The European Supervisory Authorities have published their Autumn 2026 risk update, identifying reliance on non-EU providers and infrastructure, technology related threats and private credit as key vulnerabilities for the EU financial system. The system remains resilient, with strong bank capital and profitability, sound insurer fundamentals and stable investment funds, but cyber and fraud risks are rising and asset quality is expected to weaken in some commercial real estate and small and medium sized enterprise portfolios. Concentrated dependence on non-European Economic Area ICT providers, payment systems and financial infrastructure could amplify geopolitical and operational shocks. Advanced artificial intelligence could enable faster and more powerful cyberattacks, while quantum computing may undermine widely used cryptography before commercially viable applications emerge. Private credit remains relatively small in the EU but is growing rapidly. EU and EEA bank exposures to private credit funds and related asset managers reached nearly EUR 150 billion, or 0.6% of total assets, in June 2025, with risks arising from opaque valuations, uncertain leverage, liquidity mismatches and links to the larger U.S. market. The authorities called on supervisors and financial institutions to strengthen geopolitical scenario analysis, crisis preparedness and resolution coordination. They also recommended closer monitoring and stress testing of non-EEA and private credit exposures, continued oversight of concentrated technology dependencies, robust valuation practices and early preparation for risks from artificial intelligence and quantum computing.
2026-09-23European Banking Authority
European Supervisory Authorities identify external dependencies, cyber threats and private credit as key EU financial vulnerabilities
The European Supervisory Authorities identified non-EU dependencies, cyber and emerging technology threats, and private credit as key vulnerabilities, while assessing the EU financial system as resilient overall. They called for stronger crisis preparedness, monitoring and stress testing of external and private credit exposures, and early action on risks from artificial intelligence and quantum computing.