Author: Esther Chihaavi – 04/09/2026
Regulatory gaps in overseeing frontier LLM deployment in financial services
The article examines the regulatory challenges posed by the deployment of frontier large language models in financial services, focusing on cybersecurity risks, institutional vulnerabilities and the limits of current national and regional regulatory frameworks. It argues for greater sector-specific oversight and stronger international coordination to address the growing asymmetries created by advanced AI systems.
#Frontier AI; #Financial Regulation; #Cybersecurity; #Cybersecurity #Regulatory Governance
Technological advancement is at an all-time high, with advanced systems being deployed on the market sooner than many expected. It is only a couple of years back when cryptography was thought to be the perfect solution to addressing security of financial systems, both for centralized and decentralized finance. It is not in doubt that a large part of Decentralized finance is grounded on this aspect. However, we do see that as AI systems continue to advance, a threat is posed to these systems that were meant to provide secure and direct unmediated interactions between parties. One such threat is that posed by Frontier AI Models that have immensely high capabilities. This is not only a threat to both centralized and decentralized financial systems that depend on cryptography to secure their systems and reduce risks of unauthorized access.
A look back at the 2008 Financial Crisis exposes the critical position that financial institutions are in. The crisis brought to light the risk posed by instability in the financial system. In the EU, the European Central Bank intervened to rescue member states such as Greece from financial collapse.
The crisis further demonstrated the reliance placed on mediated transacting in the financial sector. It was in light of this that Decentralized Finance took center stage, allowing actors in the financial system to interact directly without intermediaries using blockchain technology. Infrastructure relating to both native and non-native assets, such as Ethereum, began to gain momentum. They allowed for a less regulated space, allowing actors to trade in a secure way in the absence of intermediaries. It is not to be forgotten that market-based regulation poses a risk to financial institutions.[1]
On the other hand, financial institutions have progressively placed reliance on AI to increase the effectiveness of service delivery, and to secure their systems against cybersecurity risks. A report by the Bank of England highlights that 75% of financial institutions placed reliance on AI, as of 2024.[2] It is inevitable that this number has only increased with the advancement of AI systems.
Financial institutions and systems have a central role in most, if not all, economies of the world. A nation’s economic stability largely leans on the stability of their financial systems. In the wake of the technological revolution, these systems face some risks. First, the security of financial systems is under threat in the presence of highly advanced systems that can exploit zero-day vulnerabilities. As it stands, encryption is one of the best defense against cyber security risks, as it renders data unreadable to those who are not the intended recipients. Frontier AI presents a double-edged sword, that is both of benefit in terms of Defending financial systems, but it also enables attackers to have an easier time seeking to compromise systems, and at a cheaper cost than the work of defending systems.[3]
At present, we see a fragmented approach to regulation on a global scale, noting that the risks posed by such systems are not limited to particular geographical areas therefore it behooves states to take a concerted effort to respond to these, and to oversee the deployment of these systems.
We take, for instance, the deployment of Anthropic’s Claude Mythos 5. As it stands, the US government restricted access to the model, later on restoring access to trusted partners.[4] However, this implies that the US can definitively decide on access to such a system, serving different jurisdictions. This ostensibly overrides the ability of financial regulators in different states to determine the viability of use of a frontier AI system prior to full market deployment.
Additionally, in the absence of the ability of different states to contribute to the discussion or decision of whether or not to deploy such systems, and not having the privilege of granting financial institutions first access to these systems to enable them further strengthen their systems, financial institutions are left exposed to a new kind of risk, with attackers maintaining a solid advantage.
Given the present landscape, it is crucial that the regulatory landscape take into consideration, having carried out an impact assessment, provisions requiring deployers of increasingly capable frontier systems to preliminarily disclose the risks posed by this systems with particular regard to financial systems. This will enable financial institutions prepare both technically and economically for the oncoming risks.
It is not in doubt that the EU has attempted to achieve this by way of the EU AI Act, that presents a categorization of risks, ranging from high risk to low risk systems.[5] However, the Act does not deal with different sectors, with the level of detail required to address the challenges posed by frontier AI and AI agents generally in specific sectors. It goes without saying that different sectors require laws fine tuned to address the particular challenges, some being weightier than others; in our case, the financial sector.
As such, it is necessary to approach regulation in this sector not only by national, or as in the particular case of the EU, regional law, but also by a concerted global effort, if we are to avoid an approach where a single state determines what counts as a risk and who should be entitled to access information related to this risk. Additionally, steps taken by states ought to take into consideration particular needs in different sectors and develop regulations appropriate and relevant to different sectors.
[1] Dirk A Zetzsche, Douglas W Arner and Ross P Buckley, ‘Decentralized Finance (DeFi)’ (2020) 6 Journal of Financial Regulation 172
[2] ‘Artificial Intelligence in UK Financial Services – 2024’ (24 July 2026) <https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024> accessed 4 August 2026.
[3] Iñaki Aldasoro and others, ‘A Mythos Moment? Frontier AI and Cyber Risk’ <https://www.bis.org/publ/bisbull129.htm> accessed 9 August 2026.
[4] David Shepardson, Chris Thomas and Chris Thomas, ‘US Allows Anthropic to Release Mythos AI to “trusted” US Organizations’ Reuters (26 June 2026) <https://www.reuters.com/technology/us-releases-anthropic-model-mythos-some-us-companies-semafor-reports-2026-06-26/> accessed 10 August 2026.
[5] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) 2024.

Esther is a lawyer qualified to practice in Kenya, and she is currently doing her Masters in Law and New Technologies at Roma Tre University. Her interests lie in Data Protection and Privacy, AI Governance, Fintech, and Digital Sovereignty & Digital Democracy, and she regularly publishes her thoughts on these areas.
Other Articles by Esther Chihaaavi:
