- SPEECH
Where AI risks meet
Welcome address by Christine Lagarde, President of the ECB and Chair of the European Systemic Risk Board, at the tenth annual conference of the ESRB
Frankfurt am Main, 1 October 2026
It is a pleasure to welcome you to the tenth annual conference of the European Systemic Risk Board (ESRB), as we mark 15 years since its creation.
The ESRB was born of a hard lesson laid bare by the global financial crisis and reinforced by Europe’s sovereign debt crisis.
Risks had been building across institutions and markets, while the view of any one authority remained incomplete. Europe needed a way to see the financial system as a whole, so it brought central banks and supervisors together around one table to provide that overall perspective.[1]
15 years on, the rising importance of artificial intelligence (AI) is putting that system-wide view to the test.
Generative AI is already widely used in finance. Nearly nine out of ten significant euro area banks use it.[2] Furthermore, in a recent survey of EU securities market firms, seven out of ten respondents expected to increase their investment in AI.[3]
There is good reason for that interest. AI can help financial institutions analyse vast amounts of data more quickly and improve how they assess risk.[4] More broadly, the potential productivity gains could allow firms to offer customers a better service while using their resources more efficiently.
To date, most uses of AI in finance involve limited autonomy. But AI agents are beginning to take on more discretion. They can pursue a goal with limited human direction, potentially devising trading strategies or finding vulnerabilities in the systems on which trading depends.
The ESRB is well placed to examine how recent developments in AI could create risks across the financial system. I see three areas that call for particular attention.
In financial market trading, AI agents may pursue goals in ways their human overseers did not intend and cannot detect.
In cyber resilience, an attack on shared technology has the potential to disrupt several firms at once.
And in geopolitics, international tensions can increase the threat of cyberattacks[5] and prompt restrictions on the frontier models that firms use to defend themselves.
Taken alone, each risk is serious. But together they can interact and compound across the financial system. That potential interplay calls for careful and encompassing macroprudential monitoring going forward.
Financial market trading
Let me start with financial market trading.
The use of AI in financial markets predates generative AI. Investment firms have long relied on algorithms to execute trades, and banks have already been using AI to assess credit and detect fraud.[6]
The possibility that AI could amplify market moves has been recognised for some time. The Financial Stability Board warned almost ten years ago that traders adopting similar machine learning strategies could reinforce a financial shock.[7]
Today, competitive pressure gives firms a strong incentive to adopt the latest AI models to hold their ground against their rivals.[8] Those frontier models are few in number.
The ESRB’s Advisory Scientific Committee has recently warned that the widespread use of similar models may lead firms to assess a shock in much the same way and make similar trades in response, reinforcing the move in prices.[9]
Against this background, the arrival of AI agents could mark a new stage in how financial markets use the technology.
The use of agentic AI is still limited. In a survey conducted this year, only 5% of asset managers said they gave AI autonomous or semi-autonomous authority over investment recommendations or trades.[10] But that percentage may well increase over time.
In a potential sign of things to come, one of the world’s largest hedge funds has launched a strategy in which AI is the primary decision-maker, with the firm’s stated goal “to build a fully artificial investor that can outcompete humans”.[11]
The uptake of agentic AI may mitigate some risks, but it could create new ones.
If firms train their AI agents on proprietary data – for instance, their balance sheets or client flows – trade decisions may become less correlated than if traders were simply querying the same models with similar prompts.[12]
But greater autonomy also brings a new risk for financial markets: misalignment, where AI agents may pursue goals in ways their human overseers neither intended nor can detect.
In one study, researchers gave an AI model the role of a trader at a fictional investment firm. It traded on an inside tip, knowing that management disapproved, then hid the reason for its trade from its manager.[13]
Separate research finds that AI trading programs learned to collude without communicating in a simulated market, creating a risk of market manipulation and distorted prices.[14]
As more discretion passes to ever more powerful machines, human oversight will likely become harder to sustain. And when we cannot fully understand how those machines reach their decisions, the consequences may be harder to foresee and mitigate.
Cyber resilience
The risks also extend beyond the decisions AI agents make. AI is changing how quickly weaknesses in financial firms’ systems can be found and exploited.
