KESHO PARTNERS
Financial-services operations team monitoring technology and cyber resilience

Financial services

Frontier AI and cyber resilience for financial services

How regulated firms can prepare their governance, vulnerability operations, suppliers, and board reporting for faster AI-enabled cyber discovery.

By Kesho Partners

14 minute read

Financial-services firms should treat frontier AI as a stress test of cyber and operational resilience, not simply a new security tool. The priority is the harness around the model: asset and dependency context, restricted permissions, expert validation, risk-based prioritization, remediation capacity, change controls, supplier coordination, and board visibility. The FCA's September 2026 review introduces no new rules. Separately, PS26/2 creates operational-incident and material third-party reporting requirements from 18 March 2027 for firms within scope.

Separate FCA observations from binding rules

The FCA published its frontier AI and cyber resilience multi-firm review on 2 September 2026. It summarizes observations reported by firms and expressly states that it does not introduce new rules, guidance, or regulatory expectations. Firms should use it as a current view of emerging operational practice, not mislabel it as a new legal obligation.

PS26/2 is different. Published in March 2026, it establishes final FCA rules and guidance for operational-incident and material third-party reporting. The regime applies from 18 March 2027 to the firms specified in the policy statement. Scope differs between incident reporting and third-party reporting, so firms need a legal-entity assessment.

Current FCA position
PublicationStatusOperational implication
Frontier AI and cyber resilienceMulti-firm observations; no new rules or expectationsUse findings to challenge cyber and operational readiness
PS26/2 operational incident reportingFinal rules applying 18 March 2027 to stated scopeImplement thresholds, data, workflow and standardized submission process
PS26/2 material third-party reportingFinal rules applying 18 March 2027 to stated scopeNotify material arrangements and maintain the required register

Sources: [1], [2]

The bottleneck moves from discovery to response

The FCA reports that frontier AI is accelerating vulnerability identification, validation, and prioritization faster than some firms can respond. More findings do not create resilience when validation, ownership, remediation, testing, and change implementation remain constrained.

This changes the risk question. Firms must test how a continuous increase in findings affects people, engineering queues, emergency change, evidence of closure, supplier coordination, and the continued delivery of important business services.

Sources: [1]

Engineer the harness around the model

The FCA uses harness engineering to describe the environment, controls, and processes around a model that make outputs useful, safe, and reliable. Firms told the FCA that value depends less on the model alone than on technical and organizational context.

For vulnerability work, the harness should connect model output to assets, dependencies, important business services, existing controls, exposure, exploitability, validation evidence, remediation ownership, and change constraints. It should restrict permissions and sensitive access, require approval for higher-risk actions, and retain complete traces.

Frontier AI cyber harness
LayerRequired capabilityEvidence
ContextMap code, assets, owners, dependencies and important servicesCurrent asset and service dependency records
AccessUse least privilege, isolation and approval for consequential actionsIdentity, permissions and approval logs
ValidationDistinguish plausible output from reproducible exploitabilityExpert validation and reproducibility record
PrioritizationCombine exploitability, chainability, exposure, controls and service impactRisk-ranked remediation decision
RemediationAssign ownership, capacity, testing, change route and closure evidenceTicket, patch test, approval and closure proof
OversightEscalate material findings and monitor capacity and residual riskOperational dashboard and governance decisions

Sources: [1]

Run a vulnerability-volume stress test

A controlled stress test should increase plausible and validated findings without exposing production systems to uncontrolled action. The objective is to locate the first constraint in validation, triage, engineering, patch testing, supplier response, change approval, and closure evidence.

Model the service impact of remediation as well as the impact of the vulnerability. Accelerated change can itself create outages, regressions, or control failures. The exercise should preserve normal incident, operational resilience, and change-management authority.

Vulnerability-volume stress-test design
StageTestMeasure
BaselineRecord current arrival, validation and closure flowQueue age, throughput, lead time and rework
2x inflowDouble candidate findings by affected service and supplierFirst breached service level and team constraint
5x inflowSustain higher volume with mixed exploitabilityBacklog growth, expert capacity and prioritization quality
Critical chainInject a multi-vulnerability path affecting an important serviceEscalation, decision and containment time
Supplier dependencyAdd a material finding requiring third-party actionNotification, evidence, workaround and remediation time
Accelerated changeRun emergency remediation while protecting service continuityFailure, rollback and impact-tolerance performance

Prioritize attack paths, not isolated severity scores

The FCA reports that frontier models can connect multiple lower-rated weaknesses into alternative paths to compromise. Traditional severity ratings remain useful, but firms need service and attack-path context to make proportionate decisions.

Remediation decision record
FactorQuestion
ExploitabilityCan the finding be reproduced under realistic access and prerequisites?
ExposureWhich users, networks, identities and interfaces can reach it?
ChainabilityCan it combine with other weaknesses to change the attack path?
Business serviceWhich important service and impact tolerance could be affected?
Compensating controlsWhich preventive, detective and recovery controls reduce current risk?
Change riskCan remediation be tested and deployed without creating disproportionate disruption?
DependencyDoes resolution require a supplier, shared platform or coordinated sector response?

