# BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026): The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience

Source: https://www.bankingnewsai.com/ai-regulation/documents/uk-joint-statement-frontier-ai-cyber-resilience-2026
Last updated: Aug 26, 2026

On 15 May 2026 the Bank of England, FCA and HM Treasury jointly warned that frontier AI models' cyber capabilities already exceed what a skilled practitioner could achieve, at higher speed, scale and lower cost, and that regulated firms and FMIs must act under existing operational-resilience rules to plan for and mitigate the resulting threats. It sets expectations across governance and strategy, vulnerability identification and remediation at scale, third-party and open-source supply-chain risk, protection, detection and response, and says firms that have underinvested in cyber fundamentals will become progressively more exposed.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) |
| Type | Guidance |
| Status | In force |
| Published | May 15, 2026 |
| Effective | May 15, 2026 |
| Applies to | All PRA- and FCA-regulated firms and financial market infrastructures, under existing operational-resilience rules |
| Official text | https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience |

## Key points

- Published 15 May 2026 on both the Bank of England and FCA sites; addressed to regulated firms and FMIs.
- Boards and senior management must understand frontier AI risk; investment should reflect the threat, including end-of-life and unsupported systems, and insurance should be reviewed.
- Firms should triage, prioritise and remediate vulnerabilities more quickly, more frequently and at scale, using automation where appropriate.
- Third-party and supply-chain risk, including open-source software, must be identified, monitored and remediated at scale.
- Protection expectations: access management, network security and data protection to shrink the attack surface a frontier model could reach.
- Creates no new rule; it interprets existing operational-resilience and outsourcing expectations in light of frontier AI.
- Issued amid public debate about frontier models with advanced vulnerability-discovery capabilities.

## What changed for banks

It is the first UK financial-regulatory statement treating frontier AI as a cyber threat requiring immediate action rather than a technology to be monitored. Supervisors can now cite it when assessing whether a firm's cyber programme is adequate, so it functions as de facto guidance despite not changing the rulebook.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)

## FAQ

### Does the May 2026 frontier AI statement impose new requirements on UK banks?

No new rules, but it states that under existing operational-resilience rules firms must take active steps now on governance, vulnerability management, third-party risk, protection, detection and response against frontier AI-enabled attacks.

## Related documents

- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [HM Treasury Financial Services AI Adoption Plan (Jul 2026)](https://www.bankingnewsai.com/ai-regulation/documents/hmt-financial-services-ai-adoption-plan-2026) — Financial Services AI Adoption Plan (Jul 14, 2026)
- [2026 BoE/FCA AI survey](https://www.bankingnewsai.com/ai-regulation/documents/uk-ai-in-financial-services-survey-2026) — The Bank of England and FCA's 2026 AI Survey (Jun 5, 2026)
- [BoE response to Treasury Committee AI inquiry (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-response-tsc-ai-inquiry-2026) — Response to TSC inquiry report on AI in financial services (Apr 1, 2026)
- [BoE/PRA plan for safe AI innovation (Apr 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-pra-safe-ai-innovation-plan-letter-2026) — Letter from Sarah Breeden and Sam Woods to the Chancellor and Secretaries of State on enabling safe AI innovation (Apr 1, 2026)
- [DSIT/DBT strategic letters to regulators (Jan 2026)](https://www.bankingnewsai.com/ai-regulation/documents/gov-uk-dsit-dbt-safe-ai-innovation-letter-2026) — How will regulators enable safe AI-powered innovation: joint letter from DSIT Secretary of State and DBT Secretary of State (Jan 28, 2026)
- [PRA AI/ML model-risk roundtable (Nov 2025)](https://www.bankingnewsai.com/ai-regulation/documents/pra-mrm-roundtable-ai-ml-2025) — The PRA holds model risk management roundtable on artificial intelligence and machine learning technologies (Nov 24, 2025)

Last reviewed Aug 26, 2026. Cite the official text (https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/uk-joint-statement-frontier-ai-cyber-resilience-2026
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
