EU Supervisors Warn External Dependencies, AI & Private Credit Are Testing Financial Resilience
Key Takeaways
- External Dependencies Draw Scrutiny: The ESAs warned that reliance on non-EU technology providers, payment systems and financial infrastructure could amplify operational and geopolitical shocks.
- AI Could Intensify Cyber Risk: More capable AI models could allow attackers to identify and exploit vulnerabilities faster, while quantum computing presents longer-term risks to widely used cryptographic systems.
- Private Credit Links Are Growing: The EU private credit market remains relatively small, but limited transparency, uncertain leverage and growing connections with banks and insurers are attracting supervisory attention.
- Financial Fundamentals Remain Strong: EU banks, insurers and investment funds have remained resilient despite geopolitical tensions, market volatility and rising operational risks.
- Preparedness Is the Priority: The ESAs called for stronger scenario planning, stress testing, crisis preparedness and closer monitoring of external dependencies, private credit, AI and quantum computing.
Deep Dive
Europe’s financial system has spent much of 2026 absorbing shocks without looking particularly shaken by them. Markets have lurched with geopolitical events and energy prices. Cyber threats have persisted. New technologies have developed faster than the institutions charged with overseeing them can comfortably digest. Through it all, European banks, insurers and investment funds have remained remarkably sturdy.
That is the reassuring half of the European Supervisory Authorities’ latest assessment. The other half is about what happens when the trouble comes from somewhere the financial system cannot easily control.
In their Autumn 2026 update on risks and vulnerabilities the European Banking Authority, European Insurance and Occupational Pensions Authority and European Securities and Markets Authority turned their attention toward three vulnerabilities that increasingly resist neat institutional boundaries. Europe’s financial sector depends heavily on companies and infrastructure outside the EU. Artificial intelligence is beginning to alter the character of cyber risk. And private credit, though still comparatively small in Europe, is growing into a more complicated web of borrowers, funds, banks and insurers.
None amounts, for now, to a declaration of imminent danger. That is partly the point. The ESAs are looking at the places where an otherwise resilient financial system could discover that strength in one institution does not necessarily protect it from weakness elsewhere.
The foundations remain solid. European banks reported a 10.5% return on equity in the first quarter, while their common equity tier 1 ratio stood at 16.2%. Non-performing loans remained close to historic lows at roughly €375 billion ($442 billion), or 1.8% of total loans. Insurers maintained stable median solvency ratios, and EU investment funds continued to perform relatively well through volatile markets.
There are cracks worth watching. Banks expect deterioration in asset quality to be concentrated particularly in commercial real estate and small and medium-sized enterprise portfolios. More frequent and severe natural catastrophes could widen insurance protection gaps. Cyber and fraud risks remain the principal sources of concern on the operational side. But the report becomes more interesting when it leaves the balance sheet and begins tracing the connections between institutions.
The Risk Beyond Europe’s Borders
A financial system can be well capitalized and still depend upon things it does not control. For European finance, some of those dependencies are substantial. EU equity UCITS have 52% of their geographic exposure in the United States. Bond funds are less concentrated, with 45% of their geographic exposure in Europe and the remainder distributed more widely. The largest 10 non-EU UCITS asset management groups had €6.6 trillion ($7.8 trillion) in European assets under management in mid-2025, with five U.S.-based groups accounting for roughly 65% of that total.
The infrastructure underneath those markets has dependencies of its own. More than half of the outstanding principal in repo transactions involving EEA entities remains with non-EEA counterparties. UK central counterparties conduct the bulk of clearing for interest-rate derivatives, while a U.S. CCP performs the bulk of clearing for credit derivatives. The large credit rating agencies are headquartered outside the EU, though the ESAs noted that 95% of EU issuers are rated by analysts located within the bloc.
Insurers are connected to the world somewhat differently. Roughly 13% of their investments are outside the EEA, while about 28% of ceded risks are transferred to non-EEA counterparties, concentrated heavily in the UK, Bermuda and Switzerland. Those relationships spread risk, which is one of their purposes. They also create counterparty and concentration exposures capable of carrying trouble back across borders.
For banks, the dependency that troubles supervisors most is less financial than technological.
Around 80% of banks responding to an EBA survey identified reliance on ICT service providers as their biggest challenge among non-EU and non-EEA dependencies. Payment solutions came next, identified as a material risk by roughly 60%. Cloud services, software and payment infrastructure have become part of the ordinary machinery of banking. Much of that machinery belongs to providers domiciled elsewhere.
The danger is not that foreign providers are inherently less reliable. It is that concentrated reliance creates another path by which geopolitical disruption, regulatory divergence or operational failure can enter the European financial system. A bank does not need a direct exposure to a conflict zone to feel the consequences of events there.
