Technology · Financial regulation
European regulators warn AI development outpacing financial rules
Top officials from the ECB, Bank of England and FCA say traditional rulemaking cannot match the speed of agentic AI, while Europe risks falling further behind in frontier technology investment.
Europe's most senior financial officials delivered a coordinated warning this week: the continent's regulatory architecture is falling behind the pace of artificial intelligence development, particularly the emergence of agentic AI systems capable of autonomous decision-making in markets. Speaking at the European Central Bank's annual forum in Sintra, Portugal, the euro area's equivalent of the Jackson Hole symposium, and in parallel interviews, the leaders of the ECB, the Bank of England and the UK's Financial Conduct Authority described a widening gap between technological change and the tools available to oversee it.
Lagarde identifies a new order of risk
Christine Lagarde, president of the European Central Bank, struck the most urgent note. In an interview with France's Les Échos, she acknowledged AI as a source of productivity gains but characterised its acceleration as a "major risk" to financial stability. "For about a decade now we have been talking about cybersecurity risks, hacking, data theft and so on," Lagarde said. "But with the acceleration and deepening of AI models, we are confronted with a much more serious risk, because it is happening very, very quickly, and because the means of defence, and the funding required for them, have yet to be found." Her remarks reflect a shift in the ECB's public posture: from treating AI as an operational challenge for supervised banks to viewing it as a systemic vulnerability that could propagate across the financial system faster than existing contingency frameworks can respond.
The Sintra forum, held over several days this week, placed AI's impact on productivity and market integrity at the centre of its agenda. That positioning is deliberate. The ECB has spent the past two years expanding its analytical capacity on non-bank financial intermediation, climate stress testing and cyber resilience. AI now sits at the intersection of all three. Supervisors are particularly concerned about concentration risk: a handful of large language models and infrastructure providers underpin a growing share of financial services activity, creating single points of failure that traditional prudential regulation was not designed to capture.
Breeden proposes circuit breakers for autonomous trading
Sarah Breeden, deputy governor of the Bank of England, used her Sintra speech on Tuesday to focus on market dynamics. She said that, for now, trading firms mainly deploy autonomous AI for lower-risk operational tasks such as research and post-trade processing. "But that could change quickly," she warned. Increased use of agentic AI in core trading functions may require "greater oversight", including guardrails "analogous to circuit breakers or kill switches" that would "limit or stop trading market-wide if faulty AI models cause market meltdown." The analogy to existing market-wide circuit breakers, triggered when equity indices fall by predefined percentages within a session, is deliberate. It signals that the Bank of England is considering treating malfunctioning AI systems as a category of market infrastructure risk comparable to exchange outages or clearing failures.
Breeden's intervention carries weight because the Bank of England has been among the most active central banks in stress-testing non-bank financial institutions. Its 2023 and 2024 system-wide exploratory scenarios examined liquidity mismatches in funds and leverage in hedge funds. Adding an AI-driven contagion channel to those frameworks would represent a significant methodological expansion. The Prudential Regulation Authority, which sits within the Bank, has already asked major UK banks to map their critical third-party AI dependencies. Extending that mapping to trading venues and systematic internalisers would be a logical next step.
Rathi argues for collaborative oversight over prescriptive rules
Nikhil Rathi, chief executive of the Financial Conduct Authority, took the argument further. Speaking to CNBC's "Squawk Box Europe" on Thursday, he said the traditional cycle of rulemaking "doesn't work" when technology moves in weeks or months. "The reality is some of these technologies now move in weeks, or months, and the traditional cycle of rulemaking simply doesn't work in that way, so we need to think about new tools and a different way of working with the market in a more collaborative way, for example, on financial crime and AI risks, to be able to make sure we secure our objective of market integrity," he said. Rathi highlighted the UK's AI Safety Institute and the Financial Stability Board's work on frontier AI as examples of the infrastructure needed to bridge the knowledge gap between regulators and developers.
The FCA's approach reflects a broader British regulatory philosophy that has persisted since the 1990s: principles-based regulation supplemented by intensive supervisory engagement, rather than detailed prescriptive rules. That model was tested during the cryptoasset boom of 2020-22, when the FCA's registration regime for crypto businesses was criticised for being both too slow and too permissive. Rathi's emphasis on collaboration suggests he wants to avoid a repeat with AI. The risk, industry observers note, is that collaborative frameworks can lack enforceability and transparency, leaving consumers and smaller market participants without clear protections.
Europe's investment gap undermines regulatory ambition
Boris Vujčić, vice-president of the ECB, supplied the geopolitical context. "Europe is now in a situation where… it has to, of course, develop its own capabilities in the AI sphere. There has also been a lot of talk about sovereignty issues in the AI sphere. Europe has in the past shown it is capable of adapting new technologies…[to] lift productivity growth. [But] it has not always been at the frontier," he said. The data support his assessment. According to OECD figures, the European Union accounted for roughly 18% of global private AI investment in 2023, compared with 60% for the United States and 15% for China. The EU's flagship AI Act, which entered into force in August 2024, is the world's first comprehensive horizontal AI regulation, but it governs deployment rather than development. Frontier model training remains overwhelmingly concentrated in US labs.
