AI · Systems

Model Risk Has Become an Infrastructure Problem

When firms share data, model providers, hardware, and cloud infrastructure, model errors and operational failures cease to be independent. The systemic exposure is common dependency, not model capability in isolation.

A model-dependency network A network diagram. At the centre is a shared-infrastructure hub, the data vendors, pre-trained models, and cloud platforms that many firms rely on, ringed by a faint dashed shockwave and marked with a burst. Four firm nodes at the corners, each with its own risk engine and trading desk, connect to that hub by gold edges whose arrowheads point outward to the firms, showing a shock at the centre reaching every dependent firm at once regardless of how well each governs its own models. A regulator node below connects to the hub by a dashed cyan monitoring link. A model-dependency network one shared layer beneath many firms a shock here reaches every firm at once Shared infrastructure data vendors · models · cloud Firm A risk engine · desk Firm B risk engine · desk Firm C risk engine · desk Firm D risk engine · desk Regulator system-wide monitoring Schematic. Shared-node risk needs vendor controls, resilience, substitutability, and system-level monitoring, beyond firm-level validation.
Figure 10 · A model-dependency network One shared layer of data, models, and cloud beneath many independent-looking firms A critical failure can sit outside the firm. Common providers and data can correlate operational outages or model errors across institutions that otherwise maintain separate governance and trading books.

Conventional model-risk management begins inside the institution: specify the model, challenge its assumptions, validate its data, and control its use. Shared technological dependencies add a second unit of analysis. If several firms rely on the same data feed, base model, hardware stack, or cloud service, an error can cross institutional boundaries without any bilateral financial exposure. The question is no longer only whether one model is wrong. It is how many nominally separate decisions inherit the same failure mode.

Section 01Four vulnerabilities, one theme

In November 2024 the Financial Stability Board identified four AI-related vulnerabilities with potential financial-stability implications: third-party dependencies and provider concentration; market correlations from common models and data; cyber risk; and model risk, data quality, and governance. They are distinct channels, not one problem in disguise. Their interaction is what matters. Concentrated infrastructure can spread a cyber or operational incident, while common data and objectives can correlate otherwise valid model outputs.

This is what makes the framing an infrastructure question rather than a capability question. None of the four vulnerabilities is about whether a model is clever. Each is about what happens when a great many firms quietly come to depend on the same small set of components, so that a weakness in one component is no longer contained within one firm. The risk is structural, and it lives in the wiring between institutions rather than inside any one of them.

Section 02The dependency network

Figure 10 draws the dependency layer beneath a set of independently governed firms. A flaw in a widely used model, an outage at a cloud provider, or an error in a common data feed can become a simultaneous incident for every dependent institution. Internal controls still matter: they can detect, contain, or reject faulty inputs. But validation of the local model cannot by itself supply an unavailable service or diversify a provider used across the market.

The FSB is explicit about the concentration that produces this. Reliance on specialised hardware, cloud services, and pre-trained models, it noted, has increased the potential for AI-related third-party dependencies, in a market for those products and services that is itself highly concentrated, exposing financial institutions to operational vulnerabilities and to systemic risk from disruptions affecting the key providers. The diagram's centre is small on purpose. The fewer the shared nodes, the more of the system a single failure can take with it.

per firm:    risk ~ P(model wrong)            # validation lowers this

systemic:    N firms share model M and data D
             corr(model errors)  ->  high      # they are wrong together
             correlated errors   ->  simultaneous action
                                 ->  amplified move, liquidity crunch

firm-level governance alone does not identify system-wide error correlation

Validation estimates local fitness. Dependency mapping asks whether the same error or outage can arrive at many firms together. The two controls answer different questions.

Section 03Correlation is the exposure

The correlation channel cannot be observed from one institution's inventory alone. The FSB notes that common models and data may increase correlation in trading, lending, and pricing, with possible amplification through liquidity and asset prices. This is a conditional mechanism rather than an established empirical magnitude. Similar inputs do not guarantee identical actions, but they reduce one source of diversity and make common optimisation targets more important to monitor. A well-governed firm can still participate in a market-wide feedback loop.

That is why supervision is moving from the firm to the network. The FSB followed its 2024 assessment with a monitoring framework in October 2025, an effort to track the adoption of AI and the concentration of its providers across the system, precisely because no single firm can see, let alone manage, the correlation it is part of. The supervisory recognition matches the engineering one: the way to reduce shared-node risk is not better validation of one model but genuine diversity, of models, of data, of vendors, plus monitoring at the level where the correlation actually lives.

Validation answers whether your model is wrong. It cannot answer whether everyone is wrong together.

The resulting risk inventory has two layers. The first is familiar: model purpose, assumptions, validation, limits, and monitoring. The second maps dependencies, substitution time, data lineage, concentration, and failure propagation across providers. Diversity can reduce common-mode risk, but only if alternatives are genuinely independent and operationally usable. Model risk has not simply moved outside the firm; it now spans the boundary between local governance and shared infrastructure.

  • AI adoption across finance is uneven, and the FSB describes potential vulnerabilities, not realised events.
  • This is not an argument against AI or shared infrastructure, both of which bring real benefits; it is an argument about correlation and concentration.
  • Provider concentration changes over time, and Figure 10 is a schematic of the mechanism, not a map of any specific market.

This research is analysis and commentary for general information. It is not investment advice, an offer, or a solicitation, and it contains no price forecasts. Descriptions of the FSB's work summarise the cited sources; the interpretation is the author's.

References & notes

  1. Financial Stability Board (14 November 2024). The Financial Stability Implications of Artificial Intelligence. Primary source for the four vulnerability channels discussed in the research.
  2. Financial Stability Board (10 October 2025). Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector. Follow-up framework for monitoring adoption, third-party dependency, provider concentration, and data gaps.

Return to the front page