Europe's financial regulators warn of non-EU dependence risks across AI, quantum and private credit
Key Takeaways
- •The Joint Committee of the European Supervisory Authorities handed its autumn 2026 risk update to the EU Financial Stability Table on 10 September 2026, with details made public on 23 September.
- •EU finance relies on non-EU systems at nearly every layer, including large U.S. exposures in funds, ICT and payment suppliers outside the EEA, funding gaps in the dollar, sterling and Swiss franc, and non-EU clearing, repo and credit rating firms.
- •The regulators cautioned that frontier AI models can rapidly find and exploit software weaknesses, heightening the potential damage of AI-assisted attacks, a conclusion echoed by ENISA's 2026 threat report recording over 48,000 new vulnerabilities in 2025, a 22% increase.
- •Google Quantum AI researchers estimated in March that breaking the cryptography behind many cryptocurrencies might require roughly 20 times fewer qubits than previously thought, though no such machine exists yet, and developers including Jameson Lopp and the Ethereum Foundation are already pursuing defenses.
- •Private credit was identified as a third risk area: EU and EEA bank exposures total just 0.6% of assets, but regulators cited rapid growth and limited transparency as reasons to monitor the segment closely.

Three of Europe's financial regulators have warned EU governments that the bloc's banks, funds and insurers depend heavily on foreign providers and infrastructure, a reliance that could magnify the impact of any geopolitical shock or cyberattack.
Findings from the ESAs' Joint Committee
The Joint Committee of the European Supervisory Authorities (ESAs) — which brings together the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) — handed its autumn risk update to the Financial Stability Table of the EU's Economic and Financial Committee on 10 September 2026. The details were made public on 23 September. The handover is part of the joint committee's regular cycle of spring and autumn risk updates.
The assessment comes amid a broader EU focus on European economic security, a policy agenda centered on strengthening supply chain resilience and safeguarding critical technologies.
Dependence on non-EU systems at nearly every layer
The central concern is that EU finance is too closely tied to non-EU systems at almost every layer. Equity UCITS funds and alternative investment funds carry large U.S. exposures. Banks also rely on information and communications technology suppliers and payment systems based outside the European Economic Area (EEA), and run funding gaps in currencies they do not issue — mostly the US dollar, sterling and the Swiss franc. Clearing, repo and credit ratings are likewise largely routed through non-EU firms.
The authorities noted that dependence on non-EU counterparties leaves EU firms exposed to foreign regulatory regimes and political events beyond their control.
Frontier AI raises the stakes for cyberattacks
The regulators said frontier AI models can find and exploit software weaknesses quickly and easily, increasing the potential damage of AI-assisted attacks. That caution sits alongside the committee's own finding that EU banks lean on ICT suppliers based outside the EEA.
Europe's cybersecurity agency ENISA reached a similar conclusion on frontier AI in its own 2026 threat report. That report lists more than 48,000 new vulnerabilities logged in 2025 — a 22% jump — and points out that threat groups are increasingly using AI in their operations.
Is quantum computing a real threat to crypto traders?
Quantum computing is among the areas flagged by the ESAs. The concern is that a sufficiently powerful quantum machine could one day derive a private key from an exposed public key, enabling unauthorized transactions. No such computer exists yet.
However, Google Quantum AI researchers estimated in March that creating a computer capable of breaking the cryptography behind many cryptocurrencies might take roughly 20 times fewer physical qubits than once thought.
Developers are already working on defenses. In February, Bitcoin developer Jameson Lopp, alongside five collaborators, proposed a plan that would retire the network's current signature scheme. The Ethereum Foundation, meanwhile, is aiming to strengthen Ethereum against quantum attacks by December 2029. The work fits into a broader field of post-quantum cryptography, in which the U.S. National Institute of Standards and Technology published its first finalized quantum-resistant encryption standards in 2024.
Private credit flagged as a third area of concern
Private credit is the third risk area identified by the ESAs. The committee found that the EU market for private credit remains small, with banks in the EU and EEA holding related exposures worth just 0.6% of their total assets. Even so, the regulators flagged the segment as one to watch closely, citing rapid growth and limited transparency.