01The BIS identified AI investment concentration as a financial stability risk
The BIS 2025 annual report confronted head-on the question of how AI investment affects financial stability. The five largest hyperscalers are spending more than $1 trillion on AI-related capital expenditure across 2025-26, with some issuing corporate bonds to cover the gap between spending and cash flow. AI now accounts for roughly half of all investment-grade bond issuance and 87% of venture capital funding.
BIS modelling showed that if competitive pressure continues to push capital expenditure higher, the net economic surplus for the AI sector as a whole could turn negative under adverse scenarios. Direct lending funds have quadrupled their lending to AI and IT sectors over the past five years, and these sectors now represent about 15% of their portfolios. This concentration creates a transmission channel: if AI returns disappoint, a credit crunch could follow. Task-level studies report 20-50% productivity gains from AI, but whether these gains justify the investment scale remains an open question.
02Central banks are already using AI operationally
The most active AI adopters are the central banks themselves. The BIS Innovation Hub's Project Aurora combined AI with payments data to detect cross-border money laundering, reporting up to three times the detection rate of conventional rule-based methods and up to 80% fewer false positives. The ECB has incorporated a machine-learning model into its inflation forecasting toolkit since late 2022. Drawing on roughly 60 indicators covering inflation expectations, cost pressures, real economic activity, and financial conditions, the model is used to prepare monetary policy decisions for the Governing Council.
The Banque de France, Banco de Portugal, Deutsche Bundesbank, and Bank of Japan apply machine learning to securities and derivatives data for anomaly detection. The Federal Reserve and ECB use natural language processing on supervisory reports and consumer complaints to identify emerging risks. For central banks, AI is simultaneously a subject of study and a working tool.
03The FSB proposed monitoring indicators across five domains
The Financial Stability Board published a report in October 2025 titled "Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector." Responding to the G20 South African presidency, it proposed a framework combining direct and proxy indicators across five domains: AI adoption scale, third-party dependency, market correlation, cyber threats, and model governance. The preceding November 2024 report had identified four vulnerabilities — third-party concentration, market correlation, cyber risk, and model risk/data quality — and the monitoring indicators translate those categories into measurable metrics.
The report included a case study on the AI supply chain, highlighting vulnerabilities tied to financial institutions' reliance on a few critical third-party providers: criticality, concentration, and substitutability. It urged national authorities to strengthen data-sharing to build a more comprehensive picture of AI usage in the financial sector.
| Institution | Publication date | Focus | Key proposal |
|---|---|---|---|
| BIS Annual Report | June 2025 | AI investment concentration and financial stability | Warning on capex overheating and credit crunch risk |
| FSB Report | October 2025 | AI adoption monitoring | Five-domain framework of direct and proxy indicators |
| IMF Blog | July 2026 | AI and systemic risk | Strengthening macroprudential buffer design |
| ECB Lane Speech | July 2026 | AI and monetary policy transmission | Analysis of productivity, distribution, and natural rate effects |
04The EU AI Act reaches full enforcement for high-risk systems in August 2026
The EU AI Act (Regulation (EU) 2024/1689) has been applied in stages. Prohibitions on unacceptable-risk AI took effect in February 2025, followed during the same year by chapters covering general-purpose AI models and governance. On August 2, 2026, obligations for high-risk AI systems become fully enforceable. AI use cases common in finance — credit scoring, loan approval, fraud detection, AML risk profiling, and automated decision-making — are explicitly classified as high-risk.
High-risk systems must meet requirements spanning risk management, human oversight, transparency, auditability, and ongoing monitoring. The European Banking Authority plans activities in 2026-27 to support implementation of the AI Act in the banking and payments sector, promoting a common supervisory approach across national authorities. The dual application of the AI Act and DORA demands that financial institutions build governance frameworks addressing both AI-specific requirements and operational resilience simultaneously.
