Bank of England boosts funding to tackle frontier AI risks
The Bank of England's Court approved extra funding for frontier AI work on 16 July 2026, without disclosing the amount or programme. Here's what it signals for UK banks' cyber defences.
- Published

The Bank of England's Court of Directors approved additional funding on 16 July 2026 for work addressing the challenges posed by frontier AI during the current financial year. The decision only became public when the Court's minutes were published on 1 October 2026, and even then the Bank disclosed neither the amount nor the detailed programme behind it.
That matters to UK banks, insurers, payment firms and financial market infrastructures because the funding decision sits alongside a parallel strand of work recorded in the same minutes: Governor Andrew Bailey told Court that the Bank was supporting banks to secure sufficient access to AI models to protect their cyber security. Read together, the two items are evidence that the Bank is devoting institutional attention and resources to frontier AI as an operational-resilience and financial-stability issue, even though no new rule has been written.
The timing is not incidental. It follows a May 2026 joint statement from the Bank, the Financial Conduct Authority (FCA) and HM Treasury telling regulated firms to prepare for AI-accelerated cyber threats under existing rules, and the July 2026 launch of a forum for systemically important deposit-takers and financial market infrastructures in UK-headquartered groups to share information on using frontier AI defensively. For a UK reader working in financial services, the practical question is not whether a new obligation has landed, but whether existing operational-resilience duties are now being tested against a much faster-moving threat.
What Court actually approved
The Court minutes record the request and the approval in three sentences, under an agenda item headed "Frontier AI impact on the Investment Portfolio". The text uses "additional investment" in describing the request and "additional funding" in recording the approval, but it does not state a sum, a budget line, a procurement route, named recipients, milestones or expected outputs. Court minutes can omit information where publication would raise public-interest, legal or commercial sensitivity, but the published record does not disclose the amount or the programme and does not say whether that provision applies in this instance.
The agenda heading refers to the Bank's Investment Portfolio, which could suggest the funding concerns how frontier AI affects the Bank's own investment operations. But the accompanying description is broader — work "to address frontier-AI challenges" — and nothing in the published record confirms whether the money is going toward the Bank's internal technology, its financial-stability research, its supervisory capacity, portfolio management, or some combination of these. Readers should treat any more specific characterisation of the funding's purpose as inference, not disclosed fact, until the Bank publishes further detail, for instance through its annual accounts.
A second, separate strand: helping banks reach the models
At the same Court meeting, Bailey said the Bank was supporting banks in gaining sufficient access to AI models to protect their cyber security. The minutes do not explain the mechanism — whether this means convening firms and model providers, facilitating information-sharing, supporting testing arrangements, or something else. There is nothing in the public record to suggest the Bank is purchasing model licences on banks' behalf, and the minutes do not say whether this work draws on the same funding Court just approved or is resourced separately; the two matters were recorded separately in the minutes of the same meeting, and the public record does not establish a connection between them.
This work is not happening in isolation. In July 2026 the Bank launched the Frontier AI Information Sharing Forum (FAISF) with the FCA, HM Treasury and the National Cyber Security Centre, aimed at systemically important deposit-takers and financial market infrastructures in UK-headquartered groups, to support safe and responsible information-sharing about using frontier AI for cyber defence. The FAISF's published material is explicit that it introduces no additional supervisory expectations, and the Bank's AI Consortium had already discussed the implications of recent frontier-model breakthroughs for financial services in June 2026.
Why model access is a cyber-defence question, not a procurement detail
The reason the Bank is treating model access as a priority worth raising at Court is laid out in its own risk assessments. The Financial Policy Committee (FPC) judged in its July 2026 record that frontier AI could pose material risks to UK financial stability through cyber and operational-resilience channels, because vulnerabilities in software might be found and exploited faster than firms can detect, contain and remediate them. The FPC repeated that warning in its September 2026 record, saying firms should prepare for frontier-AI cyber and operational risks and engage with regulators, the National Cyber Security Centre and sector groups.
The Bank's assessment is explicitly two-sided. Frontier AI can strengthen defensive vulnerability discovery, but the same capability can increase the speed, scale and sophistication of attacks. The May 2026 joint statement from the Bank, FCA and HM Treasury said current frontier-model cyber capabilities already exceed those of a skilled human practitioner in speed, scale and cost. At the same time, the Bank's July 2026 Financial Stability Report cautioned that testing does not show frontier models can yet conduct fully autonomous, reliable and undetected attacks against well-defended real-world targets. Both qualifications sit in the public record, and neither cancels the other out: the threat environment is judged to be moving quickly, but the authorities have not presented evidence that defended UK financial institutions have already been beaten by autonomous AI attacks.
Operational resilience, now running at AI speed
None of this changes the formal rulebook. The May 2026 joint statement says plainly that it is not intended to introduce new expectations; it consolidates and reinforces messages that already apply under the UK's existing operational-resilience framework. That framework, which took effect for FCA and PRA purposes from 31 March 2022, requires in-scope firms to identify their important business services, set impact tolerances, map dependencies, test against severe but plausible disruption scenarios, and remediate vulnerabilities. Firms had a transition deadline of 31 March 2025 to be able to remain within those impact tolerances. In observations published on 27 March 2026, the FCA said operational resilience remains an ongoing obligation after that deadline, and that it is engaging directly with firms where improvement is needed.
