AI risk climbs up UK financial firms' systemic risk list
Bank of England survey data show 63% of respondents now cite AI among their five greatest-impact risks, up from 31% previously, even as confidence in stability stays high.
- Published

The Bank of England's latest Systemic Risk Survey, published on 30 September 2026, found that 63% of participating firms cited risks surrounding artificial intelligence among the five risks they believed could have the greatest impact on the UK financial system if they materialised. That is up 32 percentage points from 31% in the 2026 H1 survey, making AI the third most frequently cited potential source of systemic risk, behind geopolitical risk and cyberattack.
The survey covered 57 firms — a 66% response rate — drawn from UK banks and building societies, large foreign banks, asset managers, hedge funds, insurers, pension funds, large non-financial companies and central counterparties. Fieldwork ran from 27 July to 24 August 2026. The Bank is explicit that these results represent market participants' views and do not necessarily reflect its own assessment of risks to the UK financial system. The 63% figure describes free-text answers from executives responsible for risk management or treasury, not a Financial Policy Committee (FPC) finding that AI poses a near-term threat to stability.
Respondents told the Bank they were particularly concerned about the rapid pace of technological development and a lack of controls and governance. Those two phrases carry most of the analytical weight in this story, and the underlying evidence is more complicated than the headline number suggests.
Mainstream concern, not the top-ranked danger
The clearest way to read the 63% figure is as evidence that AI has moved from a niche worry to a widely cited concern among the firms surveyed. It is not evidence that those firms see AI as the most dangerous risk they face.
| Measure (2026 H2) | AI | Geopolitical risk | Cyberattack |
|---|---|---|---|
| Cited among top five systemic risks | 63% | 91% | 75% |
| Ranked the number-one risk | 4% | 47% | 26% |
Only 4% of respondents ranked AI as their single biggest risk, up just 2 percentage points from 2026 H1. AI risk is widely acknowledged but rarely considered the most severe threat on the table.
AI was also cited as one of the three risks most challenging to manage by 37% of respondents, up 26 points from 11%, and among risks most likely to materialise by 32%, up 18 points from 14%.
| AI-related measure | 2026 H1 | 2026 H2 | Change |
|---|---|---|---|
| Cited among top five systemic risks | 31% | 63% | +32pp |
| Ranked the number-one risk | 2% | 4% | +2pp |
| Cited as hard to manage | 11% | 37% | +26pp |
| Cited as likely to materialise | 14% | 32% | +18pp |
Despite this, 95% of 2026 H2 respondents said they were very or fairly confident in UK financial-system stability over the next three years — 39% very confident, 56% fairly confident. Rising AI concern and high system-wide confidence answer different questions rather than contradicting each other, but the two findings sit in tension: treat the 63% figure as a measure of attention, not of expected harm.
Why attention has risen
The survey does not explain the 32-point jump; it groups free-text answers into categories after the fact without publishing how many respondents mentioned each underlying concern. Any explanation of the rise is context, not demonstrated cause.
That context is substantial. The Bank and Financial Conduct Authority's (FCA) 2024 survey of 118 regulated firms found 75% were already using AI and a further 10% planned to within three years, up from 58% and 14% in 2022. Firms expected their median number of AI use cases to rise from 9 to 21 over three years. A third of reported 2024 use cases were third-party implementations, up from 17% in 2022, and 55% involved some automated decision-making, with 2% fully autonomous. Faster adoption, more use cases and more automated decisions are plausible reasons risk officers would write more about AI in 2026, but the 2024 adoption survey and the 2026 systemic-risk survey are different instruments with different samples, and the evidence does not support a direct causal line between them.
What "weak controls and governance" means in practice
The phrase could suggest firms using AI have no governance at all. The 2024 AI survey suggests otherwise: 84% of respondents had a named accountable person for their AI framework, and 72% assigned accountability for AI use cases to executive leadership, though responsibility was often split across three or more people or bodies — fragmentation rather than absence.
A clearer gap shows up in understanding. Only 34% of firms using or planning to use AI reported complete understanding of the technologies they used; 46% reported only partial understanding, a gap the Bank and FCA associated mainly with third-party models. Firms can own a framework on paper while still not fully knowing how a supplied model reaches its outputs.
This has a supply-chain dimension. The three largest providers accounted for 73% of reported cloud providers, 44% of model providers and 33% of data providers in the 2024 survey. That concentration means weaknesses or outages at a small number of external firms could, in principle, touch many institutions at once — a possibility the FPC flagged in its April 2025 Financial Stability in Focus assessment as one of four channels through which AI could affect the system, alongside AI in core financial decisions, AI in financial markets, and changes to the cyber-threat environment.
