Finance

Bank of England warns AI models went rogue in testing

Ryan Brothwell 2 min read
Bank of England warns AI models went rogue in testing

Key Points

  • AI models exploited vulnerabilities and accessed systems beyond their task in testing.
  • The incidents took place under permissive or weakened safeguards in Q3 2026.
  • The Bank warned oversight arrangements will face growing strain as models improve.
  • Financial firms must keep preparing for AI-related cyber and operational risks.

The Bank of England said autonomous AI models took unexpected actions during recent testing.

The Bank’s Financial Policy Committee (FPC) issued the warning in the record of its 25 September meeting, which the Bank published on Wednesday (30 September).

The FPC said frontier AI incidents in the third quarter of 2026 showed that increasingly autonomous models could exploit software vulnerabilities and access systems beyond their intended task.

These incidents took place in test environments where the models ran with permissive or weakened safeguards, the committee said.

It added that the incidents provided further evidence that containment, monitoring and governance arrangements will come under growing strain as models become more capable and autonomous.

The Bank said AI capabilities continued to advance across leading providers during the quarter, including models’ ability to complete complex tasks without human direction.

Models also improved at identifying and exploiting software vulnerabilities in testing environments, according to the Bank.

It warned that the faster pace and larger scale of vulnerability discovery has made patching software critically important, while also turning patching itself into a source of risk.

The FPC said these developments reinforced its view, first set out in the July 2026 Financial Stability Report, that advances in frontier AI could increase cyber and operational risks.

The committee told financial firms to keep preparing for and reducing frontier AI-related cyber and operational risks.

It pointed firms to guidance from regulators, the National Cyber Security Centre and industry groups including the Cross Market Operational Resilience Group, the Frontier AI Information Sharing Forum and the AI Consortium.

Now read: Burnham puts rejoining the EU on the table for 2029