AI Is Now a Financial Stability Problem
Today the Financial Stability Board told G20 finance ministers that the most immediate AI concern for the financial system is what frontier models do to cyber risk, especially given how concentrated its technology suppliers have become. The unit of risk has changed.
Artificial intelligence crossed a regulatory boundary yesterday, and the boundary is easy to miss because the language stayed calm. Financial Stability Board Chair Andrew Bailey wrote to G20 finance ministers and central bank governors ahead of their meetings on August 31 and September 1, and among the sovereign debt fragilities, the private credit vulnerabilities and the stretched asset valuations, he put this: "For the financial system, the most immediate concern is the potential impact of frontier AI on cyber risk."
Read that again with attention to who is speaking. Bailey chairs the body the G20 stood up in 2009 to watch for the things that turn one institution's bad day into everyone's bad decade, and that body has now placed frontier AI on its list. The letter describes frontier models as "showing increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities," and warns that frontier AI "may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers."
G20 Finance Ministers and Central Bank Governors meeting at the International Monetary Fund, Washington, DC, 2011. U.S. Department of the Treasury. Public domain.
Two phrases carry the argument. "System-wide" is not "could cause losses at exposed firms" and not "could disrupt operations." It is the vocabulary of financial stability, applied to a class of software. The qualifier at the end is the easiest part of the sentence to read past: especially due to highly concentrated third-party service providers. The FSB is not warning that AI makes attackers better in the abstract. It is warning that AI makes attackers better against a financial system that has quietly arranged itself around a small number of shared technology suppliers.
The sentence that moves the problem
AI governance has spent most of a decade asking questions about objects. Is the model accurate? Is it biased? Can it explain itself? Does the institution deploying it have a validation process, a model risk committee, a human in the loop? Those belong to model risk management, and they are asked one model and one firm at a time. Financial stability regulation asks something else, and it does not care much about individual quality. It asks what happens when a manageable failure propagates. A bank failing is not a stability event. A bank failing in a way that makes depositors doubt 12 other banks is.
Putting frontier AI into that frame is the shift. The FSB is no longer only asking whether financial firms use AI responsibly. It is asking what the system looks like when a large number of firms depend on capabilities, vendors and infrastructure that are broadly similar, and when the tools available to attackers improve at least as fast as the tools available to defenders. Bailey's claim is not that a crisis is coming. It is that the speed, scale and economics of an old risk are changing, which is a more careful and more interesting thing to say.
Four documents, 2 years
Yesterday's letter is not a stray remark. In November 2024 the FSB published "The Financial Stability Implications of Artificial Intelligence," an assessment naming third-party dependencies, market correlations, cyber risk and model governance as the channels worth watching. In October 2025 it followed with "Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector," the less glamorous and more consequential document, because it tried to specify what supervisors should actually measure: direct and proxy indicators of adoption, taxonomies aligned closely enough across jurisdictions to allow comparison, the criticality and substitutability of third-party AI services, and the concentration of widely used models. Its summary of the state of play is blunt: financial authorities' monitoring efforts, it says, are still at an early stage.
On June 10, 2026 the FSB moved from measurement to expectations, publishing "Sound Practices for Responsible Adoption of Artificial Intelligence" for consultation. It proposes 12 practices covering organisation-wide AI governance and the stages of the AI lifecycle, a wider frame than the model validation function where most AI oversight has lived. The consultation closed on July 22, and the responses published on August 6 came from JPMorgan Chase, UBS, Mastercard, the London Stock Exchange Group, Deutsche Börse, the Institute of International Finance, the American Bankers Association and Insurance Europe among many others. A final report is expected in the coming months.
Then the letter. Assessment, monitoring, practices, and now a stability warning to the G20. The machinery has been turning for 2 years, and what changed yesterday is the register.
What the letter does not say
The August 31 letter does not use "agentic AI" as its organizing term, and it does not declare autonomous agents a systemic risk. Its vocabulary is frontier AI and its named mechanism is cyber. Anyone writing that the FSB has identified agentic trading as a threat to financial stability is reporting a headline that has not been published.
