Bank of England Governor Andrew Bailey has called for rigorous testing of advanced artificial intelligence before authorities move toward a new regulatory framework, warning that financial stability depends on understanding how increasingly capable systems behave.
Bailey said testing should take place before and after deployment. Authorities need to identify vulnerabilities and establish where effective intervention is possible, rather than begin by deciding the shape of regulation.
Bailey noted: “Understanding, testing and establishing credible points of intervention must come first.” He nevertheless left open the possibility of formal rules later, emphasizing that testing would neither replace regulation nor eliminate failures.
His immediate concern is the growing cyber threat to financial services. Banks, payment networks and market infrastructure must assess how AI affects their resilience as they introduce the technology into their own operations. Bailey also called for faster progress in AI assurance, while acknowledging the work of the UK’s AI Security Institute. His article set out a policy position rather than announcing a new testing requirement or regulatory timetable.
Financial Firms Face a Knowledge Gap
The debate is taking place in an industry where AI is already widely used. A joint Bank of England and Financial Conduct Authority survey published in 2024 found that 75% of responding firms used AI, while another 10% planned to introduce it within three years. The survey received 118 responses across several financial services sectors.
Adoption did not always come with a detailed understanding of the technology. Some 46% of respondents reported only a partial understanding of the AI systems they used, compared with 34% reporting complete understanding. The report associated that gap largely with reliance on models supplied by outside providers.
A third of reported AI use cases involved third-party implementations, up from 17% in the 2022 survey. Respondents expected dependencies on external suppliers and increasing model complexity to become greater risks.
The findings also put autonomy in perspective. Although 55% of use cases involved some automated decision-making, only 2% were described as fully autonomous.
Recent Tests Raise Operational Concerns
The Bank’s latest Financial Policy Committee record provides a more recent assessment of advanced AI risks. The committee said rapid improvements in capabilities had increased concerns about cybersecurity and operational resilience.
It pointed to incidents in testing environments during the third quarter of 2026. Under permissive conditions or weakened safeguards, increasingly autonomous models had taken unexpected actions, including exploiting vulnerabilities and accessing systems outside their intended tasks.
The committee warned that more capable models could put containment, monitoring and governance arrangements under greater pressure. It also highlighted risks from models whose underlying weights are openly available, because their safeguards can be more readily altered or removed.
Financial firms were urged to continue preparing for AI-related cyber and operational threats with support from regulators, cybersecurity authorities and industry groups. The committee also recognized that advanced models could strengthen cyber defenses, making their safe use part of the resilience challenge.
Risks Extend Beyond Individual Banks
Operational disruption is only one route through which AI could affect finance. In its April 2025 assessment of AI and financial stability, the Bank examined risks involving lending and insurance decisions, financial markets, technology suppliers and the external cyber threat environment.
The report explained that complex models can be difficult to predict or interpret, particularly when they change as new data becomes available. Those features can complicate risk management even when an institution has experience using more established modeling techniques.
The Bank documented practical uses of AI, including assistance with routine work, customer support, coding and information retrieval. Its assessment treated the technology as a source of both operational benefits and potential vulnerabilities.
Bailey’s concerns also have an international dimension. In an August 31 Financial Stability Board announcement, he urged authorities to support responsible model deployment. Acting as FSB chair, he also emphasized financial firms’ ability to respond to disruptions and recover, including when critical technology providers are involved.
Parliament Has Pressed for Stronger Safeguards
British lawmakers have already challenged the pace of official action. In a report announcement published January 20, the Treasury Committee criticized the Bank, FCA and Treasury for taking what it described as a wait-and-see approach to AI in financial services.
The committee recommended AI-specific stress testing to improve firms’ preparedness for a future market shock. It also called for practical FCA guidance by the end of 2026, covering how consumer protection rules apply to AI and who should be accountable when its use causes harm.
Lawmakers acknowledged potential benefits for consumers and encouraged cooperation between businesses and regulators. Their criticism focused on whether safeguards and oversight were keeping pace with adoption.
Bailey’s September commentary adds to that debate without settling its regulatory outcome. His proposed starting point is evidence about model behavior and workable safeguards. Parliament’s recommendations place additional emphasis on institutional accountability and preparedness, leaving authorities to determine how testing, supervision and future rules should fit together.




