
George Osborne, the former UK chancellor who now leads OpenAI for Countries, has added another voice to the growing warning that artificial intelligence is becoming both a cyber risk and a cyber defence tool. In a Financial Times letter published today, Osborne argued that governments, financial institutions, cybersecurity firms and AI labs must act together rather than treat the problem as separate private-sector headaches.
His argument builds on recent concerns from Bank of England governor Andrew Bailey and the UK Financial Conduct Authority. The FT previously reported that AI tools can spot cybersecurity vulnerabilities in financial firms faster than those firms can fix them, creating a dangerous bottleneck between discovery and remediation.
That is the key point. AI does not only make cyberattacks faster. It also makes vulnerability discovery faster. A bank, insurer, exchange or payment company may suddenly find thousands of weaknesses that need triage, repair and verification. If engineering teams cannot keep up, the organisation becomes more aware of its risk without necessarily becoming safer.
Osborne says AI should be used not only to detect weaknesses but also to prioritise, repair and verify fixes. That sounds sensible, but it also raises the central contradiction of the moment: the same class of models that may help secure financial systems can also be misused to attack them. That concern sits behind the coming US-China AI safety talks and the wider debate over AI-enabled cyber threats.
The timing is awkward for OpenAI. The company has been dealing with questions about rogue-agent incidents, disclosure and model control, including the German wiki episode . At the same time, OpenAI wants to position itself as a serious partner for governments and critical infrastructure. Those two realities now sit side by side.
For financial firms, the message is blunt. Buying AI tools will not solve a cyber resilience problem by itself. A firm still needs engineering capacity, incident response, access controls, governance, testing and executives who understand that a vulnerability report is only useful if someone can act on it quickly.
This is why the conversation has moved beyond ordinary cybersecurity. If advanced AI systems can scan, plan, exploit and explain at speed, then finance, energy, water, telecoms and government systems all need stronger defences. As AI models become more complex , human oversight must become more deliberate, not more casual.
Osborne’s letter is partly a call for cooperation, but it is also a signal of OpenAI’s strategy. The company wants to be seen not just as a model builder but as a national infrastructure partner. That may be useful if handled transparently. It may also raise questions about how much influence private AI labs should have over public-sector cyber defence.
The practical lesson is clear. AI will not wait for institutions to modernise slowly. If it can expose weaknesses faster than firms can repair them, then cyber resilience becomes a race between discovery, prioritisation and action. The winners will not be the organisations with the longest vulnerability list. They will be the ones that can fix the right problems first.







