What role will AI play in the next crisis? Is it the one the authorities expect?
AI Systemic risk Regulations
We have been seeing a lot of official discussion on how artificial intelligence might affect financial stability. Distilling what the various policy reports, policymakers' speeches and financial stability reports say about the topic, a fairly consistent list of financial stability concerns emerges.
Dependence on a small number of third-party providers. Correlated positions arising from firms using the same models. Cyber attacks made cheaper and more powerful. Model risk. Overreliance that follows when models perform well. Speed and volatility in markets under stress. A fall in AI asset prices when financed by debt.
Others come up as well, real but not systemic in themselves. Fraud and scams made cheaper and more convincing. Bias and data privacy. Consumer protection. A runaway algorithm or a trading outage.
It is certainly worthwhile to discuss all these concerns, but much discussion focuses more on what could go wrong in generalities rather than on how those failures would affect the financial system. In other words, more on the triggers and less on the consequences. And that is important, because resilience has to be built against the ultimate consequence, not the trigger that leads to it.
Three ideas frame what follows. The first is what I called the double coincidence a decade ago. Suppose a serious cyber attack on the financial system lands on a calm day, as it would most of the time. There are no liquidity tensions, so the private and public sectors can absorb it, and it remains a costly operational incident. Now suppose the same attack had landed on 16 March 2020, at the height of the Covid dash for cash, or on 1 October 2008, after Lehman failed. The attack and the liquidity crisis would have viciously amplified each other, all while draining the credibility of the very institutions charged with containing them, just when that credibility mattered most.
The second idea is monoculture, a problem I have written about since 2001, and in the AI context since 2017. Only a handful of vendors operate at the frontier of AI, joined by open-source suppliers whose models are trained on much the same data. Most institutions, private and public alike, likely end up running the same few models, which may cause them to see and react to risk in similar ways. The consequence is procyclicality, and for that the models do not have to be identical as common suppliers, data and objectives can be enough. This works against resilience since a more diverse system absorbs shocks because its participants respond differently, some buying while others sell. A monoculture arising from industry wide use of a very small number of model has no such shock absorbers when everyone heads for the same exit at the same time.
The third idea is AI wrong-way risk, where the trust we place in AI grows with its performance in normal times, just as its reliability falls in times of stress.
The three ideas work together. The double coincidence makes instability depend on the state of the system, the monoculture pushes institutions towards responding to that state in similar ways, and wrong-way risk means the shared engines are least reliable in precisely the state where their similarity is most dangerous.
AI undermines supervision
I have seen little discussion of the threat of AI being used to optimise against the rulebook, what is often called in the AI literature adversarial compliance. In practice it means firms use AI to shape reported risk, capital, liquidity and leverage so that the rulebook sees less than the firm is really doing.
I see optimisation against the rulebook as a core threat.
A regulated firm might use AI to find leverage that does not show up as leverage. It might optimise its way through a stress test, presenting positions that pass while the underlying risk stays put. Or it might produce disclosures that are formally compliant but economically misleading.
How common is this? Hard to gauge. My anecdotal evidence is that plenty of old-style human reporting is still being done, but institutions are actively studying the area and seem intent on expanding AI use in reporting, for cost reasons if nothing else.
The authorities cannot keep up. They have limited AI resources and find it hard, both financially and structurally, to acquire more. Their approach to supervision is still built on PDF reports, database dumps and inspections, with humans analysing reports the machines wrote.
Why is the private sector so much quicker to adopt AI? Competition. A firm that shuns AI in a fiercely competitive financial system earns lower profits, and its decision-makers enjoy lower compensation. No such pressure bears on supervisors. Legacy practices, and the restrictions under which public sector organisations operate, hold back adoption even when it would cut costs and improve supervision.
The supervisor inside the monoculture
The public authorities are part of the monoculture too. When supervisors rely on the same engines as the firms they oversee, as seems likely, they share the same blind spots in identifying risk and deciding how to respond.
No official report says the supervisor is inside the monoculture. On the contrary, they all seem to assume that the supervisor is an outside observer, as if the authorities were monitors with better tools than the private sector. They do not ask whether supervisors themselves become part of the same model monoculture they are meant to oversee.
The exception seems the one central bank, the Bank of Korea that runs its own model, giving it advantages the rest do not have.
When stress hits, it hits in minutes
Some discussion mentions the speed of AI, but as far as I can tell, generally not taking the next step of outlined the actual mechanism by which AI affects crises. That is a topic Andreas Uthemann and I first discussed in a 2024 column and then analysed in the Journal of Financial Stability last year.
Most of the time, financial institutions maximise profit and treat risk and regulation as an irritant. In crises, everything changes. When a shock hits, the first to act is the best placed to survive it. When Archegos collapsed in 2021, the banks that moved first, Goldman Sachs and Deutsche Bank, came off best, followed by Morgan Stanley. Credit Suisse and Nomura, the slowest to react, lost $5.5 billion and $2.85 billion respectively. I called this the one-in-a-thousand-day problem. For 999 days out of a thousand, banks compete for profit. On the thousandth day, survival is all that matters.
Survival in crisis has always meant withdrawing liquidity wherever one can. In times past that meant buying gold. Today it means banks parking money in their reserve accounts at the central bank. Those without access, run to short term treasuries, repos and whatever else is closest to cash. That rapid withdrawal of liquidity is the main damage a crisis does, and the reason central banks inject liquidity.
