By This Hour Finance Desk

Bank of England Governor Andrew Bailey has publicly rejected an allegation that the central bank has inadequate cyber defences, using a letter to the Daily Mail to argue that the more pressing concern is the effect frontier artificial intelligence could have on the financial system and its customers.

The letter, published by the Bank on 23 July 2026, offers a rare public defence of the institution’s own preparedness while drawing a line around the information it will disclose. Bailey said the Bank could not describe its defences in detail for security reasons, but maintained that it has suitable investment, skills and capabilities and works closely with specialist partners, including the National Cyber Security Centre.

That combination of assurance and restraint is central to the letter. The Bank is seeking to answer a direct criticism of its internal protections without identifying systems, controls or operational practices that could themselves become useful to an attacker. Bailey’s broader message is that the risks associated with advanced AI are not confined to one public institution: they concern the resilience of banks and other supervised firms, the continuity of financial services and the exposure of customers to increasingly persuasive criminal scams.

Governor shifts attention from the Bank to system-wide exposure

Bailey acknowledged the seriousness of frontier AI in relation to cyber-attacks, rather than disputing the premise that the technology could alter the threat. His objection was directed at the allegation about the Bank’s own cyber maturity, which he described as wrong and unsupported. The letter does not set out the underlying allegation in detail, nor does it provide technical evidence that would enable an outside reader to assess the Bank’s defences independently.

Instead, the Governor framed the public-interest question more broadly. In the Bank’s account, frontier AI could reduce the effort or time needed to mount cyber-attacks, make the consequences of an outage more severe and help criminals produce more convincing scams. Those are risk assessments expressed by the Bank, not quantified forecasts of particular losses, incidents or market outcomes. The letter does not identify an imminent attack, a specific affected company, or a recent breach.

That distinction matters for financial firms and their customers. A threat can become more consequential even when no individual institution’s controls have been shown to fail. Faster or easier attacks could increase the operational pressure on detection and response teams. More disruptive outages could test firms’ ability to restore services. More credible fraud attempts could place customers at greater risk of deception. Bailey’s letter presents these as connected concerns, with resilience requiring both preventive measures and recovery capacity.

It also avoids presenting cyber security as a problem that can be solved solely at national level. Bailey said no country can isolate itself from the relevant risks. That position places cross-border coordination alongside domestic supervision, reflecting the Bank’s stated view that frontier AI and cyber risks have implications beyond any one institution or jurisdiction.

Testing, patching and recovery form the Bank’s stated approach

The letter says the Bank has spent several years warning firms to improve how they identify threats and react to them, to correct vulnerabilities more quickly and to retain the capacity to recover when an incident occurs. The sequence is important. Detection addresses the possibility that a harmful intrusion or attempted intrusion may be noticed. Response concerns the action taken once it is detected. Faster patching is intended to reduce the period in which known weaknesses may be exploitable. Recovery focuses on restoring operations when preventive controls have not been enough.

Bailey said banks are required to demonstrate such capabilities through stress testing and penetration testing. This is the Bank’s own description of its regulatory expectations and should be read as such. The published letter does not provide the design of those tests, identify participating firms, give individual results, or establish how each firm has performed. Nor does it explain whether the testing referred to covers every type of AI-related threat described in the letter.

Still, the statement makes clear that the Bank sees cyber resilience as more than an abstract objective. It says firms must be able to show the regulator that their arrangements work under testing. In a sector dependent on continuous access to payments, banking and other services, the ability to recover is presented as a core part of the supervisory concern, not an afterthought once an incident has occurred.

The Bank’s position is also notable for the balance it strikes between institution-level defences and sector-wide oversight. Bailey did not suggest that private firms bear responsibility alone, nor that the central bank can eliminate the risk on their behalf. His account describes a regulatory model in which supervised institutions strengthen their own controls and demonstrate them, while the Bank works with specialist domestic bodies and international counterparts.

Calls for model testing go beyond conventional cyber controls

Bailey linked the Bank’s supervisory work to its call for stronger international coordination around testing frontier AI models before they are deployed more widely. The letter does not specify what a common international testing framework would require, which models it would cover, who would carry it out, or how any resulting findings would be enforced. It nevertheless identifies model testing as part of the response, alongside the operational resilience measures expected of financial firms.

The logic presented in the letter is that the risk cannot be treated only after a tool is in broad use. If advanced systems can affect the speed, accessibility or sophistication of cyber-enabled harm, scrutiny before wider deployment may be relevant to financial-sector resilience. That is a policy position articulated by the Governor; the letter does not claim that a particular model has already caused a named financial disruption.

Within the United Kingdom, Bailey said the country is well positioned through the AI Security Institute and the National Cyber Security Centre. He said the Bank is working quickly with those bodies and with international partners to reinforce the cyber resilience of the banks and firms it supervises. The letter does not describe particular joint projects, deadlines, funding commitments or measurable outputs. Its significance lies in the stated direction of travel: coordination among the Bank, specialist cyber and AI bodies, and overseas counterparts is being treated as part of the response.

For markets, the letter supplies no current asset prices, company valuations, earnings figures or estimates, and it does not report a market reaction. It should therefore not be read as a trading signal or as a basis for an investment view. Its financial relevance is structural: it concerns operational risk in a regulated sector and the official approach to a technology that the Bank believes could alter that risk.

Public assurance leaves crucial evidence outside view

Publishing the letter was itself a deliberate choice. Bailey said the Bank was placing it in the public domain because of strong public interest and in the interests of transparency and accountability. Yet the stated need to protect security-sensitive details creates an unavoidable limit on what transparency can deliver here. Readers are asked to weigh an official assurance against an allegation that the Governor rejects, without access in the letter to the evidence that could fully resolve the dispute.

The Bank’s claims about its investment, expertise, capabilities and relationships with expert partners are material because they are the basis for Bailey’s rebuttal. But the publication contains no independent technical assessment, test result or outside validation of those claims. Likewise, while it says banks must prove relevant capabilities through stress and penetration testing, it does not disclose evidence showing how those requirements are applied in specific cases or the outcomes they produce.

The account does establish several bounded points: the Governor accepts that frontier AI may intensify cyber-related risks; the Bank says it has set resilience expectations for firms over a number of years; it says it uses stress testing and penetration testing in relation to those expectations; and it says it is coordinating with named UK bodies and international partners. It does not establish that the Bank’s own defences are adequate by an independently verifiable standard, that every supervised firm meets the stated expectations, or that the proposed coordination will prevent disruptions or scams.

The report has not been independently corroborated. It is based on the Bank of England’s published letter and attributes its assurances, supervisory descriptions and assessment of AI-related risks to the Bank and its Governor. The supplied material contains no independent evidence resolving the disagreement between Bailey’s rejection of the criticism and the underlying allegation about the sophistication of the Bank’s cyber defences.

What follows is likely to be judged less by the letter’s confidence than by the evidence institutions can safely make available over time: whether firms can detect and contain incidents, restore services after disruption and protect customers as criminal methods change. Bailey’s intervention sets out the Bank’s stated posture on those questions. It does not, on its own, provide a public audit of the safeguards on which that posture depends.

Sources