What the May statement adds is a specific lens on how that obligation applies when the threat is AI-enabled. It lists board and senior-management understanding, investment and resourcing, faster vulnerability remediation, third-party and supply-chain management, access controls, data protection, AI-enabled defence, and response and recovery as the areas firms should examine. For a UK bank or insurer, this plausibly means boards should be able to show they understand frontier-AI cyber risk specifically, that vulnerability-patching processes can keep pace with a much larger and faster flow of discovered weaknesses without introducing outages through rushed changes, and that incident response plans assume a faster-moving adversary. None of this is a new legal requirement; it is the same impact-tolerance and severe-but-plausible-scenario testing duty, applied to a harder scenario.
The shared-supplier problem
A faster threat also interacts with how concentrated UK financial services already are in a small number of technology providers. The Bank and FCA's 2024 survey of close to 120 financial firms, published 21 November 2024, found 75% of respondents were already using AI and a further 10% planned to within three years. Foundation models made up 17% of reported AI use cases, and third-party implementations had grown to around a third of use cases, up from 17% in the 2022 survey. The top three providers accounted for 73% of reported cloud providers, 44% of model providers and 33% of data providers among respondents.
That pattern of concentration is relevant to frontier-AI cyber risk because a vulnerability at a widely used model, cloud service or data provider can affect multiple firms at once, rather than staying contained to one. The Bank's April 2025 Financial Stability in Focus report on AI in the financial system set out exactly this channel: shared critical third parties and shared vulnerabilities can turn a weakness at one provider into correlated disruption across multiple institutions at once. This is a concentration and supply-chain risk that firms are already expected to manage under existing third-party and outsourcing rules, not a new category of obligation created by the frontier-AI statements.
Beyond access: controlling what the model can touch
Getting hold of a capable model is only part of the problem. In September 2026, the Bank published material from the FAISF on what it calls "harness engineering" — the tools, workflows, controls, data and operating environment that surround a frontier model in practice. The article argues that firms need to control what organisational information a model can access, and that using AI for cyber defence safely requires combining AI literacy with red-teaming, security architecture, software engineering and operational cyber expertise, rather than treating access to a powerful model as sufficient on its own. The same article is explicit, as the FAISF material generally is, that it does not constitute guidance or create a new supervisory expectation; it summarises industry discussion.
The practical implication for firms considering defensive AI tools is that giving a model broad system access to be useful for threat-hunting or patch triage can itself create a new high-privilege attack surface if permissions, data exposure, output validation and human sign-off are not designed carefully. That is a governance and engineering problem as much as a procurement one, and it sits squarely within the existing expectation that firms manage access controls and data protection as part of operational resilience.
What this does not mean
It is worth being precise about the limits of what has been announced. Court approved extra funding, but the amount, the recipients and the work programme were not published. The Bank said it is helping banks reach AI models, but the mechanism, the participating banks and the models involved were not disclosed. The May 2026 joint statement and the FAISF's own publications state directly that they introduce no new UK regulatory requirements. There is no public evidence of a grant scheme open to firms, no confirmed funding figure, and no indication that any particular AI model or provider has received a regulatory stamp of approval. Firms that use AI tools, defensive or otherwise, remain subject to the same operational-resilience, governance, outsourcing and cyber rules that applied before these announcements, and any product built on AI can still carry the ordinary risks of cost, service disruption or data loss that apply to any technology deployment.
What to watch next
The clearest gap in the public record is the number itself. Whether the Bank discloses the size or scope of the frontier-AI funding through its annual accounts, a further Court paper, or in response to a freedom of information request, is unclear. Readers with a direct interest should also watch for further FAISF publications, any consultation from the PRA or FCA on cyber and ICT risk management that references frontier AI specifically, and future Financial Policy Committee records, where the Bank has twice in 2026 flagged frontier-AI cyber risk as a standing concern. Official detail, when it comes, will sit on the Bank of England's and FCA's own publication pages rather than through any commercial intermediary.
Sources
- Minutes of the Meeting of the Court of Directors held on 16 July 2026 (opens in a new tab)
Bank of England · · Accessed
- The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience (opens in a new tab)
Bank of England, Financial Conduct Authority and HM Treasury · · Accessed
- Frontier AI Information Sharing Forum (FAISF) (opens in a new tab)
Bank of England · · Accessed
- Frontier AI: Harness engineering (opens in a new tab)
Bank of England · · Accessed
- Financial Policy Committee Record – July 2026 (opens in a new tab)
Bank of England · · Accessed
- Financial Stability Report - July 2026 (opens in a new tab)
Bank of England · · Accessed
- Financial Policy Committee Record – September 2026 (opens in a new tab)
Bank of England · · Accessed
- Financial Stability in Focus: Artificial intelligence in the financial system (opens in a new tab)
Bank of England · · Accessed
- Artificial intelligence in UK financial services - 2024 (opens in a new tab)
Bank of England and Financial Conduct Authority · · Accessed
- Operational resilience: insights and observations one year on (opens in a new tab)
Financial Conduct Authority · · Accessed
- PS6/21 Operational resilience: Impact tolerances for important business services (opens in a new tab)
Prudential Regulation Authority · · Accessed


