Andrew Bailey spent his August letter to G20 finance ministers telling them exactly what to worry about, then handed them nothing they can actually do about it. As chair of the Financial Stability Board, Bailey warned that frontier AI models are showing “increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities,” and that cyber risk is “the most immediate concern” arising from that shift. He is right about the risk. He is not offering a remedy proportionate to it, and regulators who read his letter as a call to action rather than a description of a gap should be worried about the gap, not reassured by the letter.
What Bailey actually said
The specific warning is worth taking seriously on its own terms. Bailey wrote that “frontier AI may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers.” That is a precise claim: a small number of cloud and AI vendors now sit underneath a large share of the financial system’s technology stack, and a frontier model compromised or misused at one of those vendors could propagate faster and further than a conventional breach. Bailey also flagged the cross-border nature of the problem directly, writing that “AI will not respect national borders,” and conceded the regulatory gap head on: “many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond.”
The counter-argument, stated fairly
The case for Bailey’s approach is that the FSB was never built to regulate anything directly. It is a coordinating body that makes recommendations to national authorities, who retain the actual rulemaking power, and its own history, the post-2008 push toward Basel III capital rules, shows that FSB soft-law warnings can precede binding national and international rules by years. Moving too fast on frontier AI, before anyone understands the failure modes well enough to write specific rules, risks writing bad rules that lock in the wrong assumptions, or drives frontier AI development further into jurisdictions with weaker oversight rather than better behavior inside regulated markets. On that view, a letter that names the risk and calls on jurisdictions to “take appropriate steps to support safe and responsible model release and deployment as a priority” is exactly the right amount of institutional humility for a body several steps removed from any actual model deployment decision. It is also consistent with how the UK Treasury itself has been handing the Bank of England open-ended mandates rather than prescriptive deadlines on other fast-moving technology questions, on the theory that the regulator closest to the risk should set the pace.
Why that is not enough here
That argument works for risks that develop slowly enough for soft law to catch up before real damage happens. Bailey’s own letter argues this one will not. If frontier AI can alter “the speed, scale and economics of cyber risk” and concentration among third party providers is already a named vulnerability, the FSB is describing a risk whose defining feature is that it moves faster than the multi-year process by which FSB recommendations typically become national law. A recommendation to “take appropriate steps” carries no deadline, no minimum protocol, and no consequence for a jurisdiction that does nothing, which is precisely the outcome Bailey’s letter says is already happening in “many jurisdictions.” Naming a fast-moving, cross-border risk and then routing the response through the slowest, most nationally fragmented layer of financial regulation is not caution, it is a mismatch between the diagnosis and the prescription.
The FSB is not entirely without options here even within its coordinating mandate. It could set a concrete timeline for member jurisdictions to report what frontier-AI protocols they actually have in place, the same way it uses peer review to track Basel implementation gaps today, which would at least convert Bailey’s warning into a measurable baseline rather than a one-time letter. The FSB has signaled it is “looking at what steps it can take, within its mandate and expertise,” language that leaves room for exactly that kind of tracking mechanism. Absent a deadline attached to it, the September G20 finance ministers’ meeting risks becoming the moment regulators agreed the risk was real and then moved on, the same pattern this publication flagged when the US Treasury’s quantum computing task force was announced without one.
Financial institutions should not wait for that timeline to appear before doing their own work. The concentration risk Bailey named, a small number of AI and cloud vendors underneath a large share of the sector’s infrastructure, is something a bank’s own third-party risk function can map today, deadline or not.
Source: Financial Stability Board
