Financial systems are exposed to a structural AI risk with "no effective mitigation," EU warns
European Systemic Risk Board issues frightening forecast setting out the dangers of frontier artificial intelligence.
Frontier AI models pose a novel, fast-growing and currently unsolvable structural risk to the financial system, officials have warned.
In an alarming advisory about security-focused AI systems, the EU's European Systemic Risk Board said rapid AI development constitutes a “structural increase in systemic cyber risk to the EU financial system for which no fully effective mitigation framework currently exists.”
The paper sketches out three ways this threat could escalate: criminal attacks that gradually erode trust in smaller institutions, long-term espionage against major banks and authorities, and a coordinated assault on critical infrastructure at the heart of the financial system, causing lasting damage across Europe.
It also makes a startling confession about the sheer scale of the response needed to shore up systemic defences against the structural risk, which would involve hitherto unprecedented collaboration between "AI providers, software providers, security firms, open source maintainers, financial institutions and authorities at both national and EU level".
Risks at the frontier of AI development
Governments and central banks have been publicly grappling with the systemic risks of frontier AI since Anthropic revealed that Claude Mythos could autonomously discover previously unknown zero-day software vulnerabilities and develop working exploits. Since then, OpenAI has also announced GPT-5.5-Cyber, a specialist model designed for advanced cybersecurity work.
To keep a lid on the threat, AI providers have begun limiting access to their most powerful models or throttling their capabilities. OpenAI has restricted its specialist cyber model to approved users, while Anthropic also imposed tighter safeguards which effectively dial down the capabiltiies of the publicly available version of its latest model.
READ MORE: The Silicon Age Collapse: Systemic risks that could derail digital civilization
But the levee AI firms have built between their models and critical systems is unlikely to hold for long. The most capable open-weight models are nowonly about four months behind their closed competitors, according to research from the nonprofit research institute Epoch AI.
Defining frontier AI models as “advanced general purpose AI models capable of materially affecting offensive or defensive cyber operations" and giving them the very European acronym FAIM, the EU systemic risk body wrote:
“The emergence of FAIMs with capabilities rivalling those of humans, together with the proliferation of FAIM-powered weaponised critical vulnerabilities, has drastically increased risks to individual critical and important functions, financial institutions and the entire financial system."
Humans out of the loop
Models do not have to conduct an entire attack autonomously to be dangerous, the Eurocrats pointed out. AI agents can be linked together in a pipeline to carry out an attack without human intervention, while less autonomous systems can still help threat actors accelerate their work - particularly the discovery and exploitation of vulnerabilities rated as high or critical severity levels.
One of the most concerning aspects of offensive AI is its ability to shrink the time available to defenders “from weeks to hours". This means financial institutions could be forced to apply urgent patches while trying to avoid the operational failures that hurried changes to critical systems can cause.

READ MORE: Stablecoins could become a systemic risk to global financial stability, central banks warn
Is it highly unlikely that defenders will be able to move at the same speed as attackers. For example, banks and other regulated institutions must follow structured, bureaucratically sluggish processes for testing, validation, risk assessment and change management. These controls are essential to stability, but will slow the deployment of defensive measures during a fast-moving attack.
Although AI is likely to strengthen cyberdefences over the longer term, the ESRB said these operational, regulatory and technological constraints give attackers a “decisive short to medium-term advantage.”
Vulnerability cascades
One of the concerns officials raised is that the sheer number of critical vulnerabilities uncovered by frontier models risks “overloading current vulnerability management frameworks" - causing what we refer to as vulnerability cascades.
That could place systems such as the CVE program - a global mechanism for cataloguing and assigning identifiers to publicly disclosed software flaws - under intense pressure as researchers struggle to verify, disclose and patch vulnerabilities anywhere near as quickly as AI can find them.
But that's not all. AI is also creating greater “asymmetry in the cyber domain,” with far fewer resources needed to carry out complex cyberattacks. Sophisticated operations that once required teams of highly skilled hackers could become feasible for a much wider range of criminals, hacktivists and state-backed groups - exponentially increasing the threat level.
