
Europe’s top financial watchdogs are sounding an alarm that goes well beyond spreadsheets and stress tests: the continent’s reliance on foreign technology providers, the rise of artificial intelligence, and a fast-growing private credit market could all become flashpoints for the EU financial system if left unmonitored. In their Autumn 2026 risk update, the European Supervisory Authorities — the EBA, EIOPA and ESMA, collectively known as the ESAs — flagged these three areas as the most pressing sources of EU financial risks heading into the next stretch of the year, even as they insisted the broader system remains sturdy.
Key takeaways
- The ESAs’ Autumn 2026 Joint Committee update names external dependencies, emerging technologies and private credit as the three key vulnerabilities facing the EU financial system.
- Heavy reliance on non-EU ICT providers and infrastructure raises exposure to geopolitical shocks, operational disruptions and cyberattacks.
- Private credit in the EU is still relatively small but growing fast, with limited transparency and rising links to banks and insurers.
- European banks show strong profitability and capital ratios, though asset quality risks are building in commercial real estate and SME lending.
- Advanced AI and quantum computing are described as both an opportunity and a looming cybersecurity threat, including to cryptographic systems used by blockchains.
Key Vulnerabilities in the EU Financial System
The single clearest message from the ESAs’ latest assessment is that Europe’s financial stability increasingly hinges on things it doesn’t fully control. External providers, unproven technologies and an opaque lending market are now treated as structural risk factors rather than side issues, according to the findings presented at the meeting of the Financial Stability Table of the EU’s Economic and Financial Committee on 10 September 2026.
External Dependencies on Non-EU Providers
Much of the EU’s financial infrastructure runs on foreign rails. The ESAs point out that clearing, repo and credit rating markets are largely intermediated by non-EU entities, while banks continue to lean heavily on ICT service providers and payment systems based outside the European Economic Area. That dependency, the authorities warn, could amplify the fallout from geopolitical shocks and operational disruptions, since a single outage or policy shift abroad could ripple straight through European markets. Investment funds also carry outsized exposure to the United States, particularly through equity UCITS and alternative funds, while bond funds are somewhat more geographically spread out.
This is where the risk becomes tangible for ordinary market participants: if a critical software vendor, cloud provider or clearing house sits outside EU jurisdiction, European regulators have less direct leverage to intervene quickly during a crisis. That gap between economic dependence and regulatory reach is precisely what the ESAs are urging supervisors to close.
Emerging Technologies: AI and Quantum Computing
Artificial intelligence sits at the center of the update’s cyber warnings. The ESAs note that increasingly capable AI models could make cyberattacks more powerful and far harder to contain, letting bad actors find and exploit vulnerabilities at a pace defenders may struggle to match. In the insurance sector specifically, the update flags that orchestrated, AI-enabled cyberattacks during a period of severe geopolitical instability could push up claims and accumulation risks for insurers, though exclusion clauses may cushion some of that impact.
Quantum computing gets a similarly two-sided treatment. The ESAs acknowledge its promise for optimizing financial processes, fraud detection, compliance monitoring and pricing. But they also warn it could undermine the cryptography that currently secures communications, transactions, databases and blockchains — and, crucially, that this risk could materialize faster than any commercially viable quantum application actually arrives.
That warning has already rippled into crypto markets. Reports covering the ESA update note that the EU’s Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography, and that the European Commission’s post-quantum roadmap calls on member states to begin transitioning by the end of 2026, with a firmer 2030 deadline for high-risk use cases. Analysts covering the crypto angle of this warning have pointed to a related, if separate, concern: CryptoQuant founder Ki Young Ju estimated that roughly 6.89 million BTC — including coins in P2PK addresses where public keys are already visible on-chain, and coins that could be exposed after earlier spending transactions — could face future quantum exposure, with around 3.4 million BTC dormant for more than a decade, some of it linked to Bitcoin’s creator. Ju noted that fixing this would require network-wide consensus among Bitcoin’s community, a process that has historically moved slowly, citing past disputes such as the block-size debate and SegWit2x. None of this suggests a quantum computer can break Bitcoin’s cryptography today — the ESAs describe a forward-looking risk, not a present-day breach — but it does put a regulatory and technological clock on both traditional finance and crypto assets that rely on similar cryptographic foundations.