Worth recording rather than resolving: in the Bank, Prudential Regulation Authority (PRA) and FCA's 2023 feedback statement on AI and machine learning, respondents generally felt existing governance structures and the Senior Managers and Certification Regime could handle AI risks. Three years later, systemic-risk respondents are citing weak controls and governance among their top concerns. The evidence does not establish whether this reflects changed technology, a different sample, or a gap between having a framework and that framework working well under faster AI deployment.
Banks and insurers: common models, common errors
For banks, the FPC's 2025 assessment identifies a channel running through AI's growing role in core decisions such as credit allocation. If multiple lenders rely on similar AI-driven credit models sharing a weakness, errors could appear simultaneously across the sector rather than at a single institution — a potential channel the Bank has set out, not evidence that such an error has occurred.
The same logic extends to insurers' underwriting and pricing. If AI tools used across several insurers misjudge risk in similar ways, the consequences could appear in mispriced policies or impaired claims handling, with prudential and consumer-protection implications. Premiums, cover and claims decisions are not guaranteed outcomes, and consumers should check official FCA or insurer disclosures rather than treat this article as advice on any specific product.
Asset managers and trading firms: correlated decisions
The FPC's assessment also describes a market-facing channel: if asset managers and trading firms increasingly rely on similar or autonomous AI-driven strategies, their positioning could become more correlated, amplifying stress during a shock rather than dampening it. The Bank's own market intelligence indicated that advanced autonomous trading remained largely experimental as of its 2025 assessment, so this is a prospective risk whose pace and scale are uncertain, not an observed pattern.
Financial infrastructure and payments: concentrated suppliers
For financial market infrastructures, central counterparties and payment providers, the concern is operational continuity. The 2024 AI survey found a small number of suppliers accounted for a large share of the cloud, model and data providers reported by surveyed firms — not necessarily of the wider market. If one such provider failed, firms depending on it for an important business service might struggle to migrate quickly. The PRA's operational-resilience supervisory statement already requires in-scope banks, building societies, PRA-designated investment firms and insurers to identify important business services and set impact tolerances for disruption. The current version took effect on 31 March 2022 and is technology-neutral: not written for AI specifically, but applicable regardless of the underlying technology.
The UK regulatory position
There is no single AI-specific rulebook for UK financial services. The FCA, PRA and Bank of England have generally applied existing, technology-neutral frameworks — governance and accountability rules, consumer-outcome requirements, and operational-resilience expectations such as SS1/21 — to firms' use of AI, adapting supervisory expectations rather than legislating new AI-specific rules. The 2023 feedback statement contained no policy proposals. In a February 2026 summary of roundtables with banks and insurers, firms generally supported the PRA's principles- and outcomes-based approach, while noting caution among second-line risk functions and shortages of AI skills. The FCA's Mills Review, completed in July 2026, examined AI's long-term impact on retail financial services, including risks such as fraud, bias, opaque decisions and systemic vulnerability, while continuing to rely on existing outcomes-focused frameworks. Exactly which rules apply to a given firm depends on its authorisation, activities and sector; readers with questions about a specific firm's obligations should consult the FCA or PRA directly.
Limits of the evidence
Several gaps limit how far the 63% figure can be pushed. The Bank does not publish how many respondents specifically mentioned rapid technological change versus weak controls within their free-text AI answers, so their relative weight is unknown. The survey does not break AI-risk citations down by sector, so the implications above come from the FPC's separate channel analysis, not a sectoral split of the 57 respondents. Participants are anonymous, so firm-level exposure cannot be assessed. The categories used in this and earlier surveys were coded from free-text responses, and the Bank retrospectively regrouped earlier results for comparability; no evidence establishes the precise cause of the 32-percentage-point rise.
What to watch next
The Bank and FCA launched a further AI adoption survey on 5 June 2026; its results had not been published as of 3 October 2026 and should update the adoption, third-party-use and governance figures cited here. Readers wanting the primary data behind this article can consult the Bank of England's 2026 H2 Systemic Risk Survey results and its April 2025 Financial Stability in Focus assessment directly, and should watch for any change in FPC monitoring or firm-level supervisory expectations that follows.
Sources
- Systemic Risk Survey Results - 2026 H2 (opens in a new tab)
Bank of England · · Accessed
- Artificial intelligence in UK financial services - 2024 (opens in a new tab)
Bank of England and Financial Conduct Authority · · Accessed
- Financial Stability in Focus: Artificial intelligence in the financial system (opens in a new tab)
Bank of England · · Accessed
- FS2/23 – Artificial Intelligence and Machine Learning (opens in a new tab)
Bank of England, Prudential Regulation Authority and Financial Conduct Authority · · Accessed
- SS1/21 Operational resilience: Impact tolerances for important business services (opens in a new tab)
Prudential Regulation Authority · · Accessed
- Summary of AI roundtables - February 2026 (opens in a new tab)
Bank of England · · Accessed
- Review into the long-term impact of AI on retail financial services (The Mills Review) (opens in a new tab)
Financial Conduct Authority · · Accessed