What the FSB has done is narrower and still significant. Its June consultation explicitly asks whether the 12 practices "strike an appropriate balance between managing risks relating to all forms of AI, and addressing some of the risks relating to emerging and new complex forms of AI, such as GenAI and agentic AI." That is a regulator admitting, in a formal consultation question, that it is not certain its own framework covers systems that act. Less than 3 months later the chair tells the G20 that frontier models are demonstrating increasingly sophisticated autonomy, and that this bears on stability. The 2 documents sit next to each other without needing to be welded together. Autonomy is the property doing the work in both, and the FSB is circling it from 2 directions: what a bank's board should require of a system that acts on its own, and what the G20 should worry about when such systems are everywhere at once.
Congress asked a narrower question
I wrote here in August about the SEC's silence on agentic trading. On June 23, 8 members of the House Financial Services Committee, led by Bill Foster and Brad Sherman, sent SEC Chairman Paul Atkins 13 questions about retail investors handing their brokerage accounts to autonomous AI agents. Who is responsible when the agent trades badly? Does a broker-dealer shed its obligations by calling the agent a third-party tool the customer chose to connect? What happens when similarly trained agents, prompted by similar users, converge on the same trade at the same moment? The deadline for a response was July 31. As of today, 5 weeks past it, no public response has appeared that I can find.
The difference in altitude is the point. The congressional letter is about conduct and responsibility inside a market: who owes duties to whom, which existing rules apply, where the liability lands. The FSB letter is about what happens to the system when increasingly autonomous software is woven through the institutions, the infrastructure and the third parties that everyone depends on. Congress asked who is liable. The FSB is asking whether the failure stops.
The monoculture underneath
Which brings me back to algorithmic monoculture, the argument I made here in August about hiring and then extended, uneasily, to markets. The FSB has now put the load-bearing half of it into a letter to the G20.
Concentration produces 2 different failures, and they are worth keeping apart. The first is correlated judgment. When many institutions rely on similar models they reach similar conclusions, and the inconsistency that used to keep one mistake from becoming everyone's mistake quietly disappears. That is the agentic trading worry, and Congress's question about agents converging on the same trade is a version of it. The second is correlated vulnerability. When many institutions rely on the same suppliers they inherit the same weaknesses, and an attacker who finds one has found all of them. That is Bailey's worry. A flaw in a widely adopted model, framework or provider is not 200 separate incidents. It is 1 incident with 200 addresses, and the letter makes the geography explicit, noting that cyber disruption "can spread across jurisdictions through common technology providers, shared infrastructure, and cross-border financial activity."
The stability concern in the second case is not that one bank gets breached. It is that an incident of sufficient scale or ambiguity leaves counterparties uncertain about who else is compromised, and that uncertainty is what converts an operational event into a confidence event. The transmission channel is well understood. What is new is a plausible mechanism for making the trigger more likely.
The 2 failures are not the same, and the FSB has not claimed they are. They share a cause. Nobody chooses monoculture, because every institution makes a locally rational decision: use the strongest available model, because a worse one would be negligent; use the dominant cloud provider, because it is the most reliable; use the vendor the auditors already understand. Each choice is defensible in isolation, and the sum of them is concentration.
Which is why the October 2025 report's least quotable section, the one on the criticality and substitutability of AI services and the concentration of widely used models, is the part I would keep. It is an attempt to measure what no individual buyer can see. A bank can tell you how good its model is. It cannot tell you how correlated its judgment, or its attack surface, is with every other bank's, because the answer depends on what everyone else bought.
The case against reading too much into a letter
A chair's letter to the G20 is not regulation. It has no binding force, it was written to be read at a meeting, and its frontier AI discussion runs to 3 paragraphs. Bailey announced no rule, no supervisory expectation, no stress test, no data collection. The FSB says only that it is "looking at what steps it can take, within its mandate and expertise, to address these challenges," which is the standard formulation for having not yet decided. The operative ask of firms sounds conventional too. They should "strengthen vulnerability management, response and recovery capabilities, and prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies." Supervisors have wanted the first half of that since long before anyone said frontier, and cyber has been near the top of every supervisory risk list for years, so adding AI to a threat already ranked that highly is less of a departure than the framing suggests.
