Invest1 publisher3 min readPublished
EU supervisors rank foreign dependence ahead of a private credit book at 0.6% of bank assets
The Joint Committee of the EBA, EIOPA and ESMA handed EU governments an autumn risk update that puts reliance on non-EU ICT, clearing, ratings and foreign-currency funding at the top, with AI-enabled attacks and quantum next.
The Investor · Invest desk

What happened
- The Joint Committee of the European Banking Authority, EIOPA and ESMA gave its autumn risk findings to the Financial Stability Table of the EU's Economic and Financial Committee on 10 September 2026.
- The three authorities also named AI-enabled cyberattacks and quantum computing as growing threats to the bloc's banks, funds and insurers.
- ENISA's own 2026 threat report logs more than 48,000 new vulnerabilities in 2025, a 22% increase, and says threat groups are using AI more in their operations.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction Only the third-ranked risk arrives with a denominator, at 0.6% of bank assets, so a risk officer allocating attention by measured size would work the register from the bottom up.
- decision Boards choose between funding migration off non-EU suppliers now at their own cost and waiting for a supervisory expectation, given that the ESAs call the system stable and ask for preparation.
- precedent The dates governing crypto's quantum migration are being set by protocol developers, so EU firms holding those assets inherit a schedule their supervisors did not write.
The Joint Committee's list divides by what a bank can change under contract. ICT suppliers and payment systems sitting outside the European Economic Area are contracts [5]. Clearing, repo and credit ratings routed through non-EU firms are contracts too [6]. Those can be re-tendered, assuming a counterparty inside the EEA exists and somebody funds the migration. The funding gaps are in dollars, sterling and Swiss francs, currencies the euro area does not issue [5].
The large U.S. exposures in equity UCITS funds and alternative investment funds are a portfolio position, closed by selling [4]. The authorities' stated worry across all of it is that EU firms end up subject to foreign regulatory regimes and political events they cannot control [7].
One item on the register has a denominator. Banks in the EU and EEA hold private credit exposures worth 0.6% of total assets, which the ESAs put third, behind the dependence problem and the technology threats, and flagged because the market is growing fast and is not very transparent [16]. The ESAs did not quantify the dependence items they ranked above it. A complete write-off of the private credit book costs 60 basis points of assets [5].
The cyber number is larger and looser. ENISA's 2026 threat report logs more than 48,000 new vulnerabilities in 2025, a 22% jump [11], which implies about 39,300 the year before and roughly 8,700 more to triage [1][2], or about 131 a day [3]. The ESAs said frontier AI models can find and exploit software weaknesses very quickly and easily, and that this raises the potential damage of AI-assisted attacks [9].
Quantum is the item with dates attached, and the protocol developers are setting them. Google Quantum AI researchers estimated in March that a machine able to break the cryptography behind many cryptocurrencies might need roughly 20 times fewer physical qubits than once thought [13], and no such machine exists [12]. Bitcoin's Jameson Lopp and five collaborators proposed in February to retire the network's current signature scheme [14]. The Ethereum Foundation is aiming for quantum resistance by December 2029 [15], about 39 months after the committee handed its findings over [4].
The dependence item is the one I would expect to generate supervisory work. AI attacks and quantum both need an event to arrive; the ICT contracts, the clearing routes and the dollar funding gaps are in place now [5][6][12]. The counter-thesis is inside the update. The ESAs said the system remains stable for now and asked institutions to prepare for emerging technology risks [10]. A bank can comply with that by writing a paper.
Migrating off a non-EU clearing or ratings relationship comes out of the same change budget as everything else the institution has queued, and so far the ask is preparation [10]. If next autumn's update repeats the dependence language with no data collection and no supervisory expectation attached, the sovereignty framing was rhetoric. That would leave the 0.6% private credit exposure as the only quantified risk on the register [16].
What to watch
- Whether the ESAs' next risk update attaches a data collection or supervisory expectation to the non-EU dependence language.
- Whether EU and EEA banks' private credit exposures move materially above 0.6% of total assets.
- Whether the Ethereum Foundation holds its December 2029 quantum-resistance target.