Edition 1 · 29 September 2026
AI Risk Reading
A short, selective list of new papers on AI risk that boards should know about, with a judgement on what is genuinely new and whether it is worth your time.
Bank for International Settlements
Financial Stability Institute, Occasional Paper 28
9 September 2026
The essential read
What is new
Frontier models can now find serious vulnerabilities and build working exploits on their own, cutting the skill, time and money a sophisticated attack needs. The paper sets out what that means for financial institutions: shorter windows to fix weaknesses, a higher chance of breach, and greater exposure through shared cloud, software and AI providers. Authorities are responding by tightening existing resilience frameworks rather than creating new AI-specific rules.
Why a board should care
If the time between a weakness being found and being exploited shrinks from weeks to days, decision rights and escalation routes built for the old pace may simply be too slow.
Verdict: read in full.
Question for the boardIf our window to fix a critical weakness fell to days, which decisions would still need to reach us, and would they arrive in time?
Financial Conduct Authority
Multi-firm review
2 September 2026
What is new
The FCA reports what firms are actually finding: frontier AI identifies weaknesses faster than teams can validate and fix them, and it exposes gaps in vulnerability management, access controls and dependency mapping. These are observations from firms, not new rules, but they show where supervisors will look.
Why a board should care
The FCA treats frontier AI as a test of organisational resilience rather than a productivity tool, and asks directly who owns decisions about using it.
Verdict: read in full.
Question for the boardWho owns the decision to turn frontier AI on our own systems, and could we fix what it finds as fast as it finds it?
EIOPA
Eurofi magazine article
16 September 2026
What is new
EIOPA argues that Europe does not need another layer of AI regulation for finance, but rigorous use of the rules it has. Firms should map their material dependencies, test what happens if a provider or model fails, and confirm that exit plans actually work. It also makes a sharp point: swapping reliance on a few non-EU providers for reliance on a few EU ones would leave the concentration risk largely unchanged.
Why a board should care
Resilience comes from being able to substitute a provider, not from where the provider is based. That is a test boards can apply to their own AI dependencies.
Verdict: skim. It is short; read the section on sovereignty and resilience.
Question for the boardHave we tested whether our AI exit plan works, or only written it down?
This edition’s question
Are we taking on AI dependencies faster than we can test our way out of them?