The warnings arose ahead of the release of GPT‑6 Astra, OpenAI’s latest AI model, on Thursday, which the company said, “with the right tools and access … can find previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step”.
On Wednesday, the UK’s Financial Conduct Authority (FCA) said that frontier AI – a term used to describe the capabilities of the very latest AI models under development – is “changing the speed, scale and manner in which vulnerabilities can be discovered and may need to be addressed” and “exposing existing cyber- and operational resilience weaknesses”.
The FCA’s alert follows that raised by Australian regulators last week in which they highlighted how vulnerabilities that might have taken cybersecurity experts months to find can now be identified and exploited in minutes owing to the capabilities of frontier AI.
Sandwiched between those publications was a warning from Bank of England governor Andrew Bailey (3-page / 100KB PDF) of the risk frontier AI poses to financial stability. Writing to other central bank governors and finance ministers of G20 countries in his capacity as chair of the Financial Stability Board (FSB), Bailey cited the speed at which the latest AI tools could be used to exploit vulnerabilities and cause disruption across the “highly interconnected” global financial system and raised concern that “many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models”.
Bailey called on financial institutions, financial market infrastructures, and technology providers “to strengthen vulnerability management, response and recovery capabilities, and prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies”.
“These developments reinforce the importance of robust response and recovery capabilities, including the ability to restore critical systems and data from ‘bare metal’ following a significant cyber incident, as well as the importance of resilience amongst critical third-party technology providers and other common service providers, on which the financial system depends,” Bailey said.
In a separate open letter published on 27 August, more than 100 other organisations, including OpenAI, Google, Anthropic and Microsoft, warned that “status quo security won’t be enough” to mitigate cyber attacks enabled by the latest AI models. Among other recommendations, they called on businesses to “make cyber defence an immediate leadership priority” and use frontier AI tools to enhance their own cybersecurity. However, they said there is just “a limited window” in which to act.
“Raise your security standards and meet them with the urgency and coordination of an incident that takes precedence over everything except critical business operations,” the companies said. “Fix the highest-risk weaknesses, verify results without disrupting essential services, and raise the security bar for what you buy, build, and deploy, including AI-generated code. Upgrade or replace systems to build in least privilege, strong access controls, and defence in depth. Use capable, lower-cost models for broad coverage, and apply frontier capabilities to the hardest problems. Where a system cannot be patched without disrupting essential services, apply and verify compensating controls.”
Recent disclosures, made by OpenAI, Anthropic and the UK’s AI Security Institute in the context of cybersecurity testing highlighted how AI agents can act in ways that are unprompted to solve problems and adapt to barriers in the way of them performing tasks they have been set. In one example, an AI agent deployed deceptive practices in an attempt to achieve its objective, creating fake online identities with a view to persuading a person to approve malicious code it tried to insert.
In relation to its release of GPT‑6 Astra, OpenAI said it has “significantly strengthened” its protections “against the model taking harmful cyber actions, whether that’s due to misuse or misalignment”. It has separately announced plans to provide organisations with subsidised access to its “frontier cyber capabilities” to help them defend against AI-led cyber attacks.
Earlier this summer, the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA) and European Securities and Markets Authority (ESMA) suggested “risk mitigation strategies and actions” for financial firms to adopt to address frontier AI risk.