Europe's financial sector faces a serious structural vulnerability. The three European Supervisory Authorities (ESAs) have warned that the EU's growing reliance on non-European cloud services, data centers, and AI models risks amplifying geopolitical shocks and multiplying operational failures across banks, insurers, and investment funds. The warning appeared in their latest periodic risk update, published jointly by EBA, EIOPA, and ESMA.
Geopolitical Tensions Enter Financial Risk Calculations
In the ESAs' own words, published in their joint risk assessment: “The strong exposure of the European financial sector to digital infrastructure and service providers from outside the continent, particularly cloud computing services, data centers, and artificial intelligence models, seriously risks amplifying the impact of geopolitical shocks and multiplying operational disruptions.”
The authorities pointing this out are not minor players. The ESAs, short for European Supervisory Authorities, comprise three institutions: EBA (the European Banking Authority), EIOPA (which oversees insurance and pension funds), and ESMA (the European Securities and Markets Authority). When all three speak in unison about a systemic risk, Brusssels tends to pay attention.
US tech giants are the implicit target. These are the same companies whose AI divisions are pushing the Nasdaq to record highs, precisely because European financial institutions are among their most committed customers. The dependency goes both ways: European finance funds American tech, and American tech runs European finance.
In their joint analysis, cloud platforms, data centers, and AI models developed outside the European Economic Area are identified as potential risk multipliers for banks, insurers, and fund managers across the EU. The concern is not theoretical: operational concentration in a handful of non-EU vendors creates a single point of failure that crosses national borders.
Cloud Concentration: The Specific Threat ESMA and EBA Identify
Cloud services, in this context, means the infrastructure that allows banks, insurers, and asset managers to store data and run applications on remote servers. The problem the ESAs flag is concentration: most of these services are controlled by a small number of large technology groups, none of them European.
Should geopolitical tensions escalate further, or a major technology outage occur, the risk index could rise sharply and fast. A political dispute between the US and EU, a sanctions regime, or a cyberattack on a non-European provider could simultaneously affect thousands of European financial institutions with no local fallback.
These concerns are not new. The Governor of the Bank of England raised similar warnings several weeks ago, flagging AI-related systemic risk to global finance. In Washington, Senator Bernie Sanders introduced legislation to slow AI development, though the bill's prospects remain dim given the Trump administration's explicit policy of non-interference in the AI sector.
What Could Actually Go Wrong
The ESAs frame their concern around what they call a “possibilistic” reasoning: not a certainty, but a plausible chain of events. The authorities acknowledge that cyber threats from hostile states and terrorist actors have been on the radar for years. What has changed is the geopolitical backdrop, which has become considerably less stable.
A political or economic shock between major world regions could now translate far more easily into operational disruptions for European financial firms, precisely because their critical digital infrastructure sits abroad or is controlled by operators outside the continent. There is no quick domestic alternative to switch to.
At the core of the ESAs' concern is the rapid growth of AI models embedded in financial operations: tools for data analysis, risk management, and process automation. These systems are becoming more powerful at speed. And as their complexity increases, so does the attack surface they present.
More Technology Means More Entry Points for Attackers
More connected systems and larger volumes of processed data mean more potential entry points for hacking and cyberattacks. Each new technology layer introduced into a financial institution's stack creates a potential new breach point for malicious actors to exploit.
The ESAs do not call for a wholesale reversal of digital transformation. What they urge, repeatedly, is sustained vigilance: tighter oversight of third-party digital dependencies, clearer contingency planning, and a regulatory framework that treats foreign AI and cloud exposure as a systemic risk category in its own right.
For European investors and financial institutions operating under MiCA and DORA (the Digital Operational Resilience Act, which entered into force in January 2025), the ESA warning adds political weight to compliance obligations already on the books. DORA specifically requires financial entities to stress-test their ICT third-party dependencies, including cloud and AI providers. The ESAs are effectively saying that stress tests alone may not be enough if the geopolitical environment deteriorates further. Regulatory watchers should track how EBA, EIOPA, and ESMA translate this warning into supervisory guidance over the coming months.


