01The top three cloud providers hold 73 percent of financial infrastructure

The third Bank of England and FCA survey on AI in UK financial services, published in November 2024, put numbers on the degree of concentration. Among the 118 respondents, the top three named cloud providers accounted for 73 percent of all reported cloud-provider relationships. For AI model providers the figure was 44 percent; for data providers, 33 percent. Third-party implementations now represent 33 percent of all deployed AI use cases, up from 17 percent in 2022.

Two facts emerge from these figures: financial institutions are rapidly increasing their dependence on external AI, and that external supply is concentrated among a small number of firms. The FSB's November 2024 report, "The Financial Stability Implications of Artificial Intelligence," identified third-party dependencies and service provider concentration as one of the principal AI-related vulnerabilities to financial stability.

Figure 1 How dependence on a few providers becomes systemic risk
ConcentrationformsSinglepoint of…PropagationIndividualfirms choose…Top 3 cloudproviders hold…Singleprovider…Systemic riskBeyondindividual firm…Concentration formsSingle point offailurePropagationIndividual firms choose the sameproviders for efficiencyTop 3 cloud providers hold 73%Single provider failure hits theindustry simultaneouslySystemic riskBeyond individual firm control
Individual optimization by each institution aggregates into industry-wide concentration, turning a single provider's failure into systemic risk.

02A single provider's failure can halt an entire industry

What concentration means in practice was demonstrated by actual incidents. On July 19, 2024, a faulty configuration update to CrowdStrike's Falcon Sensor affected approximately 8.5 million Microsoft Windows devices worldwide. Banks lost online banking and ATM services, the London Stock Exchange Group's workspace platform went down, and card payment networks were disrupted. Estimated losses for the financial sector reached $1.15 billion. Across the Fortune 500, direct losses exceeded $5 billion.

On October 20, 2025, a DynamoDB DNS management failure in the AWS US-EAST-1 region caused a roughly 15-hour disruption affecting over 1,000 companies. Payment services and banking applications went offline, and user-reported incidents exceeded 6.5 million worldwide. Economic losses were estimated at over $1 billion. Downstream SaaS providers experienced cascading failures, making visible how a single cloud outage amplifies through multiple layers of dependency.

03The FSB identified four vulnerabilities and proposed a monitoring framework

The FSB's November 2024 report found that rapid AI adoption could amplify financial sector vulnerabilities across four areas: third-party dependencies and service provider concentration, market correlations, cyber risks, and model risk combined with data quality and governance. The report also flagged that generative AI could increase financial fraud and disinformation in financial markets.

A follow-up report in October 2025 proposed a framework of direct and proxy indicators for authorities to monitor AI adoption and identify related vulnerabilities. The indicators cover five domains: AI adoption scale, third-party dependency levels, market correlations, cyber threats, and model governance. Responding to a request from the South African G20 Presidency, the FSB moved toward common monitoring frameworks rather than leaving surveillance entirely to national discretion.

04DORA designated 19 providers for direct oversight

The EU's Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) entered into application in January 2025. It requires financial entities to implement ICT risk management, incident reporting, third-party risk management, and resilience testing. DORA's central innovation is bringing third-party concentration risk inside the financial regulatory perimeter.

On November 18, 2025, the European Banking Authority, EIOPA, and ESMA jointly designated 19 critical ICT third-party providers. The list includes AWS, Google Cloud, Microsoft, Oracle, SAP, and Deutsche Telekom, among others. Designation criteria include four factors: the potential systemic impact of a large-scale operational failure, the systemic importance of dependent financial entities, the degree of concentration of reliance, and the substitutability of the provider's services. Designated providers are subject to direct inspection by European supervisory authorities. The list will be updated annually.

Figure 2 Three-layer concentration in the AI supply chain
AI supply chainLayer 1: GPUsemiconductorsDesign dominated by one firmLayer 2: CloudinfrastructureTop 3 hold majority shareLayer 3: FoundationmodelsCapital ties to cloud layerAI supply chainLayer 1: GPU semiconductorsDesign dominated by one firmLayer 2: Cloud infrastructureTop 3 hold majority shareLayer 3: Foundation modelsCapital ties to cloud layer
Concentration exists across all three layers — semiconductors, cloud, and models — and these layers are interlinked through capital and operational ties, so a single failure can propagate through multiple layers.

