
Financial services
Frontier AI and cyber resilience for financial services
How regulated firms can prepare their governance, vulnerability operations, suppliers, and board reporting for faster AI-enabled cyber discovery.
By Kesho Partners
14 minute read
Financial-services firms should treat frontier AI as a stress test of cyber and operational resilience, not simply a new security tool. The priority is the harness around the model: asset and dependency context, restricted permissions, expert validation, risk-based prioritization, remediation capacity, change controls, supplier coordination, and board visibility. The FCA's September 2026 review introduces no new rules. Separately, PS26/2 creates operational-incident and material third-party reporting requirements from 18 March 2027 for firms within scope.
Separate FCA observations from binding rules
The FCA published its frontier AI and cyber resilience multi-firm review on 2 September 2026. It summarizes observations reported by firms and expressly states that it does not introduce new rules, guidance, or regulatory expectations. Firms should use it as a current view of emerging operational practice, not mislabel it as a new legal obligation.
PS26/2 is different. Published in March 2026, it establishes final FCA rules and guidance for operational-incident and material third-party reporting. The regime applies from 18 March 2027 to the firms specified in the policy statement. Scope differs between incident reporting and third-party reporting, so firms need a legal-entity assessment.
| Publication | Status | Operational implication |
|---|---|---|
| Frontier AI and cyber resilience | Multi-firm observations; no new rules or expectations | Use findings to challenge cyber and operational readiness |
| PS26/2 operational incident reporting | Final rules applying 18 March 2027 to stated scope | Implement thresholds, data, workflow and standardized submission process |
| PS26/2 material third-party reporting | Final rules applying 18 March 2027 to stated scope | Notify material arrangements and maintain the required register |
The bottleneck moves from discovery to response
The FCA reports that frontier AI is accelerating vulnerability identification, validation, and prioritization faster than some firms can respond. More findings do not create resilience when validation, ownership, remediation, testing, and change implementation remain constrained.
This changes the risk question. Firms must test how a continuous increase in findings affects people, engineering queues, emergency change, evidence of closure, supplier coordination, and the continued delivery of important business services.
Sources: [1]
Engineer the harness around the model
The FCA uses harness engineering to describe the environment, controls, and processes around a model that make outputs useful, safe, and reliable. Firms told the FCA that value depends less on the model alone than on technical and organizational context.
For vulnerability work, the harness should connect model output to assets, dependencies, important business services, existing controls, exposure, exploitability, validation evidence, remediation ownership, and change constraints. It should restrict permissions and sensitive access, require approval for higher-risk actions, and retain complete traces.
| Layer | Required capability | Evidence |
|---|---|---|
| Context | Map code, assets, owners, dependencies and important services | Current asset and service dependency records |
| Access | Use least privilege, isolation and approval for consequential actions | Identity, permissions and approval logs |
| Validation | Distinguish plausible output from reproducible exploitability | Expert validation and reproducibility record |
| Prioritization | Combine exploitability, chainability, exposure, controls and service impact | Risk-ranked remediation decision |
| Remediation | Assign ownership, capacity, testing, change route and closure evidence | Ticket, patch test, approval and closure proof |
| Oversight | Escalate material findings and monitor capacity and residual risk | Operational dashboard and governance decisions |
Sources: [1]
Run a vulnerability-volume stress test
A controlled stress test should increase plausible and validated findings without exposing production systems to uncontrolled action. The objective is to locate the first constraint in validation, triage, engineering, patch testing, supplier response, change approval, and closure evidence.
Model the service impact of remediation as well as the impact of the vulnerability. Accelerated change can itself create outages, regressions, or control failures. The exercise should preserve normal incident, operational resilience, and change-management authority.
| Stage | Test | Measure |
|---|---|---|
| Baseline | Record current arrival, validation and closure flow | Queue age, throughput, lead time and rework |
| 2x inflow | Double candidate findings by affected service and supplier | First breached service level and team constraint |
| 5x inflow | Sustain higher volume with mixed exploitability | Backlog growth, expert capacity and prioritization quality |
| Critical chain | Inject a multi-vulnerability path affecting an important service | Escalation, decision and containment time |
| Supplier dependency | Add a material finding requiring third-party action | Notification, evidence, workaround and remediation time |
| Accelerated change | Run emergency remediation while protecting service continuity | Failure, rollback and impact-tolerance performance |
Prioritize attack paths, not isolated severity scores
The FCA reports that frontier models can connect multiple lower-rated weaknesses into alternative paths to compromise. Traditional severity ratings remain useful, but firms need service and attack-path context to make proportionate decisions.
| Factor | Question |
|---|---|
| Exploitability | Can the finding be reproduced under realistic access and prerequisites? |
| Exposure | Which users, networks, identities and interfaces can reach it? |
| Chainability | Can it combine with other weaknesses to change the attack path? |
| Business service | Which important service and impact tolerance could be affected? |
| Compensating controls | Which preventive, detective and recovery controls reduce current risk? |
| Change risk | Can remediation be tested and deployed without creating disproportionate disruption? |
| Dependency | Does resolution require a supplier, shared platform or coordinated sector response? |
Sources: [1]
Fix foundational visibility before scaling the model
Frontier AI can expose weaknesses in asset mapping, access management, dependency mapping, risk ownership, and remediation. A firm that cannot connect a finding to an owner and important business service will produce faster uncertainty, not faster resilience.
