Edition 1 · 29 September 2026

AI Risk Reading

A short, selective list of new papers on AI risk that boards should know about, with a judgement on what is genuinely new and whether it is worth your time.

When machines attack: frontier AI cyber threats and policy responses in the financial sector

What is new

Frontier models can now find serious vulnerabilities and build working exploits on their own, cutting the skill, time and money a sophisticated attack needs. The paper sets out what that means for financial institutions: shorter windows to fix weaknesses, a higher chance of breach, and greater exposure through shared cloud, software and AI providers. Authorities are responding by tightening existing resilience frameworks rather than creating new AI-specific rules.

Why a board should care

If the time between a weakness being found and being exploited shrinks from weeks to days, decision rights and escalation routes built for the old pace may simply be too slow.

Verdict: read in full.

Question for the board

If our window to fix a critical weakness fell to days, which decisions would still need to reach us, and would they arrive in time?

Frontier AI and cyber resilience

What is new

The FCA reports what firms are actually finding: frontier AI identifies weaknesses faster than teams can validate and fix them, and it exposes gaps in vulnerability management, access controls and dependency mapping. These are observations from firms, not new rules, but they show where supervisors will look.

Why a board should care

The FCA treats frontier AI as a test of organisational resilience rather than a productivity tool, and asks directly who owns decisions about using it.

Verdict: read in full.

Question for the board

Who owns the decision to turn frontier AI on our own systems, and could we fix what it finds as fast as it finds it?

Scaling AI in finance: systemic risks, resilience and European sovereignty

What is new

EIOPA argues that Europe does not need another layer of AI regulation for finance, but rigorous use of the rules it has. Firms should map their material dependencies, test what happens if a provider or model fails, and confirm that exit plans actually work. It also makes a sharp point: swapping reliance on a few non-EU providers for reliance on a few EU ones would leave the concentration risk largely unchanged.

Why a board should care

Resilience comes from being able to substitute a provider, not from where the provider is based. That is a test boards can apply to their own AI dependencies.

Verdict: skim. It is short; read the section on sovereignty and resilience.

Question for the board

Have we tested whether our AI exit plan works, or only written it down?

This edition’s question

Are we taking on AI dependencies faster than we can test our way out of them?

All editions All writing Subscribe by RSS