Bank of England has a message for the deregulation crowd: you’re oversimplifying things. Andrew Bailey has repeatedly pushed back against calls to loosen oversight of artificial intelligence in finance, arguing that the technology’s rapid advancement demands stronger safeguards, not weaker ones.

Bailey’s position centers on a straightforward premise. Frontier AI models are getting powerful enough to pose genuine cyber threats to the financial system, and the current testing infrastructure isn’t keeping pace.

The case for more testing, not less regulation

At a Mansion House speech on July 14, Bailey called advocacy for less regulation “unhelpfully reductive.”

His argument isn’t that AI should be slowed down. It’s that the financial system needs rigorous pre-deployment and post-deployment testing protocols before these models are trusted with anything resembling systemic responsibility.

Advertisement

Bailey followed up with a letter to G20 finance ministers on August 31, where he described frontier AI’s increasingly sophisticated threat capabilities as a “most immediate concern” for cyber risks to financial systems globally.

Then on September 30, he urged authorities to “get a grip” on AI risks. Three public interventions in under three months, each more urgent than the last.

The Anthropic problem

One specific concern Bailey raised is worth unpacking. He flagged that UK banks lack access to Anthropic’s Mythos model, which he identified as a significant vulnerability in managing cyber threats.

The logic goes like this: if you can’t test against the most capable AI systems, you can’t realistically assess how vulnerable your defenses are.

Bailey’s push for international coordination makes more sense in this light. No single regulator can compel access to frontier models built by foreign companies. That requires diplomatic-level agreements, the kind that get hammered out at G20 summits rather than in domestic policy papers.

What the Bank of England is already doing

The BoE already mandates that banks demonstrate cyber resilience through stress tests and penetration testing.

The governor also pointed to existing vulnerabilities in the financial system, including high leverage and concentrated asset valuations, that could be amplified by advanced AI.

The cost of compliance vs. the cost of inaction

For banks and financial institutions, Bailey’s regulatory push likely translates to higher operational costs. New testing requirements, additional compliance infrastructure, and potential restrictions on deploying AI tools internally all carry price tags.

Bailey’s implicit argument is that the alternative is worse. A major AI-enabled cyber incident in the banking system wouldn’t just hurt the targeted institution. It could trigger the kind of cascading confidence crisis that central bankers have spent the post-2008 era trying to prevent.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Bank of England governor Andrew Bailey warns against weakening AI regulation
Bank of England governor Andrew Bailey warns against weakening AI regulation

Bailey calls for rigorous testing of frontier AI models, flagging cyber risks to global financial stability as an immediate concern.

The governor of the Bank of England has a message for the deregulation crowd: you’re oversimplifying things. Andrew Bailey has repeatedly pushed back against calls to loosen oversight of artificial intelligence in finance, arguing that the technology’s rapid advancement demands stronger safeguards, not weaker ones.

Bailey’s position centers on a straightforward premise. Frontier AI models are getting powerful enough to pose genuine cyber threats to the financial system, and the current testing infrastructure isn’t keeping pace.

The case for more testing, not less regulation

At a Mansion House speech on July 14, Bailey called advocacy for less regulation “unhelpfully reductive.”

His argument isn’t that AI should be slowed down. It’s that the financial system needs rigorous pre-deployment and post-deployment testing protocols before these models are trusted with anything resembling systemic responsibility.

Advertisement

Bailey followed up with a letter to G20 finance ministers on August 31, where he described frontier AI’s increasingly sophisticated threat capabilities as a “most immediate concern” for cyber risks to financial systems globally.

Then on September 30, he urged authorities to “get a grip” on AI risks. Three public interventions in under three months, each more urgent than the last.

The Anthropic problem

One specific concern Bailey raised is worth unpacking. He flagged that UK banks lack access to Anthropic’s Mythos model, which he identified as a significant vulnerability in managing cyber threats.

The logic goes like this: if you can’t test against the most capable AI systems, you can’t realistically assess how vulnerable your defenses are.

Bailey’s push for international coordination makes more sense in this light. No single regulator can compel access to frontier models built by foreign companies. That requires diplomatic-level agreements, the kind that get hammered out at G20 summits rather than in domestic policy papers.

What the Bank of England is already doing

The BoE already mandates that banks demonstrate cyber resilience through stress tests and penetration testing.

The governor also pointed to existing vulnerabilities in the financial system, including high leverage and concentrated asset valuations, that could be amplified by advanced AI.

The cost of compliance vs. the cost of inaction

For banks and financial institutions, Bailey’s regulatory push likely translates to higher operational costs. New testing requirements, additional compliance infrastructure, and potential restrictions on deploying AI tools internally all carry price tags.

Bailey’s implicit argument is that the alternative is worse. A major AI-enabled cyber incident in the banking system wouldn’t just hurt the targeted institution. It could trigger the kind of cascading confidence crisis that central bankers have spent the post-2008 era trying to prevent.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.