In July, the ESRB issued a warning on the cyber risks posed by frontier AI models.[15] Independent tests show how quickly their capabilities have advanced. In a simulated 32-step attack, models released at the end of 2025 completed about a third of the steps on average, with the remaining steps proving too difficult for them.[16] The latest models, however, completed every step.[17]
Rapid advancement in AI could leave financial institutions far less time to contain an attack. The ESRB has warned that the interval between an initial exploit and widespread automated exploitation could fall from weeks to hours.[18]
We already know that human attackers are using AI to find weaknesses and move faster. Misalignment is now emerging as a risk to cyber resilience too. We have seen several incidents this year in which agents from leading AI labs breached the systems of firms and governments.[19]
In one case, around 1,200 agents being tested at an AI lab were meant to work in isolation. But they found a way to communicate and formed a swarm. A hierarchy emerged, with some assigning tasks to others. The swarm gained internet access, and hundreds of the agents joined an attack on Hugging Face, a platform for AI developers.[20]
So firms, once again, face a strong incentive to build their defences with frontier AI.
But while frontier AI can help defenders find weaknesses faster, financial institutions still need to test their fixes before deploying them in essential services. That can take time. Attackers, by contrast, can exploit a weakness as soon as they find it.
For that reason, the ESRB expects attackers to hold an advantage in the short to medium term, even as AI strengthens defences over time.[21]
Geopolitics
Nevertheless, access to frontier models can still materially shorten the time a defender needs to respond to attacks. So retaining that access will become a matter of fundamental national security.
In an environment of growing geopolitical tensions, however, that creates another form of risk.
Frontier model development is concentrated in the United States and China.[22] For Europe, that raises a question: who controls access to the models its financial institutions may come to rely on?
That question was once hypothetical. Since this summer, it no longer is. In June, a US export-control directive concerning two advanced models led their provider to suspend access. For Europe, the result was an abrupt cut-off.[23]
While access to the general-use model was restored a few weeks later, access to the model with fewer cyber safeguards remained limited to organisations vetted by the US administration.[24]
That incident passed without any discernible disruption to the financial system. But bear in mind that we are only in the early stages of the AI revolution.
We have already seen what concentration risk can mean. In the summer of 2024, one faulty software update grounded flights and disrupted banking services around the world.[25]
Now imagine a future in which almost every institution depends on a select few models or AI firms to adjust trading strategies or find vulnerabilities in their systems. In that scenario, a loss of access could prove highly disruptive to financial stability.
What may begin as a short-term decision driven by a strategic imperative can quickly lead to unexpected knock-on effects for Europe’s financial system.
That is why Europe needs to develop AI capabilities of its own, and be an indispensable part of the supply chain that ultimately produces AI, so that access to tools that are vital for its financial resilience does not depend on a switch controlled elsewhere.
Conclusion
Let me conclude.
Stephen Hawking once described our future as “a race between the growing power of our technology and the wisdom with which we use it”.[26] AI has the potential to offer many benefits to society. But it also poses risks, including for financial stability.
So if we are to use AI wisely, policymakers need to anticipate risks to the financial system as a whole. They should use their respective mandates and coordinate where those risks cut across them.
In Europe, the AI Act sets rules for AI systems according to the risks they pose. But contending with frontier AI models that are becoming ever more powerful will also require cooperation at the global level.
History does offer some precedent.
During the Cold War, the United States and the Soviet Union agreed to limits on their own nuclear capabilities and worked to prevent nuclear weapons from spreading, even as they continued to compete with each other.
Of course, the difference with the AI race is that one country – the United States – holds a lead in frontier AI. It may view any global agreement as a means to slow it down. Yet such a view would be shortsighted.
Strategic rivals still have a shared interest in preventing frontier AI from falling into the hands of bad actors, while at the same time preserving access for those who need to defend critical systems. I hope that such global cooperation will emerge.
Here in Europe, action is already warranted.
The ESRB has warned that cyber defences around critical financial systems need to be reviewed and updated as frontier AI changes the threats they face. And financial authorities should ensure firms plan timely responses and work together where an attack could spread across the sector.[27]
Since the ESRB was established 15 years ago, the financial system has changed profoundly. AI is reshaping it once more. But one thing has remained constant: the ESRB’s commitment to its mission of monitoring how risks interact across the financial system and helping authorities respond accordingly.
