"Why the Bank of England Wants to Test AI Before It Regulates It"

"Why the Bank of England Wants to Test AI Before It Regulates It"

Andrew Bailey is not a technologist, and he'd probably be the first to say so. The Governor of the Bank of England spends his days thinking about interest rates, inflation, and the stability of the financial system — not about model architectures or alignment. So it was notable when, this week, he waded into the AI governance debate with a deliberately counterintuitive position: regulating artificial intelligence is "not the right place to start." Writing his first-ever article for Substack, Bailey argued that before anyone drafts rules for AI, they should subject it to rigorous testing to find vulnerabilities and build safeguards that contain risk. Coming from the man whose job is, in effect, to regulate financial stability, the statement carries unusual weight.

To understand why it matters, you have to know a bit about what a central bank governor actually does. Bailey chairs the Financial Policy Committee, the body responsible for spotting risks that could destabilize the UK's financial system before they become crises. That's a job defined by looking at things you can't fully predict. So when someone in that seat says "test first, regulate later," it isn't a shrug at oversight. It's a specific argument about sequencing from an institution that has spent decades figuring out how to supervise systems it doesn't fully control.

The core claim rests on a distinction between understanding and rulemaking. Testing is how you build understanding: you probe a system, find where it breaks, and design protections around what you actually observe. Regulation, by contrast, encodes what you already believe to be true. Write the rules before you've done the testing, and you risk legislating against imagined risks while missing the real ones. That's the crux of Bailey's argument, and it's more careful than a one-line headline suggests.

Here's the insight that's easy to miss: this is the stress-testing philosophy that central banks already apply to banks themselves. Every year regulators subject the largest financial institutions to hypothetical shocks — a deep recession, a market crash — to see whether they'd survive. Nobody writes capital rules before running those scenarios; the scenarios inform the rules. Bailey is essentially proposing to treat frontier AI the way his own institution treats a too-big-to-fail bank: probe it under stress, learn where it cracks, and only then codify the safeguards. It's a regulator arguing for the empirical method over the legislative one, which is a striking stance from someone whose profession is often caricatured as rule-writing.

There's also a subtler point about the shelf life of rules. Technology moves faster than the legislative calendar. A regulation written for the AI of 2026 may describe a system that no longer exists by 2028. Testing, by contrast, is always conducted against the current thing — the model as it actually behaves today, not as a draftsperson imagined it. In that sense "test first" is less a rejection of regulation than a demand that regulation stay evidence-based and keep pace with the technology it governs.

It's worth emphasizing what Bailey did not say. He was careful to reject both extremes, arguing that AI development should not be halted or prohibited — "on the contrary, the benefits are immense" — but that there must be "a system for intervention and to establish boundaries in which AI operates." That's a middle path that's easy to misread. It's neither accelerationist nor a precautionary pause. It accepts the technology as a net good while insisting that it run inside guardrails.

The vocabulary is telling. "Boundaries" and "intervention systems" are the language of financial oversight, not software engineering. A bank can operate freely within capital buffers and liquidity rules, but when it breaches a threshold, regulators step in. Bailey's framing suggests he wants something analogous for AI: let it run, define the edges, and keep a mechanism ready to intervene when a system crosses them. Governance as a circuit breaker rather than a straitjacket.

So why does the Bank of England care about AI at all? Because AI is already inside the financial system — in credit scoring, fraud detection, algorithmic trading, and increasingly in the back offices of banks and insurers. The Bank's own research has flagged risks like model concentration, where many firms lean on the same handful of foundation models, and the opacity of AI-driven decisions. That's the concrete worry hiding behind the abstract talk of "safeguards": a failure in a widely shared AI system could ripple through finance in ways a single institution's bad model never could.

The Substack detail is worth a note of its own. A central bank governor publishing on Substack is a small but real shift in how financial authorities communicate. It signals a recognition that the AI governance conversation is happening in public, at speed, among people who don't read speeches. Whatever you think of the argument itself, the venue is a deliberate attempt to meet the debate where it's actually taking place.

The honest caveat is important, and it's a point in Bailey's favor that the framing invites it. "Test first" is a sequencing argument, not a substitute for regulation — and in the wrong hands it can be abused. "We need more testing" can become an indefinite delay tactic, a way to defer hard rules forever. Bailey's version avoids that trap by pairing testing with an explicit commitment to boundaries and intervention. But the risk of the frame being borrowed by people who only want the "not yet" part is real and worth naming.

That tension sits inside a broader UK story. The country has been trying to position itself as a serious player in AI governance — hosting the first global AI Safety Summit at Bletchley Park in 2023 and standing up the AI Safety Institute to evaluate frontier models against safety criteria. Bailey's intervention fits that thread neatly: it's an argument that evaluation infrastructure — the testing — has to come before the statutory infrastructure, because good rules are downstream of good evidence. The NIST AI Risk Management Framework in the United States reaches a broadly similar conclusion, treating measurement and testing as the foundation that risk management and, eventually, regulation are built on.

Stepping back, the most useful way to read Bailey's remarks is not as a verdict on regulation but as a reminder of what regulation is for. Rules exist to constrain risk, and you can't constrain a risk you haven't yet located. Testing is how you locate it. If the governor of a central bank — a regulator by trade — thinks the testing has to come first, it's a signal that even the people who write the rules are betting the way to govern AI well is to understand it thoroughly first.

Comments

H
honestSkipper98October 1, 2026 · 9:39 pm

Testing before regulating is just voicing before you play — you don't rewrite Bach's counterpoint on a hunch. Bailey's instinct is sound; the harpsichord demands precision.

S
slowRoamer51October 2, 2026 · 3:08 am

@honestSkipper98 I dug a Roman denarius out of a field last month, worn smooth before anyone ever dated it. Bailey's just surveying the ground before he digs — that's decent archaeology.

G
grimVoltOctober 2, 2026 · 4:07 am

@honestSkipper98 Same principle in my trade — you bench-test before you energize. No inspector signs off on a hunch; that's how you get a ground fault.

G
grumpyPaddlerOctober 2, 2026 · 6:39 am

bruh regulating an ai you never playtested is like nerfing a whole class off patch notes. run the beta first fr

Leave a Comment