05Japan's FSA chose dialogue-based supervision
Japan's Financial Services Agency published its AI Discussion Paper version 1.0 in March 2025 and updated it to version 1.1 in March 2026. Rather than binding rules in the EU mold, the FSA promotes sound AI use through dialogue with financial institutions. As of March 2025, over 70% of surveyed financial institutions permitted employees to use generative AI broadly. Roughly half were using general-purpose GenAI tools with minimal customization.
The FSA convenes a task force including the Bank of Japan, the National Cybersecurity Office, the three largest banks, and Japan Exchange Group. The FSA's practical concerns center on whether machine-learning models such as gradient boosting in credit scoring satisfy audit requirements, and how to position external vendors' large language models within model risk management frameworks.
06The IMF set three policy priorities
In July 2026, the IMF published a blog post on how central banks can contain financial stability risks as AI accelerates change. The first priority is improving visibility into the accumulation of AI-related systemic risks, particularly where exposures are concentrated or highly correlated. The second is strengthening the design and deployment of macroprudential buffers. The third is containing leverage and excessive risk-taking among banks and systemically important non-bank financial institutions.
The IMF also addressed how AI amplifies cyber risk. Advanced AI models dramatically reduce the time and cost needed to identify and exploit vulnerabilities. The risk of simultaneous discovery and exploitation of weaknesses in widely used systems grows with infrastructure concentration. The ECB ordered euro-zone banks to submit plans for countering AI-powered cyber threats by October 31, 2026 — a more prescriptive approach than other major central banks have taken.
07Pharmaceutical AI governance shares the same structural challenges
The AI challenges facing financial regulators overlap structurally with those in pharmaceutical and healthcare regulation. The FDA and EMA published joint principles for good AI practice in drug development in January 2026. Under a policy of dismantling the "AI black box," companies are expected to explain AI limitations and underlying data in plain language. Under the EU AI Act, AI systems used in pharmaceutical quality control and process control are also classified as high-risk, requiring risk assessments, human oversight, and transparency.
Three issues are common to both sectors. First, model explainability: the obligation to explain the basis of a credit scoring decision and the obligation to explain why an AI selected a drug candidate share the same structure. Second, third-party concentration risk: clinical trial data management and pharmacovigilance databases run on the same few cloud platforms as financial systems. Third, international regulatory convergence: in finance, the FSB is pushing common monitoring frameworks; in pharma, the FDA-EMA joint principles serve the same function. The lesson pharmaceutical practitioners can draw from the financial debate is that regulation now moves in step with technology adoption, not after it.
Model explainability
In credit scoring and drug discovery alike, regulators now require that the basis for AI-driven decisions be explained in plain language to authorities and users.
Third-party concentration monitoring
Quantify dependency on cloud and model providers, and secure alternatives. The logic behind DORA's approach applies equally to pharmaceutical data infrastructure.
International regulatory convergence
The FSB's common monitoring indicators and the FDA-EMA joint principles both aim to harmonize fragmented national approaches into a single direction.
Simultaneous adoption and governance
The era of deploying technology first and building governance later is ending. AI governance frameworks should be designed alongside adoption plans.
08ECB's Lane argued AI could alter monetary policy transmission
ECB Executive Board member Philip R. Lane outlined three channels through which AI could affect monetary policy in a July 2026 speech. The first is productivity: AI may permanently raise output per worker, but households and firms may not immediately translate gains into spending due to uncertainty and consumption habits. The second is income distribution: if AI is capital-augmenting rather than labour-augmenting, inequality could widen, dampening demand expansion and inflationary pressure. The third is energy demand: AI data centers are pushing electricity consumption significantly higher, creating upward pressure on energy prices during the adoption phase.
Lane noted competing scenarios for the natural rate of interest. Sustained AI optimism could raise it through increased investment demand, while uncertainty about income distribution might increase precautionary savings, limiting the rise. The central bank challenge is adjusting monetary policy while AI's economic effects remain uncertain. The BIS's June 2024 observation — that widespread AI adoption could enable firms to adjust prices faster in response to macroeconomic changes, with repercussions for inflation dynamics — gains concreteness in this context.