And with that, I am pleased to open the tenth annual conference of the ESRB.
Thank you.
ESRB, “Mission and establishment”.
Banks supervised by the ECB. See Buch, C. (2026), “Digital innovation: hindrance or booster for banks’ business models?”, keynote speech at the annual Foreign Bankers’ Association of the Netherlands conference, 22 September.
Specifically, between 2025 and 2027. See European Securities and Markets Authority (2026), AI adoption and trends in securities markets: EU evidence, 20 February.
European Securities and Markets Authority (2026), op. cit.
As observed in ESRB (2026), “Outcomes of the 61st General Board meeting of the European Systemic Risk Board – 24 March 2026”, press release, 31 March.
See Bank for International Settlements (2019), “High-level summary: BCBS SIG industry workshop on the governance and oversight of artificial intelligence and machine learning in financial services”, 3 October; Financial Stability Board (2024), The Financial Stability Implications of Artificial Intelligence, 14 November; and Singh, S., Schupbach, A., Asiala, A. and Siwecki, D.A. (2025), “AI’s impact on banking: use cases for credit scoring and fraud detection”, Supervision Newsletter, ECB, 20 November.
Financial Stability Board (2017), Artificial intelligence and machine learning in financial services – Market developments and financial stability implications, 1 November.
Financial Stability Board (2024), op. cit.
ESRB Advisory Scientific Committee (2025), Artificial intelligence and systemic risk, Reports of the Advisory Scientific Committee, No 16, December.
Mercer (2026), “AI is boosting asset managers’ investment operations, but humans still call the shots, according to a new Mercer report”, 21 May.
See Bridgewater’s “AIA Labs: The Future of Investment Intelligence”.
Some correlation will likely persist given the concentration of the underlying frontier models underpinning these agents.
Scheurer, J., Balesni, M. and Hobbhahn, M. (2023), Large Language Models can Strategically Deceive their Users when Put Under Pressure, 9 November.
Dou, W.W., Goldstein, I. and Ji, Y. (2025), “AI-Powered Trading, Algorithmic Collusion, and Price Efficiency”, Working Papers, National Bureau of Economic Research, No 34054, July.
See ESRB (2026), “Frontier AI models could strain cyber resilience in the financial system, ESRB warns”, press release, 7 July.
AI Security Institute (2026), “How fast is autonomous AI cyber capability advancing?”, Blog, 13 May; see also ESRB (2026), Addressing frontier AI models with cyber capabilities from a financial stability perspective, July.
ESRB (2026), see footnote 16.
ESRB (2026), see footnote 16, p.11.
Hammond, G. (2026), “OpenAI says governments among ‘dozens’ of organisations hacked by its agents”, Financial Times, 26 September; Reuters (2026), “Anthropic discloses fourth AI hacking incident missed in earlier review”, 9 September; Morris, S. (2026), “Google’s Gemini hacked three companies in new AI safety incident”, Financial Times, 19 September.
METR and Redwood Research (2026), Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident, 26 August.
ESRB (2026), see footnote 16.
ESRB (2026), see footnote 16.
To comply with the directive, Anthropic suspended access for all customers, including those in the United States. See Anthropic (2026), “Statement on the US government directive to suspend access to Fable 5 and Mythos 5”, 12 June.
Anthropic (2026), “Redeploying Fable 5”, 30 June; see also Anthropic’s Claude Mythos overview page.
For a general overview of the incident, see Cloud Security Alliance (2025), “What We Can Learn from the 2024 CrowdStrike Outage”, 3 July.
Hawking, S. (2018), Brief answers to the big questions, Bantam Books, New York.
See footnote 15.
Bank Ċentrali Ewropew
Direttorat Ġenerali Komunikazzjoni
- Sonnemannstrasse 20
- 60314 Frankfurt am Main, il-Ġermanja
- +49 69 1344 7455
- media@ecb.europa.eu
Ir-riproduzzjoni hija permessa sakemm jissemma s-sors.
Kuntatti għall-midja