For years, the Bank of England's official line was straightforward: existing financial rules were sufficient to handle AI risks. That line has now been dropped.
On June 30, Deputy Governor Sarah Breeden told the European Central Bank's annual forum in Portugal that current frameworks were not designed for AI systems that act on their own, and that expecting humans to approve every decision these systems make is not practical at scale. It is a significant admission from an institution that had previously resisted calls to write new AI-specific rules.
The shift matters because of what is already happening inside financial firms. A 2026 Cambridge Centre for Alternative Finance survey found that 52% of financial services firms are already actively using agentic AI systems. These are not chatbots answering customer questions. These are systems that receive an objective, plan a sequence of steps, and carry them out, often without a human reviewing each action. They are being used in payments, fraud detection, back-office operations, and trading support.
The risk that regulators are now most focused on is not a single firm's AI system going wrong. It is the possibility that many firms, running systems built on similar models and trained on similar data, all respond the same way to the same market signal at the same time. Researchers call this "herding." In financial markets, synchronized behavior at scale can turn a manageable dip into a severe disruption. The Bank of England is now running simulation work with international partners specifically to understand how and when this could happen.
Breeden named cybersecurity as the Bank's most immediate concern. AI tools can help security teams find weaknesses faster, but the same capability in the hands of attackers means financial institutions could face more sophisticated, faster-moving threats. She noted that open-source AI models now trail the most advanced private models by only four to eight months, meaning powerful capabilities spread quickly and restrictions on releasing advanced models offer only a short window of protection.
The options now on the table are concrete. The Bank is considering market-wide circuit breakers or kill switches that could halt trading if AI-driven disruption reaches a certain threshold. It is also exploring whether one bank should be able to take over another bank's core functions during a crisis, and whether critical institutions should maintain separate backup systems that can be spun up quickly if their main systems are compromised.
The global regulatory picture is moving in the same direction. The Financial Stability Board, which coordinates financial regulation across major economies, published 12 draft practices for responsible AI use in finance on June 10. The FSB explicitly acknowledged that reviewing every individual decision made by an autonomous AI system is not achievable, and recommended that human oversight focus on setting boundaries and reviewing outcomes rather than approving each step. Final guidance is expected in October 2026.
For businesses that are not banks, this story has a practical dimension. Banks tightening their AI governance will pass compliance requirements down to the firms they serve. Businesses that use banking services, trade finance, payment processing, or insurance through major financial institutions should expect more detailed questions about how AI is being used in their own operations, particularly in any process that touches financial flows. Governance documentation that does not yet exist will become necessary sooner than many expect.