Historical data offer guidance on how such an AI liquidity event will play out. A crisis is collective behaviour, driven by what we economists call strategic complementarities and by the reactions of key decision-makers as events unfold. Neither the strategic interaction nor the reasoning behind those decisions is visible in the data until after the event has passed.
Those who hold endless meetings and hope for the best fail.
AI makes the cost of delay greater. The treasury function, in charge of liquidity, is already one of the largest users of AI in banks. Markets have run at machine speed for years. What is new is autonomous decision-making spreading beyond the trading floor, into treasury, collateral, credit and the interpretation of what other institutions are doing.
There are two ways AI accelerates and intensifies crises.
The first is that the engines are good at coordinating, because of those strategic complementarities, in ways nobody can detect. The engines do not need to communicate directly. One institution withdraws liquidity, moving prices and funding flows. Engines at other institutions read those moves as information, and their response validates the first decision.
The AI literature calls this stigmergic coordination, in which agents communicate indirectly by changing the environment observed by others. If the engines continue to learn, those market movements become learning signals. In effect, the engines train one another through a communication channel no human designed and supervisors may not be able to observe.
Every institution then has a reason to move faster still. Engines in different institutions can thus rapidly converge on either a crisis equilibrium or a non-crisis one. They collectively absorb a shock or collectively amplify it. The monoculture makes such convergence all the more likely.
The second is the desire to be first. AI is good at analysing and deciding, so it speeds up the decision to run or to stay.
What this means in practice is that a crisis that once took days or weeks might now take minutes or hours. Much of the official response, including emergency meetings, discretionary liquidity decisions and the time needed to assess events, remains built for human speed. It will not keep up.
AI wrong-way risk
Many reports discuss AI reliability in terms of overreliance, explainability and model-risk governance.
But those categories understate a subtler and more important problem, AI wrong-way risk. As AI proves itself on ever harder tasks, we trust it with more, until it is making the decisions that matter most. But AI, like the statistical models before it, learns from the past, and a crisis is precisely the moment the past stops being a reliable guide. It is a version of the Peter principle. The machine is promoted until it reaches a task it cannot do, and in finance that task is the crisis.
AI is least reliable exactly when the stakes are highest, when an unprecedented event arrives and there is no relevant data to have learned from.
The same applies to the authorities. They adopt AI to close the capability gap, learn to trust it after years of normal performance, and risk entering a regime change with the same blind spots as the firms they supervise.
AI makes the system easier to attack
There is plenty of discussion of cyber attacks, and it has only grown louder since Anthropic's Mythos 5 emerged earlier this year. There is less discussion of how such attacks might actually play out when they coincide with existing financial stress — the interaction I call the double coincidence.
I first argued in 2016 that cyber risk becomes systemic through its interaction with other stresses. AI cyber risk should be viewed in the same way. It lowers the cost of attacking the financial system, helping criminals find loopholes, letting terrorist groups orchestrate synchronised attacks on financial infrastructure, and allowing nation states to target the vulnerabilities of an adversary's financial system while keeping plausible deniability.
The advantage runs to the attacker. A defender has to protect the whole system. An attacker needs only to find a single critical weak point, and finding such weaknesses is exactly what AI is good at.
The most dangerous targets are not individual banks but the plumbing that connects them — the payment systems, the clearing houses, the custodian banks through which ownership of vast quantities of assets is recorded. Concentrating transactions in a central counterparty also concentrates the consequences of a successful attack.
The real danger is the double coincidence. The damage is worst when a cyber incident lands on an already fragile system. Most cyber incidents remain operational rather than systemic. But when one strikes amid market turmoil, as trust drains and institutions protect themselves, even a mild attack can tip the system into crisis.
Evaluating the financial stability impact of a cyber attack by its severity alone is therefore misleading. The state of the financial system when the attack arrives may matter more than the severity of the attack itself.
The policy response also depends on what the attack disrupts. If it disables the infrastructure through which liquidity is intermediated, injecting liquidity becomes ineffective because the payment and settlement systems needed to distribute it are unavailable. That makes those systems particularly attractive targets for the best-resourced attackers, especially nation states able to time an attack to coincide with financial stress.
Nor does the attack even have to be real. In the Great Stock Exchange Fraud of 1814, a man in uniform appeared at an inn in Dover with false news that Napoleon was dead. The London market rallied before the hoax unravelled, and several defendants were subsequently convicted of conspiracy. A convincing deepfake that a bank is failing can now do the same at global scale and in seconds, triggering a run before anyone has established whether it is true. AI helps those who would cause harm as well as those who would prevent it.
Conclusion
While AI does not create a new fundamental channel for financial instability, it amplifies the existing ones, changing the speed, scale and correlation of crises.
So what role will AI play? The answer is likely to be threefold. It can conceal fragility before the crisis, as firms optimise against the rulebook. It can accelerate the crisis when it comes, as the shared engines converge and race to be first. And it may weaken the response, because the authorities' own tools carry the same blind spots and perform worst when needed most.
The trigger might be a cyber attack, a fraud, a fall in AI asset prices or something unrelated to AI altogether. AI will help determine whether that trigger stays contained.
When identifying what matters, one can focus either on possible triggers or on the mechanisms that determine whether a shock becomes systemic. My reading of official reports and speeches suggests that most of the emphasis is on the former.
That is a concern because it can make us think we are in better shape than we are, creating the illusion of control.
Instead of trying to predict the next trigger, it is better to build resilience against the consequences of a shock amplified by AI. That includes an official response that is fast enough and still works when wrong-way risk makes AI least reliable.