This asymmetry creates a structural tension for European regulators. They are being asked to supervise systems they did not build, trained on data they do not control, running on infrastructure they do not own. The ECB's supervisory arm has begun asking significant institutions to disclose their use of third-party foundation models, but the legal basis for demanding access to model weights, training data or evaluation results remains unsettled. The AI Act's provisions on general-purpose AI models impose transparency obligations on providers, but enforcement falls to national market surveillance authorities that are still being stood up. The European Commission's AI Office, created to coordinate oversight of the most powerful models, has a staff of roughly 140, a fraction of the technical capacity available to the companies it regulates.
Agentic AI introduces novel failure modes
The specific concern uniting Lagarde, Breeden and Rathi is agentic AI: systems that can plan, execute and adapt multi-step tasks with minimal human oversight. In a financial context, this could mean an AI agent that monitors news feeds, constructs trading strategies, executes orders across venues, manages collateral and rebalances portfolios, all within risk limits set by a human but without step-by-step approval. The productivity gains are obvious. So are the failure modes. An agent that misinterprets a regulatory filing could trigger a cascade of erroneous trades across multiple asset classes before a human operator intervenes. If multiple firms deploy similar agents trained on overlapping data, correlated behaviour could amplify market moves, a dynamic familiar from the 2010 flash crash but potentially faster and harder to unwind.
Breeden's circuit-breaker proposal addresses the symptom, runaway automated trading, but not the root cause: the opacity of the decision logic inside the agent. Unlike traditional algorithmic trading, where rules are explicitly coded and can be audited, agentic systems may develop emergent strategies that their creators did not anticipate and cannot easily explain. This "black box" problem is compounded by the use of retrieval-augmented generation and tool-use frameworks that allow agents to call external APIs, query databases and execute code in real time. Regulators are only beginning to define what constitutes adequate testing, monitoring and kill-switch architecture for such systems.
Divergent regulatory tempos across the Channel
The UK's post-Brexit regulatory independence adds a layer of complexity. The FCA and Bank of England can move faster than the EU's co-legislative process, but they also face a smaller domestic market and the risk of regulatory arbitrage if UK rules diverge significantly from the AI Act. Rathi's call for collaborative oversight aligns with the UK government's "pro-innovation" AI white paper published in 2023, which favoured sectoral guidance over horizontal legislation. The EU, by contrast, has chosen a comprehensive regulatory framework with extraterritorial reach. Both approaches are being tested in real time. The FCA's sandbox for AI applications in financial services, launched in 2024, has attracted over 200 expressions of interest but only a handful of live pilots. The EU's AI Act sandboxing provisions are not yet operational.
Market participants are caught between the two regimes. A large European bank with a UK subsidiary must comply with the AI Act's risk classification, conformity assessment and post-market monitoring requirements for its EU operations, while simultaneously engaging with the FCA's supervisory expectations for its UK business. The cost of dual compliance is significant. Industry estimates suggest that implementing the AI Act's requirements for high-risk AI systems in credit scoring, insurance underwriting and algorithmic trading could add 5-15% to technology budgets for affected institutions. Smaller fintechs may lack the resources to navigate both regimes, potentially reducing competition in the very markets regulators seek to protect.
Productivity hopes collide with stability fears
Underlying the regulatory debate is Europe's stagnant productivity growth. Labour productivity per hour worked in the euro area grew at an average annual rate of 0.7% between 2010 and 2023, according to Eurostat, well below the 1.5% average in the United States. Policymakers see AI as a potential catalyst for closing that gap. The ECB's own research suggests that generative AI could add 0.2-0.4 percentage points to annual euro area productivity growth over the next decade, provided adoption is broad-based and complementary investments in skills and organisational change occur. But the same research notes that financial services, a sector where Europe has historically been strong, faces above-average disruption risk because many of its core activities (data processing, risk assessment, compliance) are highly susceptible to automation.
This creates a dilemma for central bankers. Encourage rapid adoption to boost productivity, and you may amplify the very stability risks they are mandated to contain. Restrict deployment until risks are fully understood, and you cede competitive ground to less cautious jurisdictions. Lagarde's Sintra remarks suggest the ECB is leaning toward a middle path: supervised experimentation with clear escalation triggers. The ECB's 2024-25 supervisory priorities include "digitalisation and emerging technologies" as a key risk driver, with on-site inspections planned for a sample of significant institutions' AI governance frameworks. The results, expected in early 2026, will inform the next iteration of the ECB's guide on internal models, which currently does not address AI-driven decision-making.
Sources
People mentioned
Nikhil Rathi
Sarah Breeden
Organisations
European Central Bank · Bank of England · Financial Conduct Authority · Financial Stability Board