AI spots cyber gaps faster than financial firms can fix them
Frontier AI models are finding cyber security vulnerabilities faster than financial services companies can fix them, according to the UK regulator, which warned it could cause “operational instability” at some firms.
The Financial Conduct Authority said the growing use of AI models at financial services companies to search for flaws in cyber defences is threatening to create “bottlenecks” because the new technology is finding so many problems that they are struggling to keep up.
The warning from the regulator on Wednesday, following its review of how firms are using AI to bolster cyber security, is the latest sign of how the new technology is raising concerns about the financial system’s ability to defend itself against external attacks.
Bank of England governor Andrew Bailey warned fellow central bank bosses and finance ministers of G20 countries at their meeting this week that the threat frontier AI models pose to cyber security is increasing the risk of a market meltdown as he called for more controls on the technology.
The FCA said: “Frontier AI is changing the speed, scale and manner in which vulnerabilities can be discovered and may need to be addressed.”
“Firms have suggested that it’s not just whether they can identify vulnerabilities, but whether they can effectively assess and respond to a continuous flow of findings,” it said, adding this could “put considerable pressure on remediation teams, engineering resources and change-management processes”.
Companies need to “understand where vulnerability remediation bottlenecks will arise and whether existing processes can accelerate without creating operational instability,” it said.
The logjam stems from both the large numbers of IT flaws detected by AI models and the organisational and governance challenges that hamper companies’ ability to deal with the issues or make quick decisions.
“This is what happens every time detection technology leaps ahead of the process built to act on it: alerts start multiplying faster than any team can work through them,” said Andrew Jones, co-founder of cyber security provider Adaptive Security.
“Every vulnerability a model flags carries a different level of risk, and treating them all the same is how teams end up chasing low-risk findings while high-risk ones sit untouched,” said Jones. “The fix is funding the people and systems that can rank how dangerous and business-critical each vulnerability is as fast as the model finds new ones.”
The FCA told companies to check they have sufficient specialist engineers to validate cyber security vulnerabilities and to test and implement IT patches to fix flaws in their software while keeping systems running.
Financial companies’ IT stacks can be complex, particularly those firms that have undergone mergers and rely on patched-up legacy systems.
“Attackers can already find and actively exploit a new vulnerability within hours, while many firms’ remediation cycles still run into weeks or months,” said Craig Parkin, associate managing director for cyber strategy and risk at consultants Kroll. “This will be especially difficult for older legacy systems, where weaknesses are often hard to remediate or have been risk accepted because they are unpatchable.”
Recommended
Fears about the impact of AI on cyber security intensified after recent incidents in which the flagship models being tested by Anthropic and OpenAI went rogue, hacking into external organisations and creating fake identities to deceive people who were running the tests.
“In financial services [cyber security] matters more than almost anywhere,” said Nik Kairinos, head of Raids AI, which monitors AI systems. “When an AI system fails here, money moves, legal exposure follows and reputations built over decades can be damaged in minutes.”
He added: “AI has moved faster than regulation can follow, and that gap is where the risk sits.”