On 31 August 2026, Bank of England governor Andrew Bailey wrote to G20 finance ministers in his capacity as chair of the Financial Stability Board, naming frontier AI's impact on cyber risk as the "most immediate concern" for the global financial system. His letter, addressed to finance ministers and central bank governors ahead of their meeting in Asheville, North Carolina, didn't stop at describing the technology as dangerous in the abstract. It named the specific mechanism: frontier models could "materially alter the speed, scale and economics of cyber risk," and that danger is compounded, he wrote, "especially due to highly concentrated third-party service providers."
Read past the headline framing about rogue models, and Bailey's actual argument is a familiar one to anyone working in open finance risk: a small number of providers now sit underneath a very large number of institutions, and a single point of failure in one of them can ripple outward faster than any one national regulator can see. As Bailey put it, "the risks associated with frontier AI will not respect national borders." He also named the governance gap directly: many jurisdictions, he wrote, simply don't have the protocols in place to manage how these models are developed, released and deployed, and financial institutions need to prepare for scenarios involving simultaneous disruption across multiple firms that share the same technology dependencies.
What makes this letter interesting from a UK vantage point is that Bailey's own regulators have already built a version of what he's asking the G20 to consider. On 13 July 2026, the Bank of England, the Prudential Regulation Authority and the FCA began direct oversight of the UK's first Critical Third Parties: Amazon Web Services, Google Cloud, Microsoft and Oracle, designated by HM Treasury on the basis that a failure in their services could threaten the stability of, or confidence in, the UK financial system. Oversight under the regime is limited to the resilience of the specific services these providers supply to UK financial firms, and designation is not the same as authorisation - but it is a live, functioning example of exactly the kind of concentrated third-party dependency Bailey is warning the G20 about, already under direct regulatory watch.
The regime, though, currently covers cloud infrastructure providers, not the frontier AI model providers Bailey's letter is actually about. A UK Parliament Treasury Committee report from January 2026 had already recommended that HM Treasury designate major AI and cloud providers as Critical Third Parties by the end of 2026, specifically to close this gap. As things stand, that recommendation hasn't yet been acted on for AI model providers themselves. Even the jurisdiction furthest ahead on this - the one whose central bank governor is now writing to the G20 about it - hasn't finished building the oversight its own Parliament called for.
There's a pattern worth calling out, and it's the same one we've pointed to in UK open banking: naming who's in scope is a political and administrative process, and it moves on its own clock. Treasury needed until July 2026 to designate four cloud providers under a regime that had been in force since January 2025. Extending that regime to frontier AI providers has been sitting as a formal recommendation since January 2026 and still isn't done.
That lag is the real risk, more than any single model's behaviour. Concentrated dependency doesn't wait for a designation order, and the institutions relying on a handful of providers - whether that's four cloud platforms or the frontier AI labs sitting underneath an ever-growing share of financial infrastructure - carry that exposure regardless of whether a regulator has formally named it yet. Standing, continuous risk monitoring across the dependencies an institution actually has, rather than only the ones a regulator has got round to designating, is what keeps pace with a risk that Bailey himself says won't wait for jurisdictions to catch up.
Cloud infrastructure isn't the only layer where this pattern is building. Look at the technology stack underneath a growing share of account-access relationships in open finance, and the same concentration is forming a level down: intermediaries, aggregators and third-party providers are increasingly built on a small number of frontier AI models - the agentic tools that read an account, flag a risk, or now, as we've covered on this blog before, act on an account directly, all sit on top of one of a handful of model providers. Those are the same providers Bailey's letter is actually about.
That's the fourth-party risk open finance now has to account for, one step beyond the third party a bank can see and name in a contract. If a frontier model has an exploitable flaw, or behaves in a way its own maker didn't anticipate - the kind of incident Bailey's letter cites directly - the exposure doesn't stay contained to a single AI vendor's relationship with a single TPP. It runs through every intermediary built on that same model, and every financial institution connected to them, simultaneously: the "shared technology dependencies" Bailey flags at the cloud layer, replicated one level further down the stack, underneath open finance itself.
This is exactly why AI governance sits alongside financial, operational and security risk as one of the four categories Invela's Risk Indicator monitors continuously. A model provider's status isn't something to check once at onboarding and leave alone. It needs the same standing, continuous visibility Bailey is asking the G20 to build at government level - applied at the point where frontier AI actually touches open finance: inside every intermediary and third-party provider built on top of it, not only at the cloud infrastructure sitting four companies deep in the stack.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Open finance, covered.
Learn more about the Invela Network.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.