05The UK will begin oversight of AWS, Google, Microsoft, and Oracle in July 2026

In the UK, the Bank of England, PRA, and FCA published the final policy for SS6/24, "Critical third parties to the UK financial system," in November 2024. Under this framework, HM Treasury designates critical third parties (CTPs), and regulators directly oversee their specified services. Oversight of four providers — AWS, Google Cloud, Microsoft, and Oracle — is set to begin in July 2026.

The Bank of England's Financial Policy Committee identified four AI-related focus areas at its April 2025 meeting: expanding AI use in banks' and insurers' core financial decision-making, expanding AI use in financial markets, operational risks from AI service providers, and the changing cyber threat environment. The FPC noted that if common weaknesses in widely used models cause many firms to misestimate certain risks, the resulting mispricing and misallocation of credit could become a financial stability concern.

FrameworkScopeApproach to concentration riskTimeline
DORA (EU)Financial entities and ICT third parties19 CTPPs designated, direct inspectionApplied from January 2025
SS6/24 (UK)Critical third parties' specified services4 providers from July 2026Final policy November 2024
FSB monitoringNational authorities' AI surveillanceIndicators across 5 domainsOctober 2025 report
IMF cyber noteAI and cyber intersectionWarning on correlated infrastructure failuresMay 2026 publication

06The AI supply chain is concentrated across three layers

AI concentration risk is particularly difficult for finance because the concentration does not sit in a single layer. The first layer is semiconductors: GPU design is dominated by effectively one company. The second layer is cloud infrastructure, where the top three providers hold the majority of financial sector usage. The third layer is foundation models, where the number of providers used by financial institutions is limited, and many of these providers have capital ties or operational links to the same cloud companies in the second layer.

Because these three layers are interlinked, a single failure or vulnerability can propagate through multiple layers simultaneously. The IMF's May 2026 note, "Artificial Intelligence and Cybersecurity in the Financial Sector," observed that advanced AI models can dramatically reduce the time and cost needed to identify and exploit vulnerabilities, raising the likelihood of simultaneously discovering and targeting weaknesses in widely used systems. The higher the concentration of shared infrastructure, the larger the blast radius. Pharmaceutical clinical trial data management and healthcare information systems run on the same cloud platforms, carrying similar third-party concentration risks.

Figure 3 Four stages of concentration risk management
MapPrepareVerifyGoalRegisterthird-party…Measureconcentration…SecurealternativesMulti-cloud,OSS modelsConductscenario…Businesscontinuity…MapPrepareVerifyGoalRegister third-partydependenciesMeasure concentrationquantitativelySecure alternativesMulti-cloud, OSS modelsConduct scenario testsBusiness continuity under stress
Starting with visibility into dependencies, then measuring, preparing alternatives, and testing scenarios to build resilience against concentration risk.

07Four practices for managing concentration risk

First, build a register of third-party dependencies including AI. Document which cloud, which model, and which data provider each business function depends on. The register of ICT third-party contracts required under DORA Article 28 can be extended to cover AI model providers.

Second, measure concentration quantitatively. Calculate dependency ratios weighted by business criticality. Apply to your own organization the type of metric the Bank of England and FCA survey produced — 73 percent of cloud usage concentrated in three providers.

Third, secure alternatives and switchover procedures. This means adopting multi-cloud architectures, evaluating open-source models in parallel, and establishing fallback procedures for provider outages. Reports from the October 2025 AWS outage indicate that firms with multi-cloud configurations recovered faster.

Fourth, conduct scenario tests. Verify business continuity under scenarios such as a prolonged outage at a major cloud provider, a model provider's discontinuation of service, or a simultaneous cyber attack. After the CrowdStrike incident, the FCA required financial firms to demonstrate resilience against "severe but plausible scenarios" by March 2025.

01

Third-party dependency register

Map

For each cloud, model, and data provider, document the dependent business functions, responsible owners, and contract terms.

02

Quantitative concentration measurement

Measure

Calculate dependency ratios weighted by business criticality to identify single-provider exposure.

03

Alternative readiness

Prepare

Maintain multi-cloud configurations, evaluate open-source models in parallel, and document provider-failure fallback procedures.

04

Scenario testing

Verify

Test business continuity against prolonged provider outages, service discontinuations, and simultaneous cyber incidents.

08AI concentration risk requires management on both contractual and technical fronts

Traditional third-party risk management centers on contractual controls: vendor selection criteria, SLAs, audit rights, and subcontracting restrictions. But AI model usage introduces third-party risk without a formal contractual relationship. When a firm downloads and uses an open-source pretrained model, no contract with the provider exists. The provider has no obligation to notify the firm of version changes or end of support.

