Economic and labor · Cybersecurity and infrastructure
Correlated financial fragility
Thousands of institutions deciding with the same models and the same data stop being thousands of independent decisions.
- Severity
- Severe
- Horizon
- 1–3 years
- Evidence
- Projected
- Consensus
- Medium
A market works in part because those taking part get things wrong in different ways. The risk here is not that a model fails, but that many institutions decide with the same model, the same data and the same provider, and stop being independent decisions.
The institutional map is unusually consistent. In November 2024 the Financial Stability Board named four vulnerabilities with systemic potential: third-party provider concentration, market correlation from the use of the same models and data, cyber risk from AI adoption by malicious actors, and model risk from opacity [430]The Financial Stability Implications of Artificial IntelligenceView source ↗. A year later it measured the concentration with Bank of England figures: 33% of use cases are implemented by third parties —17% in 2022— and the three main model providers account for 44% of the providers named, against 18% two years earlier [431]Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial SectorView source ↗. The mechanism is formulated by the BIS: institutions using the same algorithms could amplify procyclicality and volatility by exacerbating herding behaviour, liquidity hoarding, runs and fire sales [144]Artificial intelligence and the economy: implications for central banks (Annual Economic Report 2024, capítulo III)View source ↗. On 25 June 2026 the European Systemic Risk Board raised the register: not a report but a formal warning under Article 16, published in the Official Journal [381]Warning of the European Systemic Risk Board of 25 June 2026 on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)View source ↗.
What this does not demonstrate. None of the four vulnerabilities has shown up in a documented market episode: this is prudential surveillance, not a diagnosis of harm that has occurred. The Bank of England and FCA survey bounds the imminence: 75% of firms already use AI, but only 2% of use cases have fully autonomous decision-making [155]Artificial intelligence in UK financial services - 2024View source ↗. And the FSB itself states that it cannot properly measure what it is watching: it is up against the speed of change and the lack of data on AI use in the sector [430]The Financial Stability Implications of Artificial IntelligenceView source ↗ —which prevents both asserting the risk and ruling it out.
Chain of materialisation
PreconditionObserved
Third-party dependence is concentrated and measured
The FSB measured, using Bank of England figures, that 33% of AI use cases in UK financial services are implemented by third parties, up from 17% in 2022, and that the top three model providers account for 44% of named providers, against 18% two years earlier.
TriggerObserved
A regulator issues a formal warning, not a report
On 25 June 2026 the European Systemic Risk Board issued a warning under Article 16 of Regulation (EU) 1092/2010 on systemic cyber risks stemming from frontier AI models, published in the Official Journal. The mechanism it names is concrete: financial patching is reactive, and if the volume of discovered vulnerabilities rises, current practices may become insufficient.
Observed and demonstrated evidence ends here. What follows is projection.
CascadeProjected
The same models produce the same decisions at once
The BIS states the mechanism: the behaviour of financial institutions using the same algorithms could amplify procyclicality and market volatility by exacerbating herding, liquidity hoarding, runs and fire sales. It is an argument about correlation, and none of the FSB's four vulnerabilities has manifested in a documented market episode.
ImpactSpeculative
A stress episode with no diversity to absorb it
The FSB also declares the observation problem: authorities face the speed of AI change and the lack of data on AI usage in the financial sector. A risk the supervisor cannot measure also cannot be bounded from above.
Related measures
See on the map →Report a mistake in this entry →
Sources
- [430] The Financial Stability Implications of Artificial Intelligence · FSB 2024
- [431] Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector · FSB 2025
- [144] Artificial intelligence and the economy: implications for central banks (Annual Economic Report 2024, capítulo III) · BIS 2024
- [145] The AI supply chain (BIS Papers No 154) · BIS 2025
- [381] Warning of the European Systemic Risk Board of 25 June 2026 on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3) · ESRB 2026
- [380] Artificial intelligence and systemic risk (Advisory Scientific Committee Report No 16) · ESRB 2025
- [155] Artificial intelligence in UK financial services - 2024 · Bank of England / FCA 2024
- [1047] Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector · U.S. Treasury 2024
- [432] Financial Stability Oversight Council 2025 Annual Report · FSOC / U.S. Treasury 2025
- [121] The rise of artificial intelligence: benefits and risks for financial stability (Financial Stability Review, May 2024) · Banco Central Europeo 2024
- [288] TASRA: a Taxonomy and Analysis of Societal-Scale Risks from AI · Critch, Andrew 2023