Financial authorities in the UK are warning firms to take action on the security risks rising as a result of frontier AI.
The Financial Conduct Authority, Bank of England, and the UK government issued a joint warning to the financial sector about the cybersecurity fallouts of frontier AI models – while these models can achieve superior cybersecurity posture, they also can amplify threats if found in the wrong hands.
As the complexity of AI models increase and become more readily available, cyber risks are expected to rise as well.
The introduction of Anthropic’s Claude Mythos, an AI model boasting superior vulnerability discovery skills, has sent shockwaves through the cyber ecosystem as security experts and threat actors alike wait intently to test out its capabilities.
“It is essential that firms have effective protective, detective, threat containment and cyber response capabilities including to address faster and more disruptive frontier AI-driven attacks,” the joint statement said.
The statement called on boards and senior management to ensure they have a sufficient understanding of frontier AI risks, with investment and resource decisions reflecting emerging threats.
As AI models increase their capabilities when it comes to vulnerability discovery and exploitation, firms should ensure they can triage, prioritise, risk assess, and remediate vulnerabilities faster, more frequently, and at scale.
Firms should also ensure frontier AI cyber risks are mitigated from third parties and supply chains.
Recommended reading
- The AI Shift in Identity Security: From Static Rules to Dynamic Risk Response
- OpenAI Brings Frontier AI Models to Cyber Defence With Daybreak
- A Privilege-Centric Playbook for Identity Security in Scotland
- Is the Race for AI Risking Identity Security?
Reducing the attack surface that a frontier AI model may access is essential, requiring effective data protection, network security, and access management.
Accelerated response and recover times are also essential to mitigate new threats, the statement said.
Underinvesting in core cyber fundamentals will see firms being mercilessly exposed by threat actors using AI agents,





