Form3

Payment insights · Blog

As attack becomes machine speed, defence has to become machine speed too

As AI accelerates the discovery and exploitation of vulnerabilities, critical infrastructure needs a defence that can keep pace. Discover how Form3’s Trust Fabric and Patch Pilot help deliver machine-speed remediation and cryptographic resilience for payments that cannot fail.

September 9, 20263 min read

The Bank of England’s biannual Financial Stability Report is usually read for its musings on credit, capital adequacy and the liquidity of UK banks. However, the July 2026 iteration stood out for a different reason - naming frontier AI itself as a driver of financial instability, specifically in terms of cyber and operational risks.

While the report is framed around financial stability, the risks it outlines aren’t unique to the finance industry. Any sector running critical infrastructure, whether that be in relation to healthcare, energy or telecoms, is now facing the same threat, wherein AI is now capable of discovering and exploiting vulnerabilities at record speeds and scales that manual intervention can’t keep up with.

Within payments, which cannot afford to fail and rely on continuous, always-on infrastructure, this poses a challenge. As the world of payments continues to evolve and the need for operations to function at greater speed and complexity increases, AI is playing a key role in helping banks and fintechs prepare for a world of continuous payments, digital assets and new forms of money.

However, while AI is a force that should be embraced responsibly in payments, it is also important to acknowledge that AI can have a downside.

As the Bank outlined, AI is now capable of discovering and exploiting vulnerabilities at record speeds and at greater scale. Crucially, this isn’t a one-party view. This month, the Financial Conduct Authority (FCA) published the results of its review into frontier AI, which echoed the sentiment that AI is accelerating vulnerability discovery faster than most remediation teams and tools can keep up.

The imperative for action is therefore clear. If vulnerabilities can be discovered and exploited at machine speed, then stopping these risks must happen at the same speed.

Recognising the dual role of AI as both the weapon and the defence, the Bank of England outlines the need for firms to use AI at its own game. When effectively harnessed, frontier AI and automation can triage, process and remediate vulnerabilities at even greater scale than before.

Connecting frontier AI, cyber risk and quantum readiness as risks that are all emerging at the same time, the Bank argues for financial institutions to identify and remediate vulnerabilities faster, increasingly through automation, while preparing their infrastructure for emerging risks such as quantum. In practical terms, firms need mapping of their systems, software, data and cryptographic dependencies now, and should start preparing for post-quantum cryptography now - rather than waiting for the risk to materialise and then responding after the fact.

This is exactly the world that Trust Fabric and Patch Pilot were built for.

The Form3 solution

To match the speed of modern threats, defence needs to be automated. In response, Trust Fabric is Form3’s cloud-native trust layer, designed to provide continuous discovery, validation and enforcement of certificates to eliminate blind spots and prevent failure. In essence, it is exactly the type of defensive model that the Bank of England calls for - capable of continuously identifying vulnerabilities, automating remediation and validating and implementing changes.

On the vulnerability side, Patch Pilot acts as an AI-driven engine which helps teams fight the vulnerabilities of frontier AI with frontier AI. Patch Pilot alerts teams to common vulnerabilities and exposures and then goes one step further to write, test, and deploy fixes.

Securing the cryptographic layer

While vulnerability risk spans the entire technology stack, one critical and often overlooked layer is cryptographic and certificate risk - expiring certificates, misconfigured TLS and hidden dependencies that can silently take down critical infrastructure.

In a world where infrastructure depends on encryption at every level and Transport Layer Security (TLS) is becoming universal, certificate volumes are increasing while their lifecycles are getting shorter, making manual oversight impractical and failure more likely.

In response, Trust Fabric continually discovers, validates, and enforces certificates to eliminate blind spots and prevent failure. By uniting software patching with cryptographic resilience this provides organisations with continuous system integrity, machine-speed remediation and cryptographic resilience from source code to network layer.

Written by

Gareth

Gareth Hobson

Sales Director, Trust Fabric