Sources: [1]

Fix foundational visibility before scaling the model

Frontier AI can expose weaknesses in asset mapping, access management, dependency mapping, risk ownership, and remediation. A firm that cannot connect a finding to an owner and important business service will produce faster uncertainty, not faster resilience.

Use targeted deployments to test organizational readiness. The FCA reports that some firms use bounded use cases to identify constraints in post-discovery validation, remediation ownership, change absorption, and the ability to distinguish theoretical weaknesses from credible exploitation.

Assets
Current software, infrastructure, identity, data, cloud and end-of-life components.
Dependencies
Technology and supplier chains supporting important business services.
Ownership
Named risk, service, asset, remediation and change decision owners.
Capacity
Available specialist validation, engineering, testing and change throughput.
Recovery
Fallback, rollback, workaround and service-continuity options.

Sources: [1]

Test supplier preparedness and concentration

The Bank of England and FCA's 2024 survey found that one third of reported AI use cases were third-party implementations. The top three providers represented 73% of named cloud providers, 44% of model providers, and 33% of data providers. The survey also found critical third-party dependency was expected to be the fastest-growing systemic AI risk.

Ask key suppliers how they use AI-enabled vulnerability discovery, validate and prioritize findings, notify customers, handle accelerated patch volumes, coordinate shared dependencies, and preserve evidence. Assess what happens when several suppliers and internal teams face the same vulnerability wave.

Supplier frontier-AI evidence request
AreaEvidence request
DiscoveryScope, tools, validation method and model limitations
NotificationMateriality criteria, customer route, timing and information supplied
RemediationOwnership, capacity, patch testing, emergency change and closure evidence
DependenciesAffected subprocessors, shared services, software supply chain and concentration
ResilienceFallback, rollback, service continuity and coordinated exercise results
ReportingSupport for regulated-firm incident and material third-party data requirements

Sources: [1], [3]

Prepare PS26/2 data and decisions before March 2027

PS26/2 defines operational incidents and reporting thresholds, introduces a standardized reporting process, and provides standard and enhanced reporting routes. For material third-party arrangements, it requires firms within scope to notify the FCA of new arrangements and significant changes, maintain a register, and submit it annually.

Do not build the reporting process only around cyber tooling. Connect operational resilience, incident management, third-party inventory, legal entities, business services, materiality decisions, regulatory reporting, and governance. Use the FCA's policy statement, finalised guidance, and templates as the authoritative implementation sources.

Scope
Confirm which legal entities and permissions fall within each reporting regime.
Threshold
Translate regulatory definitions and thresholds into a documented decision workflow.
Data
Map required fields to systems, owners, timestamps, services, customers and third parties.
Submission
Assign preparation, challenge, approval, submission, correction and evidence retention.
Exercise
Test a frontier-AI-related cyber incident and a material supplier event before 18 March 2027.

Sources: [2]

Give the board a capacity and service view

The FCA observes that senior leaders may need clearer visibility of how frontier AI affects remediation capacity, operational resilience, risk, and the continued delivery of important business services. Reporting should show whether the firm's response system can absorb discovery volume, not celebrate the number of findings produced.

Board frontier-AI cyber dashboard
MeasureBoard question
Validated inflow and backlogIs discovery outpacing validation and remediation?
Time by stageWhere do validation, ownership, engineering, testing or change stall?
Important-service exposureWhich services and impact tolerances face credible paths?
Supplier dependencyWhich unresolved risks require third-party action or sector coordination?
Change and recovery riskCan urgent remediation proceed without destabilizing services?
Control performanceAre model permissions, approvals, validation, logging and shutdown effective?
Regulatory readinessCan the firm make accurate PS26/2 decisions and submissions by March 2027?

A 90-day resilience programme

Keep experimentation bounded until the firm can show that findings are valid, access is controlled, remediation can keep pace, important services remain protected, and incidents can be contained and reported. Model capability should expand only with demonstrated operating capacity.

First 90 days
PeriodActionOutput
Days 1-20Confirm owners, use cases, important services, assets, suppliers and current reporting scopeFrontier-AI exposure and accountability map
Days 21-40Define harness controls, validation method, prioritization and operating metricsApproved control and evidence model
Days 41-60Run targeted model evaluations and the vulnerability-volume stress testCapacity constraints and remediation actions
Days 61-75Exercise supplier coordination, urgent change, shutdown and service recoveryTest results and corrective actions
Days 76-90Rehearse PS26/2 decisions and approve board reportingRegulatory readiness and investment decision

Related service

Financial-services AI and cyber resilience

Kesho helps regulated firms test frontier-AI operating models, strengthen vulnerability and supplier processes, build board evidence, and prepare reporting workflows.

Explore the service