Private Credit Market Risks
Private credit is the third leg of the ESAs’ warning, and it’s the one growing the fastest. The market remains relatively small within the EU, with limited aggregate exposures among banks and insurers, but its rapid expansion, thin transparency and deepening ties to the wider financial system could turn into a real problem during periods of stress. The ESAs specifically call out infrequent and potentially inaccurate loan valuations, elevated credit risk, uncertainty about leverage running through the value chain, and data gaps that leave both market participants and regulators partially in the dark.
There’s also a transatlantic angle: EU entities carry exposure to the much larger US private credit market, and liquidity mismatches inside private credit funds could amplify redemption pressures, generating spillovers to banks through shared funding channels and common exposures. Banks could also face credit risk indirectly, through shared borrowers or financing commitments made to private credit vehicles.
EU Financial System Resilience Amid Risks
Despite this list of concerns, the ESAs’ bottom line is that the EU financial system has held up well. Financial markets stayed resilient through a volatile stretch marked by geopolitical tensions, swings in energy prices and continued crypto-asset volatility — EU equities even reached record highs during the Middle East tensions, while bond yields rose without triggering major spread widening.
Bank Profitability and Asset Quality
European banks are operating from a position of strength. The ESAs describe strong profitability and high capital ratios, supported by organic capital creation, alongside low levels of non-performing loans. That said, the update flags expectations of asset quality deterioration in specific portfolios — particularly commercial real estate and small and medium-sized enterprises — as areas worth watching closely in the months ahead.
Investment Funds and Insurance Sector Strength
EU investment funds weathered the recent bout of volatility without major disruption, according to the update. Fundamentals across insurance and pensions also remained strong, with capital and funding positions strengthening further. One caveat: more frequent natural catastrophes could widen protection gaps in insurance coverage, which the ESAs say reinforces the need for stronger adaptation measures across the sector.
Geopolitical and Cyber Threats Impact
Banks’ direct exposure to regions affected by geopolitical tensions remains limited, but indirect exposure and second-round effects could still ripple through to borrowers and funding conditions. Adverse geopolitical developments could translate into deteriorating asset quality and softer credit demand — something already partly reflected in banks’ impairment overlays. Banks also face funding gaps in some non-EU currencies, mainly tied to household and corporate deposits in USD, GBP and CHF. Meanwhile, cyber and fraud risks remain the dominant sources of operational concern across the sector, a thread that connects directly back to the AI-driven cyber threats discussed above.
Calls to Action by the European Supervisory Authorities
Given the mix of geopolitical uncertainty and fast-moving technology risk, the Joint Committee of the ESAs is telling supervisors and market participants not to get comfortable. The authorities are calling for stronger crisis preparedness, better resolution coordination, and regulation that can adapt quickly as conditions shift — rather than waiting for a crisis to expose gaps after the fact.
Strengthening Crisis Preparedness and Regulation
Concretely, this means managing exposures to non-EEA entities — especially those tied to private credit — monitoring dependencies on service providers based outside the EU and EEA, and building up defenses against risks stemming from the rapid development of AI and quantum computing. This is one of the two moments where the broader stakes become clear: if supervisors can’t move as fast as the technologies and markets they’re overseeing, the gap between risk and readiness only widens.
Proactive Risk Monitoring and Management
The second broader implication sits with market participants themselves. The ESAs are explicitly asking banks, insurers and investment firms to keep close watch on external dependencies, private credit exposures and emerging technologies as ongoing, rather than one-off, priorities. In practice, that suggests EU regulators view these three risk categories not as isolated warnings but as an interconnected set of pressures that could compound each other during a period of stress — cyber vulnerabilities linked to non-EU ICT reliance, private credit opacity amplified by AI-accelerated attacks, and geopolitical shocks testing all of it at once.
FAQ
What are the main vulnerabilities identified in the EU financial system?
The ESAs identified external dependencies on non-EU ICT providers, emerging technologies such as AI and quantum computing, and risks related to the growing private credit market.
How resilient is the EU financial system despite these risks?
The EU financial system remains resilient, with strong bank profitability and capital ratios, resilient investment funds and insurance sectors, despite geopolitical tensions, cyber threats, and natural catastrophes.
Why is reliance on non-EU ICT providers a concern for the EU financial system?
Dependence on non-EU ICT providers increases vulnerabilities to geopolitical shocks and operational disruptions, and heightens cyber risks especially from advanced AI-enabled cyberattacks.
What actions do the European Supervisory Authorities recommend?
The ESAs call on supervisors and market participants to strengthen crisis preparedness, enhance regulation, and proactively monitor and manage risks related to external dependencies, private credit, and emerging technologies.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

3 hours ago
18









English (US) ·