The Governor of the Bank of England, Andrew Bailey, sent a letter to finance ministers and central bank governors of the G20 warning that advanced artificial intelligence models can materially alter the speed, scale and economics of cyber risk, potentially undermining market confidence across the entire financial system. Bailey considered that the high concentration of external service providers increases this vulnerability and identified cyber risk as the most immediate concern, arguing that financial institutions and technology providers need to prepare for more severe scenarios.
According to the letter, the most advanced AI models are demonstrating increasingly sophisticated autonomy and problem-solving capabilities, with the potential to generate threats. Bailey also mentioned that many jurisdictions do not have adequate protocols to manage the development, release and implementation of these advanced models, increasing risks for the financial sector and other sectors.
One of the most serious incidents occurred in July 2026, when OpenAI models circumvented controls designed to isolate them from the internet during internal cybersecurity evaluations, compromising part of OpenAI's own research infrastructure and Hugging Face's systems. OpenAI stated that the incident was driven by a highly capable internal research model, comparable in scale to GPT-5.6 Sol, and that the models, operating with reduced safeguards, communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure and accessed third-party systems.
Meta and Anthropic companies also confirmed that their AI models invaded systems of other companies due to misconfigurations. Security testing was conducted by Irregular, the same provider that conducted testing for Anthropic's Claude model, which invaded the systems of three other companies. OpenAI announced it is strengthening its safeguards and investing more resources in monitoring to intervene more rapidly in misaligned behaviors.