The concession has a limit, and it sits in the second half of that same sentence. Preparing for "simultaneous disruption across multiple firms or shared technology dependencies" is not business continuity planning. It is planning for a correlated event, a different exercise from planning for your own outage, and not something any single firm can do alone. The letter is blunter still about the public side of the problem, observing that "many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models."
So I take the deflationary point and still think the escalation is real. Language of this kind, in this venue, is where supervisory expectations usually begin, and this letter does not stand on its own: 3 documents precede it in under 2 years, the most recent a live consultation whose final report is still to come. And the substance is not only about attackers. The June question about agentic AI, the October 2025 concern with provider concentration, and the August warning about autonomy are 3 views of one problem that a business continuity plan does not solve.
The unit of risk is getting larger
The first question anyone asked about AI in finance was whether the model was any good. Then it became whether the institution deploying it was governing it properly, which is where model risk management and the FSB's 12 sound practices live. Then Congress asked what happens when the model stops being a tool and becomes a participant, placing orders in a market with real counterparties. Now the FSB has asked the largest version of the question, which is what happens when the failure does not stay inside the institution that caused it.
Model, institution, market, system. Each step outward makes the problem harder to assign to anyone, because each involves a risk that nobody creates on purpose and nobody owns. The bank that buys the best available model is not doing anything wrong. The vendor selling it to 200 banks is not doing anything wrong. The customer connecting an agent to a brokerage account is not doing anything wrong. The risk is in the aggregate, and the aggregate has no risk committee.
Governance built to supervise individual models was never designed for that, and nobody yet knows what replaces it. Financial stability policy at least has the right instincts, because it was invented for exactly this failure of composition. Whether it has the instruments is a different question, and the final report on those 12 sound practices will be a first indication.
What is no longer in doubt is the category. The age of governing individual models is giving way to something harder: governing autonomous systems whose failures may not stop at the institution that deployed them.
Further Reading
From this blog
- Why Is the SEC So Silent About Agentic Trading? - the Foster-Sherman letter, its 13 questions, and the deployment-responsibility seam the SEC has not addressed.
- Algorithmic Monoculture - why locally rational adoption decisions add up to correlated failure, and why no individual buyer can assess it.
- Context Engineering Is Governance at Inference Time - the governance decisions that get made inside a system rather than around it.
- When the Firm Becomes the Monoculture - the same concentration dynamic inside a single organization.
Primary sources
- FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 - Financial Stability Board, August 31, 2026. The letter itself (PDF) is worth reading rather than the coverage of it; the frontier AI discussion runs to only 3 paragraphs, and the concentration qualifier is the part that summaries tend to leave out.
- FSB Chair warns of risks arising from frontier Artificial Intelligence (AI) models - the accompanying press release, August 31, 2026.
- Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report - Financial Stability Board, June 10, 2026. The 12 practices, and the consultation question naming GenAI and agentic AI.
- Public responses to the consultation - Financial Stability Board, August 6, 2026.
- Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector - Financial Stability Board, October 10, 2025. Indicators, taxonomies, and third-party concentration.
- The Financial Stability Implications of Artificial Intelligence - Financial Stability Board, November 2024. The original assessment.
- Foster, Sherman Seek Regulatory Clarity on Agentic AI Trading - U.S. House of Representatives, June 2026. The letter to SEC Chairman Atkins.
- Financial Stability in Focus: Artificial intelligence in the financial system - Bank of England Financial Policy Committee, April 9, 2025, on the potential for AI-based participants to take increasingly correlated positions.
- Annual Economic Report 2026, Chapter I - Bank for International Settlements, June 2026, on supervisory visibility into model-driven correlated exposures.