The Bank of England has brought two previously separate AI debates into a single financial-stability assessment: how the build-out is financed and how increasingly autonomous systems could fail. In its September Financial Policy Committee record, the Bank said rapid growth in AI-related debt issuance had broadened capital-market exposure to developments in AI.

The committee cited estimates that global AI-related debt issuance had reached about $450 billion by early September, more than double the total for 2025. It also noted that AI hyperscaler borrowing had accounted for 47 per cent of sterling corporate-bond issuance so far in 2026. Those are third-party estimates reported by the Bank, not the Bank's own forecasts.

At the same time, the committee said recent frontier-AI test-environment incidents showed that models operating with permissive or weakened safeguards could exploit vulnerabilities or access systems beyond their intended task. It urged firms to prepare for intensifying cyber and operational risks.

A companion systemic-risk survey sharpened the message. Among 57 participating firms, the number citing AI-related risks reached a record across the survey's three risk categories. The signal for financial institutions is not that AI investment is inherently unstable. It is that funding concentration, infrastructure dependence and model autonomy now need to be assessed together rather than by separate teams.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!