Bank of England gains power to regulate Amazon and Google cloud services from Monday

New rules mean the UK's central bank can directly oversee the tech companies that keep British banking running, cutting the risk of outages that could freeze millions of accounts.

AI2Day Newsdesk· 3 min read
A grand neoclassical stone building facade, the kind associated with central banking, photographed from a low angle looking upward, with dramatic overcast sky a
Share

Key points

  • From Monday, the Bank of England and the Financial Conduct Authority gain direct oversight of major cloud providers to UK banks.
  • Four large-scale cloud and tech firms, including Amazon and Google, fall under the new regime.
  • Regulators can now require these firms to prove their systems are resilient and actively guarded against cyber-attacks.
  • The rules aim to protect millions of UK consumers and businesses from outages that could freeze banking services.

British banking runs on cloud computing, the remote computer servers owned by technology giants that store data and run the software banks depend on every day. Until now, the Bank of England and the Financial Conduct Authority (FCA), the two main financial regulators in the UK, could only police the banks themselves. They had no direct grip on the tech firms underneath.

That changes on Monday.

The Bank of England and the FCA will take on what the government is calling oversight of "critical third parties": companies such as Amazon Web Services, Microsoft, Google Cloud, and Oracle, whose systems are so deeply woven into British finance that a serious failure could ripple across the entire economy. The Guardian first reported the move.

Think of it this way. If a cloud provider suffers a major outage, the bank using its services could go down with it. You might suddenly be unable to pay at a shop, access your savings, or complete a mortgage transfer. That is precisely the scenario these new powers are designed to prevent.

What does this actually mean for bank customers?

For most people, nothing changes overnight, and that is the point. The rules are designed to stop a crisis before it starts, not to respond to one already in progress.

Under the new framework, regulators can demand that cloud providers meet specific standards for resilience, meaning their systems must stay up and running even under stress. They can also require firms to show they are actively reducing the risk of cyber-attacks, the kind of targeted digital break-ins that can knock services offline or steal data.

If a tech firm fails to meet those standards, regulators now have the authority to act directly, without having to go through the bank first.

The four firms named as initial targets are among the biggest technology companies on the planet. Their services underpin not just banks but insurers, payment processors, and other financial firms across the UK.

Critics have long argued that concentrating so much of the financial system on a handful of private tech companies creates a single point of failure. One serious incident at one provider, and a large portion of UK banking could stall simultaneously.

Regulators have been watching this risk grow for years. Monday's move is their formal answer.

For customers, the practical message is straightforward: these rules exist to make sure your bank stays available. Regulators are betting that direct oversight of the cloud companies, not just the banks using them, is the surest way to deliver that.

© 2026 AI2Day