Written by a human
What the FCA’s frontier AI review means for firms
Findings from the U.K. regulator's review into frontier AI usage and risk give firms vital guidance for building operational resilience.
In brief:
- The Financial Conduct Authority has shared the results of a multi-firm review into the impact of “frontier AI” on resilience
- The regulator has warned that these technologies represent a “step change in capability” for bad actors — but also for firms
- Organizations looking to use AI to identify gaps in their resilience are finding themselves inundated with more suggested fixes than their IT resource can keep up with
The U.K. Financial Conduct Authority (FCA) has added its voice to a choir of regulatory, government, and industry bodies discussing the potential risks and rewards of “frontier AI” — hugely powerful models capable of acting at previously unthinkable scale.
The regulator has issued a range of guidance measures for financial services firms to take to increase their cyber and operational resilience and to remain ahead of potential “operational instability” resulting from the speed at which frontier models can identify vulnerabilities.
What were the findings of the FCA’s multi-firm review into frontier AI and cyber resilience?
The FCA frontier AI and cyber resilience review built on joint messaging from the regulator, the Bank of England, and the Treasury shared in May 2026 around the importance of frontier AI in financial services. It also follows a 10-recommendation AI adoption plan issued by the regulator and the U.K. government. In its review, the FCA acknowledged that frontier AI “capabilities can outpace existing regulation and risk management practice,” urging firms to exercise extra caution and to consider governance.
The review lays out expectations that firms must:
- Learn from others
- Consider the findings of the review in their adoption of AI models
- Prepare for AI-enabled cyber threats
The latter point is especially timely given recent high-profile instances of frontier AI models behaving unexpectedly and accessing company data and infrastructure outside the confines of test environments.
The review also found that:
- Human judgment remains critical: Frontier AI can supply the speed and scale, but oversight from experienced humans is vital for managing risk and prioritizing action. From assessing where remediation resource will be best placed to gauging risk and resilience, humans very much still need to be kept “in the loop.”
- Frontier AI is a test of broader organizational resilience, not just a tool: Model deployment is revealing whether firms’ governance, risk ownership, engineering/IT capacity, and remediation processes are up to the required standard, and that “organizational readiness is the primary challenge.”
- Frontier AI is making foundational cyber and operational resilience more important: By exposing both firms’ potential vulnerabilities and dependencies and how they react to them, these models are underscoring that firms that already have the “resilience basics” like clear accountability and effective oversight right are better positioned to tackle AI challenges.
- Effectiveness isn’t just down to models, but the environment around them: While frontier models continue to advance and enable firms to improve cyber discovery, they can only be truly effective when firms understand how wider systems underpin vital business services, conduct robust validation, and implement clear operational guardrails like limits on model permissions and controls over sensitive data access.
What is the FCA’s frontier AI guidance?
The review holds up a mirror to firms leveraging frontier AI to assess their cybersecurity and operational resilience posture, highlighting that it provides a wider opportunity to look at their baseline governance and resilience measures. The FCA’s guidance suggests firms should:
Consider governance: With frontier AI increasing the pace of discovery, firms need to ensure that their governance and escalation routes can keep pace. Risk committees and senior leaders may need clear visibility of model impact remediation, supplier dependencies, risk, and resilience.
Clarify accountability: Firms should ensure use of frontier AI factors in clear ownership, appropriate guardrails, and specialist review of system and data access. This includes asking questions like:
- Who owns decision making around frontier AI use for cyber-resilience assessment?
- Are outputs being assessed by people with relevant expertise?
- Is there a clear way to escalate findings and risk?
Challenge prioritization approaches: Models may bundle together multiple lower priority vulnerabilities, or not consider wider knowledge of system dependencies. Firms are encouraged to take a broad view of cyber risk that looks past severity ratings and consider critical service provision when deciding which vulnerabilities to remediate.
Take a step back: Firms are reporting that frontier AI is forcing a holistic overview of cyber resilience, including considering whether controls may only be effective in isolation, how security architectures work cohesively, how quickly they can respond to risk, and how well they understand all the technology used across the business.
Assess supply chains: With financial services firms operating complex IT environments that can include significant third-party supply chains, it is imperative for them to consider cloud dependencies, supply chain visibility, and shared infrastructure, and ask questions including:
- Do you have visibility of dependencies and suppliers supporting important business services?
- Have you asked suppliers how they are preparing for AI-enabled discovery?
- Are you sharing intelligence with providers where risk may affect shared technology?
The (not so) final frontier
Our Industry Insights Report 2026 found that 45% of compliance professionals in financial services felt that we need more specific AI regulation, while 41% thought we need more clarity on existing regulatory expectations. While the FCA’s guidance is not hard and fast legislation, it comes at a time when AI continues to shift paradigms faster than ever before.
Regulators worldwide are increasingly emphasizing the importance of firms taking action to stay in step with this pace of change, as Simone Constant, Commissioner of the Australian Securities and Investment Commission (ASIC) summarized:
“Do not wait for perfect clarity to address the threat posed by new AI models. Instead, act now, and act with discipline, to strengthen the cyber resilience fundamentals that underpin your business.”
Firms that act now, from a strong foothold of reliable, secure data and working alongside security-first partners that understand the need for collaboration amid a fast-changing risk landscape will be the ones best positioned as the industry continues to boldly go towards the new AI-enabled frontier.
In a risk environment that is evolving faster than ever before, understanding how your partners leverage AI is increasingly vital. Learn more about how Global Relay provides compliant, security-first AI surveillance solutions that help you identify risk and harness the power of Gen AI.