That distinction runs throughout the ESAs’ assessment. Direct bank exposures to regions affected by war or geopolitical tensions remain limited. Indirect effects are harder to contain. They can appear in borrowers’ finances, credit demand, funding conditions or the availability of services on which institutions have quietly become dependent.
When the Attacker Gets Faster
Cyber risk has been familiar to financial institutions for long enough that familiarity itself can become deceptive. The ESAs are concerned less with the existence of the threat than with how quickly its character may change. Cyber risk and data security remain the most significant drivers of operational risk across the EU financial sector, followed by fraud. The number of cyberattacks against financial institutions remains high, although the ESAs said available data indicate that risks may be leveling. Frontier AI models complicate that picture.
The problem is speed. More capable models could allow attackers to discover and exploit weaknesses in IT systems at unprecedented pace, including previously unknown zero-day vulnerabilities. The defensive window narrows accordingly. A vulnerability that once demanded time, expertise and patient probing may become easier to find and exploit before the institution on the other side has understood that it exists.
Insurers could encounter the consequences in a different form. More frequent or severe AI-enabled cyberattacks could increase claims and accumulation risks for cyber insurers, although exclusion clauses may limit some of the sector’s exposure.
Then there is quantum computing, a technology whose financial promise arrives with an unusually awkward risk. The same computing power that could eventually improve optimization, fraud and compliance monitoring, pricing and simulation could undermine some of the cryptographic systems used to secure communications, transactions, databases and blockchains.
The chronology is what worries supervisors. The threat could arrive before commercially viable applications do. Information stolen and encrypted today can simply be kept until the technology exists to decrypt it later, the so-called “harvest now, decrypt later” problem. The EU’s NIS Cooperation Group has recommended that member states adopt a post-quantum cryptography migration strategy by the end of 2026.
Private Credit Gets Harder to Ignore
Private credit presents almost the opposite problem. Its risks are not difficult to imagine. They are just difficult to see. The market has expanded rapidly as a source of financing globally, and the ESAs noted emerging signs of stress in some segments following high-profile defaults in late 2025. It has also become an increasingly important source of financing connected with AI investment. Europe’s market remains considerably smaller than those elsewhere, which limits the immediate systemic concern.
EU private credit funds had €97.1 billion ($114.4 billion) in assets under management, with 95.2% focused on Europe. That definition includes the UK, Switzerland and other non-EU European countries. North America accounted for just 2.8%, leaving direct contagion risk from U.S. exposures relatively limited among European private credit funds themselves.
The connections around those funds are more complicated. EU and EEA banks had nearly €150 billion ($176.8 billion) of exposures to private credit funds and related asset managers as of June 2025, equivalent to about 0.6% of their total assets. The figure is indicative rather than exhaustive. It is drawn from large-exposure reporting and includes exposures to asset managers engaged more broadly in private credit activities.
The vulnerabilities identified by supervisors are familiar individually and more troublesome in combination. Private loans may be valued infrequently and, at times, inaccurately. Credit risk can be high. Leverage across the chain is difficult to establish. Data remain incomplete.
Then there are the links that only become obvious under stress. A bank may finance a private credit vehicle while lending to some of the same borrowers. Insurers may hold their own private credit exposures. Funds facing liquidity mismatches may encounter redemption pressure. What begins as a problem in one corner of private markets can therefore find several routes into the regulated financial system.
The ESAs stop well short of describing private credit as a systemic threat to Europe. Its comparatively small EU footprint matters. So does its growth.
That combination explains the tone of the recommendations. Supervisors are not being told to retreat from private credit or external providers, nor are financial institutions being asked to prepare for one particular catastrophe. They are being asked to know where the dependencies are before those dependencies are tested.
The ESAs called for stronger geopolitical scenario planning and resilience testing, better crisis preparedness and closer coordination among authorities. For private credit and other non-EEA exposures, they want greater transparency, stress testing, robust valuation methodologies and better risk modeling. Technology dependencies should continue to be examined under the Digital Operational Resilience Act, particularly where many institutions rely on a small number of providers.
AI and quantum computing require the same habit of preparation. DORA and the EU AI Act provide part of the regulatory foundation, the ESAs said, but firms still need strong cybersecurity controls, contingency planning, better software practices and new defensive techniques, including AI-powered security testing.
The report’s most consequential warning is therefore not that European finance has become fragile. The evidence presented by the ESAs says otherwise. It is that resilience is becoming harder to locate within any single institution. Capital can be measured. Non-performing loans can be counted. Solvency ratios can be watched from quarter to quarter.
Dependencies are harder. They sit between firms, across borders and inside technologies whose importance is often clearest only when they stop working. That leaves supervisors with a less comfortable kind of risk to oversee, one in which the health of the financial system increasingly depends on understanding not simply what institutions own, but what they cannot operate without.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