These intersecting risks are a perfect storm of widening exposure, lower barriers to entry for threat actors and an explosion in both attack vectors and available exploits. The threat is particularly acute because the digital infrastructure underpinning the financial system is presumed to contain a large number of undiscovered vulnerabilities waiting to be exploited.
If defenders don't find them quickly, adversaries most certainly will.
Concentration risks
The systemic dangers of frontier AI stems partly from the financial sector’s common exposures. Banks, payment systems and financial market infrastructure biw often rely on the same cloud platforms, software suppliers, cybersecurity services and open source components. A single AI-discovered vulnerability could therefore expose multiple institutions at once, enabling correlated attacks or a widespread supply-chain compromise leading to cascading failures throughout the economy.
That makes the threat difficult to contain through action by individual institutions alone. A vulnerability affecting a major provider or widely used software component could spread disruption across the sector and, in the worst case, reach payment, clearing and settlement systems.
Worryingly, not all institutions are equally prepared. Smaller banks and nonbank financial institutions may lack the money, technology and specialist personnel available to their larger counterparts. But because the financial system is so deeply interconnected, the failure or weakening of less-protected institutions could erode confidence and transmit stress through the wider sector.
READ MORE: Agentic AI demands an upgrade to financial system resilience, Bank of England warns
Even without a catastrophic attack, persistent cyber pressure could force institutions to devote increasing amounts of money and staff to detection, containment and recovery. The ESRB warned that this could divert resources from core business, reduce profitability and weaken shareholder confidence.
Most leading AI providers are based outside the EU, meaning European institutions cannot assume they will continue to have access to the most advanced defensive capabilities. Frontier models could be subjected to export controls, while access to them could become a source of geopolitical leverage.
The danger is compounded by the concentration of AI development and infrastructure in third countries - a nod to Europe’s failure to keep up with the United States and China in this critical area. That dependence is a risk in itself at a time of “heightened geopolitical tension,” when access to frontier models is increasingly treated as a national security issue.
Systemic nightmare scenarios
The EU set out three plausible scenarios of potential incidents with systemic implications, warning:
“Developments in FAIMs should be treated as a source of systemic risk. Should incidents propagate through payment systems, clearing and settlement or other operational bottlenecks, they could severely disrupt or shock the financial system, undermine public confidence and lead to heightened financial volatility.”
“Without timely, coordinated and efficient action at EU level, the current asymmetries may evolve into structural vulnerabilities, increasing the likelihood that FAIM-induced cyber stress translates into a systemic event.”
In the first scenario, profit-driven organised criminal groups and state-affiliated threat actors use frontier models to target institutions with a “relatively weak cybersecurity posture,” focusing on those holding highly liquid, easily stolen assets or capable of initiating large capital transfers.
Attacks on smaller banks, nonbank financial institutions and crypto companies cause some failures, but the wider financial system remains intact. Even so, confidence deteriorates, driving customers and capital towards larger banks and foreign institutions while increasing funding costs for smaller firms.Imagine being able to build anything
Just by thinkingIn the second scenario, hostile states use restricted frontier models to infiltrate major EU banks, central banks and regulators for long-term espionage. Although financial services continue operating, persistent, undetected access allows sensitive information to flow to foreign competitors, gradually undermining confidentiality, trust and Europe’s competitive position.
The most extreme scenario involves a hostile state using frontier AI to infiltrate Europe’s financial market infrastructures (FMIs) - critical payment, clearing and settlement systems which money around the financial system - before launching a synchronised assault amplified by mass disinformation.
Offensive models are then passed on to criminals and hacktivists, whose attacks paralyse essential financial services, shatter public confidence and inflict severe, lasting damage on the EU financial system.
How long will that damage take to fix? We don't know.
But what is quite clear is that the pace of AI development is far outstripping the speed of a defensive response to this emerging threat.
As with so many grave risks to human civilisation - from exploding volcanoes to novel infectious agents - we will probably only find out about how to address the risk long after the damage is done.
Frontier AI models work at machine speed. We can only think as fast as our legacy biology permits. That gap will create the defining systemic risks of both today and tomorrow.