09AI regulation is advancing through simultaneous permission and surveillance
If financial AI regulation can be reduced to a single direction, it is: "Use it, but make it visible." Central banks use AI themselves and recognize its utility. At the same time, they are building monitoring and information-sharing frameworks for three vulnerabilities: investment concentration that could produce a bubble, model uniformity that could amplify market correlation, and AI-enhanced cyber threats.
This direction applies to pharma as well. The FDA and EMA encourage AI in drug development while establishing explainability and transparency principles. The FSA's dialogue approach, the EU's legally binding approach, and the FDA's flexible approach differ in method, but converge on the same conclusion: permit AI use while requiring governance. Organizations that deployed AI before governance frameworks solidified will bear the cost of retrofitting. Tracking financial regulation serves as a leading indicator for pharmaceutical AI governance design.
- The BIS flagged hyperscaler AI capex exceeding $1 trillion in 2025-26 and warned that investment concentration could turn into a credit crunch if returns disappoint. The FSB proposed monitoring indicators across five domains in October 2025, urging national authorities toward a common surveillance framework.
- Central banks are active AI users. The BIS Innovation Hub's Aurora project tripled money-laundering detection rates, and the ECB integrated machine learning into inflation forecasting. At the same time, the IMF highlighted AI-amplified cyber risk, and the ECB ordered euro-zone banks to submit AI cyber-threat response plans by October 2026.
- Financial and pharmaceutical AI regulation share three structural challenges: model explainability, third-party concentration risk, and international regulatory convergence. The financial debate offers pharmaceutical practitioners a leading indicator for their own AI governance design.
Central banks and regulators are not in a position to ban AI. It is already an analytical tool for monetary policy, an instrument of supervision, and a routine part of financial operations. What regulation is moving toward is not prohibition but visibility — making AI usage observable and rendering the systemic vulnerabilities created by concentration and uniformity monitorable. For pharmaceutical practitioners, this is where the value of tracking financial regulation lies. Designing AI governance frameworks at the point of adoption, rather than retrofitting them afterward, is becoming the only cost-effective approach.
- Bank for International Settlements. Annual Economic Report 2025. June 2025. https://www.bis.org/publ/arpdf/ar2025e.pdf
- Bank for International Settlements. Central banks must prepare for AI's profound impact on economy and financial system (press release). June 25, 2024. https://www.bis.org/press/p240625.htm
- Financial Stability Board. Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector. October 2025. https://www.fsb.org/2025/10/monitoring-adoption-of-artificial-intelligence-and-related-vulnerabilities-in-the-financial-sector/
- International Monetary Fund. How Central Banks Can Contain Financial Stability Risks as AI Accelerates Change. July 23, 2026. https://www.imf.org/en/blogs/articles/2026/07/23/how-central-banks-can-contain-financial-stability-risks-as-ai-accelerates-change
- European Central Bank. Philip R. Lane, AI and monetary policy (speech). July 6, 2026. https://www.ecb.europa.eu/press/key/date/2026/html/ecb.sp260706~b81aa4e329.en.html
- Financial Services Agency of Japan. AI Discussion Paper (Version 1.1). March 3, 2026. https://www.fsa.go.jp/en/news/2026/20260303/aidp.html
- Bank of England. Sarah Breeden, Agents of change (speech at ECB Forum). June 2026. https://www.bankofengland.co.uk/speech/2026/june/sarah-breeden-panel-at-the-european-central-bank-forum-on-central-banking-2026
- Bird & Bird. Recent developments on the interplay between AI and financial institutions. 2026. https://www.twobirds.com/en/insights/2026/recent-developments-on-the-interplay-between-ai-and-financial-institutions
- Fortune. BIS sees a $1 trillion AI investment boom headed for a reckoning. June 29, 2026. https://fortune.com/2026/06/29/bis-central-bank-warning-hyperscaler-data-center-1-trillion-gamble-recession/