Systemic risk: AI in the mirror of 2008
The Bank of England's warning on financial fragility in the face of frontier AI models and cybersecurity
September 9, 2026 · 4 min read
TL;DR: Dependence on a few technology providers and the sophistication of AI-driven cyberattacks represent a systemic risk to banking stability. The Bank of England suggests 'bare metal' recovery measures to shield the system from potential collapses.
The warning echoing in high financial spheres
The Governor of the Bank of England, Andrew Bailey, has raised the tone on a subject that transcends technological speculation: the stability of the global financial system in the face of frontier artificial intelligence. In a letter addressed to G20 finance ministers, Bailey not only points out the operational risks of AI, but also draws an implicit parallel with the 2008 crisis, suggesting that technological interdependence is our new Achilles' heel. Unlike the financial crises of the past, where opacity resided in complex derivative products like CDOs (Collateralized Debt Obligations), the current crisis is brewing in the opacity of black-box algorithms and shared infrastructure.
Historically, the banking system has evolved from physical trust to massive digitalization. However, this process has created a systemic fragility: dependence on providers that act as critical bottlenecks. Bailey argues that the speed at which AI is integrated into financial markets—from high-frequency trading to credit risk assessment—surpasses the ability of regulators to audit the behavior of these machines in extreme stress scenarios.
The paradox of technological concentration
The core of Bailey's concern lies in technological monoculture. Modern financial infrastructure rests on the shoulders of a handful of cloud service providers (AWS, Microsoft Azure, Google Cloud). This consolidation, which was once celebrated for its efficiency and cost reduction, is today a geopolitical and operational vulnerability.
If a configuration error or a targeted attack on the infrastructure layer were to affect a dominant provider, the domino effect would be immediate. Unlike traditional banks, which possess capital and liquidity to absorb shocks, AI systems are intangible assets whose failure cannot be rescued with capital injections, but rather through data recovery and model integrity. The analogy is clear: the systemic risk of 2008 was the interconnection of banks; the risk of 2025 is the interconnection of their servers.
AI as a multiplier of cyber threats
AI is not just a management tool; it is an attack architecture. Cybersecurity experts have noted that AI enables:
- Automation of social engineering: The ability to generate hyper-personalized and audible phishing attacks (voice deepfakes) that can deceive even the most sophisticated treasury departments.
- Exploitation of zero-day vulnerabilities: AI can analyze massive codebases to find security flaws at a speed that human Security Operations Center (SOC) teams cannot match.
- Algorithmic disinformation: The ability to manipulate market sentiment through the massive generation of fake news that triggers automated trading algorithms, causing panic selling (flash crashes) without human intervention.
As the analysis by Hipertextual indicates, the fear of losing control over systems that exceed our decision-making capacity is no longer science fiction; it is a tangible operational risk. The automation of financial decision-making removes the 'human factor' of pause and judgment, accelerating market crashes in a matter of milliseconds.
Towards an emergency 'bare metal'?
Bailey's proposal suggests a return to fundamentals: the construction of isolated backups (bare metal). In the cloud era, this recommendation is almost technological heresy, but it is a survival necessity. 'Bare metal' implies having the capacity to operate on local physical servers, independent of the APIs and virtual environments of cloud providers. This would allow financial institutions to continue recording essential transactions even if the central infrastructure collapses.
This measure evokes the business continuity plans of the analog era, similar to post-9/11 recovery protocols, but adapted to a hyper-connected economy. The fundamental question is whether banks are willing to bear the operational costs of maintaining this 'analog redundancy' in a market obsessed with margin optimization.
Impact and perspectives
The lesson of 2008 was that financial systems do not fail due to isolated parts, but due to opacity and excessive interconnection. AI, today, seems to be replicating that risk architecture by centralizing operational intelligence in a few hands. While there is no evidence of an imminent collapse, expert analysis suggests that regulation must move from observation to operational resilience. Speculation about a possible financial 'AI-pocalypse' must be translated into stress tests that include total cloud failure. True stability in the future of work and finance will not come from the most advanced AI, but from the ability to maintain control when technology, inevitably, fails.