On the technical side, firms need to document the pathways through which model outputs influence business decisions, and establish procedures for assessing the impact of model changes before they take effect. DORA requires this within its ICT risk management framework, but detailed technical standards specific to AI models are still being developed. The question the FSA of Japan flagged in its December 2024 model risk management progress report — how to categorize external vendors' large language models — sits at the intersection of concentration risk and model risk, extending the themes discussed in Part 6 of this series.

09Pharmaceutical data infrastructure faces the same cloud concentration

Cloud and model concentration risk extends beyond finance. Clinical trial data management, electronic case report forms, and pharmacovigilance databases run on the same small set of cloud providers that financial institutions use. The range of cloud environments that meet FDA's electronic records and electronic signatures requirements under 21 CFR Part 11 is limited, resulting in high dependence on specific providers.

A cloud outage during a clinical trial can interrupt data collection and reporting, affecting regulatory submission timelines. The structure parallels financial payment disruptions: a single provider's failure propagates across an entire industry. The framework DORA introduced for monitoring and managing third-party concentration risk in finance contains principles applicable to pharmaceutical and healthcare data infrastructure as well.

Key Points ── 3 to take away
  1. The top three cloud providers account for 73 percent of financial firms' cloud usage, and third-party AI implementations doubled from 17 percent in 2022 to 33 percent in 2024. The 2024 CrowdStrike outage ($1.15 billion in financial losses) and the 2025 AWS outage (over $1 billion) demonstrated the scale of simultaneous disruption that concentration produces.
  2. DORA designated 19 critical ICT third-party providers for direct oversight in November 2025, and the UK will begin supervising AWS, Google Cloud, Microsoft, and Oracle from July 2026. The FSB proposed common monitoring indicators, and the IMF mapped the pathways through which AI amplifies cyber risk.
  3. Managing concentration risk requires a third-party dependency register, quantitative measurement of concentration, alternative-readiness planning, and scenario testing. This includes AI models used without formal contracts, demanding management on both technical and contractual fronts.
Closing

Finance's dependence on a few clouds and models is a byproduct of the pursuit of efficiency. Individual institutions each chose the same providers for rational reasons, and the aggregate result was an industry-wide single point of failure. DORA's CTPP designations and the UK's CTP oversight represent a turning point: structural concentration risk is now treated within regulatory frameworks, not left to individual firms' self-help. Part 10 of this series will examine the broader landscape of AI-related financial regulation from the perspective of central banks and regulatory authorities.

Sources & references
  1. Financial Stability Board. The Financial Stability Implications of Artificial Intelligence. November 2024. https://www.fsb.org/2024/11/the-financial-stability-implications-of-artificial-intelligence/
  2. Financial Stability Board. Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector. October 2025. https://www.fsb.org/2025/10/monitoring-adoption-of-artificial-intelligence-and-related-vulnerabilities-in-the-financial-sector/
  3. Bank of England. Financial Stability in Focus: Artificial Intelligence in the Financial System. April 2025. https://www.bankofengland.co.uk/financial-stability-in-focus/2025/april-2025
  4. Bank of England / FCA. Artificial Intelligence in UK Financial Services – 2024. November 2024. https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024
  5. European Banking Authority / EIOPA / ESMA. Designation of Critical ICT Third-Party Providers under DORA. November 18, 2025. https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital
  6. IMF. Artificial Intelligence and Cybersecurity in the Financial Sector (IMF Notes 2026/005). May 2026. https://www.imf.org/en/publications/imf-notes/issues/2026/06/29/artificial-intelligence-and-cybersecurity-in-the-financial-sector-576706
  7. Bank of England / PRA / FCA. SS6/24: Critical Third Parties to the UK Financial System. November 2024. https://www.bankofengland.co.uk/-/media/boe/files/letter/2026/response-to-tsc-inquiry-report-on-ai-in-financial-services
  8. OrboGraph. CrowdStrike Outage: Financial Institutions Experience an Estimated $1.15B Loss. July 2024. https://orbograph.com/crowdstrike-outage-financial-institutions-experience-an-estimated-1-15b-loss/
  9. Financial Executives International. AWS October 2025 Outage: What Financial Executives Must Learn About Cloud Risk Management. October 2025. https://www.financialexecutives.org/FEI-Daily/October/aws-outage-2025-cfo-cloud-risk-management.aspx