A quiet but consequential shift has taken place inside the world’s financial watchdogs over the past few months. What was once a forward-looking curiosity about artificial intelligence in banking and markets has hardened into something closer to alarm, with regulators across continents now describing advanced AI models not as a productivity tool but as a potential source of systemic risk to the global financial system.
The Financial Stability Board, the body that coordinates financial regulation for the G20, has been among the most direct. Bank of England Governor Andrew Bailey, in his capacity overseeing global financial stability discussions, has warned that rising leverage tied to the AI investment boom is a feature of a maturing and increasingly fragile financial cycle, one that can amplify market gains just as easily as it can deepen a downturn. The concern is no longer confined to portfolio-level exposure to AI stocks; it has taken on a macro-prudential dimension, with the FSB cautioning that a shock to AI valuations or infrastructure could ripple through the wider financial system rather than stay contained to a single sector.
In Europe, the warnings have sharpened around a different but related worry: cybersecurity. The European Systemic Risk Board and the Bank of England jointly flagged that so-called frontier AI models represent a paradigm shift for cyber defence, one that currently favours attackers more than defenders. In the short to medium term, the ESRB noted, these models make it easier for threat actors to find vulnerabilities and execute attacks at a speed and scale that outpaces the industry’s ability to respond, even as the same technology is expected to eventually strengthen resilience once defensive tools catch up. The European Central Bank has since written to the boards of over a hundred significant banks, giving them until the end of October to produce concrete plans for countering AI-driven cyber threats.
America’s regulators have taken a more operational tack. FINRA’s latest annual oversight report acknowledged that generative AI tools are proliferating across broker-dealer operations, and with that spread come sharper obligations around data quality, model bias, and the governance of AI-generated communications with clients. The message running through nearly every recent report, whether from Washington, Frankfurt or London, is the same: AI risk in finance is no longer optional to manage, even for institutions that have not yet deployed the technology themselves, because the risk increasingly sits at the level of the system rather than the individual firm.
India’s own central bank has arrived at a strikingly similar conclusion. The Reserve Bank of India’s Financial Stability Report, released in June, described India’s banking system as fundamentally resilient, with gross non-performing assets at a multi-decade low and healthy capital buffers across banks, NBFCs and insurers. Yet in the same breath, the RBI flagged AI-driven market concentration and AI-enabled cyberattacks as key emerging threats to stability, both globally and closer to home. A survey of Indian banks and NBFCs cited in the report found that AI-enabled cyberattacks are now seen as the single biggest risk facing the sector over the next year, ahead of more traditional concerns such as funding pressures or asset quality. The RBI also pointed to a subtler danger: AI investment enthusiasm has begun spilling beyond equity markets into bond markets, raising the possibility that a correction in AI valuations could transmit stress through fixed-income markets that many investors still consider comparatively safe.
What unites these otherwise disparate warnings is a shared anxiety about concentration. Whether the concern is a handful of dominant AI model providers whose outages or failures could cascade across many institutions at once, or the possibility that a large share of global capital has piled into a narrow set of AI-linked assets, regulators are converging on the idea that dependence on a small number of AI systems and companies creates a single point of failure for an entire financial ecosystem. It is a risk that does not fit neatly into the traditional playbooks built around individual bank failures or liquidity crunches, which is why bodies from the FSB to the RBI are now urging supervisors to develop entirely new macro-prudential tools rather than stretching existing ones to cover a technology that behaves differently from anything finance has regulated before.
For now, none of these institutions are predicting an imminent crisis. The RBI was explicit that India’s financial system remains stable and well capitalised, and European regulators frame their warnings as calls for preparedness rather than declarations of present danger. But the tone across every recent report suggests regulators believe they are racing against a clock: AI adoption in financial services is projected to reach roughly seventy per cent of institutions by the end of this year, and the consensus emerging from central banks and standard-setters alike is that the guardrails need to be built well before the technology’s next major test arrives, not after.