Use targeted deployments to test organizational readiness. The FCA reports that some firms use bounded use cases to identify constraints in post-discovery validation, remediation ownership, change absorption, and the ability to distinguish theoretical weaknesses from credible exploitation.
- Assets
- Current software, infrastructure, identity, data, cloud and end-of-life components.
- Dependencies
- Technology and supplier chains supporting important business services.
- Ownership
- Named risk, service, asset, remediation and change decision owners.
- Capacity
- Available specialist validation, engineering, testing and change throughput.
- Recovery
- Fallback, rollback, workaround and service-continuity options.
Sources: [1]
Test supplier preparedness and concentration
The Bank of England and FCA's 2024 survey found that one third of reported AI use cases were third-party implementations. The top three providers represented 73% of named cloud providers, 44% of model providers, and 33% of data providers. The survey also found critical third-party dependency was expected to be the fastest-growing systemic AI risk.
Ask key suppliers how they use AI-enabled vulnerability discovery, validate and prioritize findings, notify customers, handle accelerated patch volumes, coordinate shared dependencies, and preserve evidence. Assess what happens when several suppliers and internal teams face the same vulnerability wave.
| Area | Evidence request |
|---|---|
| Discovery | Scope, tools, validation method and model limitations |
| Notification | Materiality criteria, customer route, timing and information supplied |
| Remediation | Ownership, capacity, patch testing, emergency change and closure evidence |
| Dependencies | Affected subprocessors, shared services, software supply chain and concentration |
| Resilience | Fallback, rollback, service continuity and coordinated exercise results |
| Reporting | Support for regulated-firm incident and material third-party data requirements |
Prepare PS26/2 data and decisions before March 2027
PS26/2 defines operational incidents and reporting thresholds, introduces a standardized reporting process, and provides standard and enhanced reporting routes. For material third-party arrangements, it requires firms within scope to notify the FCA of new arrangements and significant changes, maintain a register, and submit it annually.
Do not build the reporting process only around cyber tooling. Connect operational resilience, incident management, third-party inventory, legal entities, business services, materiality decisions, regulatory reporting, and governance. Use the FCA's policy statement, finalised guidance, and templates as the authoritative implementation sources.
- Scope
- Confirm which legal entities and permissions fall within each reporting regime.
- Threshold
- Translate regulatory definitions and thresholds into a documented decision workflow.
- Data
- Map required fields to systems, owners, timestamps, services, customers and third parties.
- Submission
- Assign preparation, challenge, approval, submission, correction and evidence retention.
- Exercise
- Test a frontier-AI-related cyber incident and a material supplier event before 18 March 2027.
Sources: [2]
Give the board a capacity and service view
The FCA observes that senior leaders may need clearer visibility of how frontier AI affects remediation capacity, operational resilience, risk, and the continued delivery of important business services. Reporting should show whether the firm's response system can absorb discovery volume, not celebrate the number of findings produced.
| Measure | Board question |
|---|---|
| Validated inflow and backlog | Is discovery outpacing validation and remediation? |
| Time by stage | Where do validation, ownership, engineering, testing or change stall? |
| Important-service exposure | Which services and impact tolerances face credible paths? |
| Supplier dependency | Which unresolved risks require third-party action or sector coordination? |
| Change and recovery risk | Can urgent remediation proceed without destabilizing services? |
| Control performance | Are model permissions, approvals, validation, logging and shutdown effective? |
| Regulatory readiness | Can the firm make accurate PS26/2 decisions and submissions by March 2027? |
A 90-day resilience programme
Keep experimentation bounded until the firm can show that findings are valid, access is controlled, remediation can keep pace, important services remain protected, and incidents can be contained and reported. Model capability should expand only with demonstrated operating capacity.
| Period | Action | Output |
|---|---|---|
| Days 1-20 | Confirm owners, use cases, important services, assets, suppliers and current reporting scope | Frontier-AI exposure and accountability map |
| Days 21-40 | Define harness controls, validation method, prioritization and operating metrics | Approved control and evidence model |
| Days 41-60 | Run targeted model evaluations and the vulnerability-volume stress test | Capacity constraints and remediation actions |
| Days 61-75 | Exercise supplier coordination, urgent change, shutdown and service recovery | Test results and corrective actions |
| Days 76-90 | Rehearse PS26/2 decisions and approve board reporting | Regulatory readiness and investment decision |
Related service
Financial-services AI and cyber resilience
Kesho helps regulated firms test frontier-AI operating models, strengthen vulnerability and supplier processes, build board evidence, and prepare reporting workflows.
Explore the service