For the better part of a decade, the financial industry has embraced a singular and seductive story about artificial intelligence: that it would make banking faster, cheaper, safer, and smarter. Boards cited it in annual reports. Chief executives invoked it at investor days. Consultants built entire practices around it. Now, the people whose job it is to prevent the next financial catastrophe are asking a fundamentally different and far more unsettling question — what if artificial intelligence becomes the biggest systemic risk the global banking system has faced since the financial crisis of 2008?

Critically, that question is not emerging from the fringes. It is not being raised by technophobes, by Luddite commentators, or by institutions that have simply failed to adapt. According to reporting by Chris Skinner in The Finanser, the warning is coming directly from financial regulators — the very authorities charged with maintaining systemic stability. When the supervisors of the system start using language borrowed from crisis-era risk assessments, the industry would be unwise to treat it as background noise.

The Gap Between Promise and Systemic Reality

The optimistic framing of AI in banking has always contained an implicit assumption: that the technology's benefits — automation, fraud detection, credit decisioning, customer personalisation — would be distributed gradually, transparently, and in ways that institutions and regulators could monitor and control. That assumption deserves rigorous scrutiny. The speed at which large language models, autonomous agents, and AI-driven trading systems are being embedded into core banking infrastructure has already begun to outpace the supervisory frameworks designed to govern them.

Consider what systemic risk actually means in a financial context. It is not the failure of a single institution, nor even the failure of several. It is the failure of interconnected systems in ways that amplify rather than absorb shocks — where the collapse of one node accelerates the collapse of others. The Bank for International Settlements and bodies such as the European Banking Authority have spent the years since 2008 building frameworks specifically designed to identify and quarantine these cascade risks. The concern now is that AI may be quietly constructing a new set of cascade vulnerabilities — ones that are harder to see, harder to model, and harder to reverse.

Concentration, Opacity, and the Herding Problem

Three structural features of how AI is actually deployed in banking make regulators particularly anxious. The first is concentration: a relatively small number of foundational AI models, supplied by an even smaller number of technology firms, are being licensed to a vast number of financial institutions simultaneously. If a flaw or a bias is embedded in a widely adopted model, the error does not remain confined — it propagates across the institutions that depend on it, potentially producing correlated failures at scale.

The second concern is opacity. Even where regulators can examine an institution's AI systems in principle, the internal logic of complex models remains genuinely difficult to audit. Explainability — the ability to trace why a system made a particular credit, risk, or trading decision — remains an unsolved problem across much of the industry. Supervisors cannot effectively stress-test what they cannot see.

The third issue is what risk theorists call herding. When multiple institutions use similar AI-driven models to make similar decisions — pulling back from the same asset classes, extending credit to the same segments, executing similar trades in response to the same signals — the diversification that is supposed to stabilise markets dissolves. AI, paradoxically, may be creating a more homogeneous financial system precisely at the moment when heterogeneity is most needed as a shock absorber.

A Regulatory Community Finding Its Voice

What is significant about the current moment is not that these risks are new in theory — academics and some practitioners have flagged them for years — but that they are now being articulated at the institutional level by regulators with enforcement authority. When supervisory bodies move from private concern to public warning, it typically signals that the issue has crossed a threshold from theoretical to operational. The language of "systemic risk since the global financial crisis" is not deployed casually by institutions that understand the weight such comparisons carry.

This represents a meaningful inflection point for the industry. Banks and financial technology firms that have treated AI governance as a compliance checkbox exercise, rather than as a genuine risk discipline, will find themselves increasingly exposed — both to regulatory action and to the underlying risks those frameworks are designed to address. Boards that have approved AI adoption strategies without equivalent investment in AI risk management now face a supervisory environment that is rapidly becoming less forgiving.

What This Means for the Industry

The industry's challenge is to close the gap between deployment velocity and governance maturity before regulators are forced to close it for them. That means investing seriously in model explainability, establishing genuine third-party auditing of AI systems embedded in critical banking functions, and engaging with supervisors as genuine partners in risk identification rather than as obstacles to be managed. It also means acknowledging, at the board level, that the same technology being marketed as a competitive advantage may simultaneously require treatment as a source of material operational and systemic risk.

The regulators have blinked. The question now is whether the industry will take that signal seriously enough to act before the next crisis makes the lesson unavoidable.

Written by the editorial team — independent journalism powered by Codego Press.