Skip to content

Product3 publishers3 min readPublished Updated

Bank of England governor warns AI boom could trigger market and cybersecurity shocks

Andrew Bailey says the Bank of England expects AI market shocks as AI-related debt issuance reaches about $450bn, more than double 2025's total. For teams buying AI tools, that puts a vendor's funding and its speed at patching flaws into the purchase decision next to price.

The Product Desk · Product desk

Photograph accompanying Bank of England governor warns AI boom could trigger market and cybersecurity shocks
Photo: thenextweb.com

What happened

  • Everybody in AI is currently priced to be a winner, Bailey told the BBC, but history shows not everybody is a winner.
  • The Bank's Financial Policy Committee warned that circular arrangements in some AI financing could amplify losses if expectations disappoint.
  • AI has created a much more powerful way of uncovering vulnerabilities in software, Bailey said.
  • Recent test incidents saw autonomous AI models take unexpected actions, including exploiting vulnerabilities, the committee said, urging firms to keep preparing.
  • Anthropic's prospectus shows the company lost $42bn in 2025, The Next Web reported.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision A customer on OpenAI's or Anthropic's current price list is relying on investors continuing to fund them, so vendor funding becomes a selection criterion next to features.
  • exposure If AI makes long-standing flaws in shared operating software easier to find, a vendor's time-to-patch sets how long its customers' systems stay reachable.
  • cost Keeping an exit open, with exportable data and a second provider wired in and tested, costs engineering time before launch, and the team pays it whether or not the vendor stumbles.
  • precedent With the Bank and the Financial Stability Board both ranking AI cyber risk high, I'd expect AI vendors selling to UK financial firms to face more questions about how their models are tested.

On Monday someone fills in the supplier-risk box on an AI rollout document and writes "low", because the vendor is big and the pilot users liked it. Every saved prompt and connected folder those users add after launch is one more thing to rebuild if that vendor later reprices or exits.

Teams tell themselves the vendor they picked will still be standing in a few years. Bailey gave the BBC a counter-example. "Google was not the first market leader in internet search. It was Netscape. Nobody can remember Netscape today. It doesn't exist. So not everybody always wins," he said [3].

His market warning is about prices. "You could see some correction of asset prices at some point," Bailey said [1]. The interview, as reported, does not name an AI company at risk, and a falling share price does not switch off an API. The borrowing is moving fast all the same. The $450bn of AI-related debt is a Morgan Stanley estimate cited by the Financial Policy Committee [5]. Because it is more than double the 2025 total, last year's issuance came in under $225bn [1]. AI hyperscalers made up 47% of sterling corporate bond issuance this year [6].

Two of the largest AI vendors are still raising money. Anthropic's 2025 loss sits beside OpenAI's search for $30bn at a $1.4tn valuation [14]. The BBC reported that both companies are preparing to sell shares on the US stock market [15].

The cyber risk reaches teams that never signed an AI contract. Of AI-powered vulnerability hunting, Bailey said: "It's revealing things that have been in bits of operating software that we've had, and all of us have had" [9]. "In the wrong hands... it's a very powerful, potentially very powerful, weapon," he said [10]. In August the Financial Stability Board named AI-driven cyber attacks the top risk to the financial system [12].

Bailey's prescription for frontier models, testing before rules, is also how a careful team buys them. He wrote that regulation is "not, in my view, the right place to start" [16]. He said testing will bring failures and "models will behave unexpectedly" [17]. "That is not evidence that testing has failed, rather it is evidence of why testing is necessary," he said [18].

The 2x2 for Monday has two axes. One is the time it would take to move the workload to another provider, measured in days or in quarters. The other is whether the vendor pays for its roadmap from revenue or from fresh outside money; its filings and funding rounds show which. Quick to move and self-funding: price and features decide it. Quick to move and funding-dependent: fine to buy, with a second provider kept tested. Slow to move and self-funding: the contract needs data export terms. Slow to move and funding-dependent is the Netscape box, where the exit plan belongs before signature. In all four, the cyber question is one number: days from a disclosed flaw to a shipped patch, as the vendor states it in writing.

What to watch

  • Pricing and contract terms from Anthropic and OpenAI once their US share sales go ahead, especially if public prices land below private valuations such as OpenAI's reported $1.4tn.
  • Whether the Financial Policy Committee's next record moves from warning about circular AI financing to specific measures for UK lenders.
  • Any UK standard built from AI Security Institute testing, which Bailey said should form part of a set of standards.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories