Inside the Bank of England's AI Warning to Finance
The central bank sees a crowded AI trade, murky debt and sharper cyber threats converging — and wants regulation rebuilt for autonomous agents.
The Brief
In its latest half-yearly stability review, the Bank of England flags AI as a growing risk to the financial system on three fronts: stretched, concentrated equity valuations that could correct sharply if AI earnings disappoint; a fast-expanding pile of opaque, leveraged debt behind the AI build-out; and frontier models that make large-scale cyberattacks easier. With these vulnerabilities increasingly likely to hit at once, Deputy Governor Sarah Breeden is calling for a bespoke regulatory framework built for autonomous, agentic AI.
Banks have never been early adopters by temperament. Faced with each new wave of technology, established financial institutions have tended to move deliberately, weighing systemic safety above speed. The Bank of England's newest assessment of risks to the UK financial system suggests that instinct is well placed: as investors pour capital into the bet that AI will pay off, the central bank argues the technology is becoming a genuine threat to financial stability — and, at the same time, leaving banks more exposed to cyberattacks.
The half-yearly review makes clear that the dangers identified in earlier reports haven't faded. Elevated share prices, heavy public borrowing and risky private credit extended to businesses all remain on the watchlist. What's changed is the arrival of fresh pressures layered on top: the possibility of a stock market bubble, sharper cybersecurity exposure, and increasingly tangled, hard-to-read debt at AI companies. Crucially, the Bank judges that the odds of several of these vulnerabilities crystallising together have risen — and that overlapping shocks could magnify each other's impact on the system.
Stretched valuations and the correction scenario
The core problem is that today's AI valuations rest on tomorrow's earnings — and those forecasts are deeply uncertain. For the market's wager to come good, the Bank says, AI has to be adopted profitably at scale, the supporting infrastructure has to get built, and the sector needs continued easy access to finance.
In the meantime, a handful of technology names have driven much of the market's rise. Companies such as chipmaker NVIDIA have seen their shares surge on AI investment and demand, leaving valuations more stretched and pushing concentration in some global indices to uncomfortable levels. That narrowness is the vulnerability: if investor sentiment towards these firms turns, the resulting fall in equity prices could be amplified by that same concentration, by crowded momentum-driven positions that deepen volatility on the way down, and by elevated leverage across the market.
The Bank's Financial Policy Committee is openly sceptical about the economic case underpinning it all, questioning both the scale and the timing of any productivity dividend and noting it remains unproven that firms can reliably monetise AI applications. The committee doesn't dismiss the technology — it acknowledges AI could lift productivity across many sectors and support long-run growth, and has already contributed to growth in some regions. The doubt is about whether the payoff arrives on the schedule the market has priced in.
The debt behind the build-out is getting harder to read
Beneath the equity story sits a borrowing story. Corporate debt at tech infrastructure providers has expanded rapidly, funding a pace of investment the Bank describes as historically unprecedented — and the structure of that borrowing is becoming more complex and less transparent.
The leverage is stacking up on both sides of the trade. AI-related companies are borrowing heavily to fund their expansion, while investors — hedge funds among them — are borrowing to buy the shares. The Bank's concern is that this opacity could turn a bad situation worse: in a crisis, limited visibility into how these entities are financed makes stress harder to trace and contain. And the sustainability of the debt loops back to the same uncertain earnings question — if AI revenues undershoot expectations, servicing those obligations could become untenable.
For now, the committee's verdict on the system itself is reassuring. The FPC, whose job is to ensure the UK financial system can absorb economic shocks, concluded that it has remained resilient and continues to support the wider economy.
Frontier models are changing the cyber threat
The second front is operational. Regulators worldwide are paying closer attention to what advanced AI can do in the wrong hands — from risks tied to frontier systems such as Anthropic's Mythos to the challenges raised by autonomous agents acting without supervision.
Progress at the cutting edge since the Bank's previous stability report last December has been rapid enough to shift its assessment: advanced models are now increasingly capable of mounting cyberattacks at far greater scale, and that represents a material step-up in risk to financial stability. The Bank wants firms and authorities to re-examine whether the resilience of critical technology providers is still adequate.
Interestingly, the report doesn't assume the attackers win. The Bank concedes it's genuinely unclear whether better AI ultimately favours those attacking financial systems or those defending them. What it does expect is a practical consequence either way: financial firms will need to ship software updates more often — and frequent updating carries its own risk of operational disruption.
The case for regulation built around agents
The rise of autonomous systems has pushed senior central bankers towards a blunt conclusion: the existing rulebook wasn't written for this. Deputy Governor Sarah Breeden has signalled the need for bespoke AI regulation to contain the risks posed by increasingly capable agentic systems.
Her argument is that the traditional supervisory toolkit was designed around human decision-makers, not digital workflows that run without a person watching. Today's frameworks, she says, are poorly equipped to oversee tools that act independently.
Regulation was never designed with autonomous agents in mind — and expecting a human to sign off on every action an agent takes simply isn't realistic. — Sarah Breeden, BoE Deputy Governor, on why supervision must be rebuilt
As financial institutions fold autonomous systems deeper into their operations, the Bank's message is that purpose-built frameworks won't be optional. They will be the mechanism for containing the overlapping risks — market, credit and cyber — that this report lays side by side.
Key takeaways
- Risks are converging, not queuing. The BoE's central worry is that stretched valuations, opaque debt and cyber threats are now more likely to crystallise together, amplifying each other's impact.
- The AI trade is dangerously narrow. Index concentration around a few tech names means a sentiment shift could trigger a correction deepened by leverage and momentum positioning.
- Watch the debt, not just the equity. AI infrastructure borrowing is growing at an unprecedented pace with structures too opaque to trace easily in a crisis.
- Frontier AI raises the cyber stakes. Advanced models can now scale attacks, and it's an open question whether AI helps defenders or attackers more — but more frequent patching, with its own disruption risk, is certain.
- Agentic AI needs its own rulebook. Sarah Breeden argues human-in-the-loop oversight won't scale, making bespoke regulatory frameworks for autonomous systems essential.
