Frontier AI is finding flaws faster than firms can fix them
The FCA's review of frontier AI and cyber resilience creates no new rules. It does quietly break one of the oldest habits in IT security: patching by severity score.
On 2 September, the FCA published the findings of a multi-firm review into how frontier AI models are changing cyber resilience, governance and vulnerability management. It followed a joint statement in May from the FCA, the Bank of England and HM Treasury describing frontier AI as a step-change in capability with significant implications for operational resilience.
The FCA is careful to say the publication creates no new rules, guidance or expectations. Firms should read it anyway. Regulators publish observations like these when they've seen something they expect to come back to.
What firms told the regulator
The core finding is uncomfortable: frontier AI is accelerating the discovery of vulnerabilities faster than firms can fix them. The constraint isn't tooling. Firms reported that organisational readiness is the main challenge, and that governance, human oversight and solid cyber hygiene remain essential even as more of the work becomes automated.
The FCA also noted that governance forums, risk committees and senior leaders may need clearer sight of how frontier AI affects vulnerability registers, remediation, supplier dependencies and operational resilience. In other words, this is a board conversation, not just a security operations one.
The finding that matters most: chaining
Buried in the review is the observation I'd put in front of every CISO. Frontier models can combine several lower-rated flaws into a working route to compromise. Security people call this vulnerability chaining. It isn't new, but it has traditionally taken skilled people and time. If firms' own models can now do it quickly, it's reasonable to assume attackers' models can too.
That undermines a near-universal practice. Most remediation policies set deadlines by severity score: critical in days, high in weeks, medium and low “when convenient”. The medium and low backlog is where chains are built from. A register of hundreds of individually unremarkable flaws is, to an AI-assisted attacker, a parts bin.
Prioritise by path, not by score
The fix isn't to patch everything immediately, which no firm can do. It's to change what drives priority. Start from the business, not the scanner: which important business services must not fail, which systems support them, and which routes lead from the outside world to those systems. A medium-rated flaw on the path to a payments platform matters more than a high-rated one on an isolated test box.
Firms already have most of what they need for this. Operational resilience work has mapped important business services and their dependencies. Few have connected that map to the vulnerability register. Doing so turns remediation from a queue sorted by a generic score into a list sorted by exposure to the things the board actually cares about.
Suppliers are part of the attack surface
The review's mention of supplier dependencies is pointed. In July, HM Treasury designated the four largest cloud providers (AWS, Google Cloud, Microsoft and Oracle) as Critical Third Parties, bringing them under direct oversight by the Bank of England, PRA and FCA. Designation doesn't move responsibility away from firms, which still own their third-party risk.
If a frontier model can find a chain through your estate, it can find one through a supplier's. The questions to ask suppliers are changing accordingly: not just “are you patched?” but “how quickly can you remediate when discovery speeds up, and how will you tell us?”
What I'd take to the board
Three things. A one-page view of how long it currently takes to remediate by severity, and how much of the backlog sits on paths to important business services. A decision on whether remediation priority should be driven by exposure path rather than score alone. And a named owner for keeping that view current, because the speed of discovery is not going to slow down.
Is your vulnerability backlog a parts bin?
A short conversation on connecting your resilience mapping to your remediation priorities.