(Re)insurers and frontier AI: ensuring resilience
Key takeaways
- The beneficial transformative effects of AI are widely recognised. At the same time there are significant challenges.
- Following May 2026’s FCA, Bank of England, and HM Treasury Joint Statement, the FCA has published its findings on frontier AI and cyber resilience, and the Bank of England has published practical considerations in relation to frontier AI: harness engineering.
- Whilst there are no new rules, guidance, or regulatory expectations, cyber resilience should remain a major focus, in tandem with (re)insurers’ wider operational resilience framework.
Recap
The transformative potential of AI in financial services is widely recognised. For example, the Yonder/FCA consumer research which accompanied July 2026’s Mills Review found that reviewing insurance was the most attractive AI use case.
At the same time, the risks of frontier AI models (i.e. those at the absolute cutting edge) are rarely out of the news. Recognition of the risks is not new: the UK Government’s inaugural AI Safety Summit took place in November 2023, reflecting the international concern about frontier AI risk. What is new is the incredible pace of change and power of the current frontier AI models.
The UK regulators do not plan to introduce extra regulations for AI. Instead, they will rely on existing frameworks, which are principles-based and so can be applied to developing areas.
What should (re)insurers be doing?
In May 2026 the FCA, Bank of England, and Treasury Joint Statement noted, among many other things, that frontier AI models could out-perform experienced hackers, working faster, at greater scale and far more cheaply than a human. On 2 September 2026 the FCA published the findings of its review on firms’ engagement with Frontier AI, and the Bank of England published practical considerations in relation to frontier AI: harness engineering.
The papers impose no new regulatory rules, guidance, or obligations. However, they do indicate a strong regulatory steer. The papers state that frontier AI does not change what good cyber resilience looks like, but it raises the pace at which firms need to deliver it. The view of the regulators and the Treasury is that success turns on governance, organisational readiness, and the design of the environment around the AI model as much as on the AI model itself. Frontier AI risk, including cyber risk, forms part of regulated firms’ existing operational resilience obligations, with updated FCA and PRA rules coming into force from 18 March 2027 (our update here).
As an overview, the Joint Statement, the FCA’s September 2026 review, and the Bank of England’s harness engineering paper can be read together as covering five domains for action:
- Board-level governance and strategic oversight
The FCA’s September 2026 review found that frontier AI is proving to be as much a test of governance, risk ownership, and escalation routes as of technology. The FCA states that boards and senior management need to take clear ownership of AI-related cyber risk, folding it into existing governance and risk oversight structures rather than treating it as a standalone issue. The FCA’s view is that firms with clear accountability and escalation structures will be best placed to tackle frontier AI risks. - Investment to address outdated or unsupported technology
Firms need to invest where the risk is, tackling legacy or unsupported systems that are especially vulnerable to AI-driven attacks, and must check that their insurance cover keeps pace too. Both the FCA’s September 2026 review and the Bank of England’s harness engineering paper found that the benefit firms get from frontier AI is driven less by the model itself and more by the surrounding tooling, validation processes, and human oversight built around it. - Faster and more scalable identification and remediation of vulnerabilities
The FCA’s September 2026 review found that firms need to get quicker and smarter at spotting and fixing weaknesses, using automation to work faster and at a greater scale, while keeping a close eye on any new risks that automation itself might introduce. - Tighter control over third-party and supply chain risk
Firms should know what software, tools, and services their third-party suppliers are using, mapping these dependencies across their supply chain. They should hold their suppliers to the same resilience standards they set for themselves and be prepared to act fast when a supplier flags a vulnerability. The FCA’s review found firms increasingly putting this into practice by engaging suppliers directly on how they are using AI-enabled vulnerability discovery. - Stronger protection, response and recovery capability
Firms should look at automated, AI-powered, defences that can keep pace with AI-driven attacks, embedding controls (such as restricted access, environment segregation, monitoring, and approval workflows) directly into the AI harness itself. The Bank of England, PRA, and FCA’s October 2025 effective practices on cyber resilience offers guidance as to how firms can ensure that they respond and recover quickly from AI attacks. The effective practices paper points firms towards having immutable back-ups in place, tested bare metal recovery, and clear priorities for restoring the most critical data and systems first.
What’s next?
To quote BIS: “Frontier AI … does not fundamentally change the foundations of cyber resilience, but it significantly increases the speed and intensity with which established practices need to be executed.”
As a priority, (re)insurers should ensure that their operational resilience framework, third-party mapping, and senior management accountability structures adequately capture the risks and dependencies that frontier AI presents.
AI will remain a key regulatory focus, both domestically and supranationally (for example, through the FSB). And frontier AI will continue to evolve at pace. (Re)insurers should keep AI high on their risk and compliance radars.
Poppy Flury, Trainee Solicitor, assisted in the preparation of this briefing.