pancucci.pro

Your AI concentration risk is not in your ICT register. It is on your balance sheet. Three times.

How financial institutions became exposed to the same risk factor through three different books, supervised by three different frameworks, none of which adds them up.

Contents
  1. The week the ratings caught up
  2. The AI loop: financing it, running on it, insuring it
  3. Book one: the assets
  4. Book two: the operations
  5. Book three: the liabilities
  6. Three ledgers, one risk factor
  7. Only AI fills all three books
  8. What a board should ask
  9. The deadline moved. The exposure did not.

Views are my own. All figures are public and sourced; they belong to different classes (funded debt, commitments, contingent guarantees, stocks, flows) and are deliberately never added into a single total.

The week the ratings caught up

In the space of five days at the end of July, four things happened that would each have been a headline on their own. Moody’s warned that “unprecedented” AI spending now threatens the credit quality of the six hyperscalers it tracks, whose lease commitments have reached $1.2 trillion, more than $820 billion of it on leases that have not even started. Fitch published a report titled “AI market correction emerging as major credit risk” and filed it, tellingly, under its banking research. The Wall Street Journal reported that Nvidia is in talks to provide roughly $250 billion in guarantees so that OpenAI’s Ohio campus can raise debt against Nvidia’s balance sheet rather than its own, since OpenAI holds no investment-grade rating. And credit default swaps on Nvidia recorded their largest intraday move since they began trading actively, according to ICE Data Services.

2026: the supervisory and rating convergence, in real time. In red, the final week.
Chart. 2026: the supervisory and rating convergence, in real time. In red, the final week.

None of this, by itself, tells the board of a bank or an insurer what to do. The question that matters inside a regulated institution is more precise: where, exactly, does this risk sit in our books? I spent the last decade running technology and operations inside a Central Bank of Ireland regulated global reinsurer, holding PCF-42 approval and sitting on its Audit and Risk Committee, and I have come to an uncomfortable answer. It sits in three places at once. And no framework, in any jurisdiction, adds the three together.

The AI loop: financing it, running on it, insuring it

Financial institutions relate to the AI complex in three distinct capacities. They finance it, as lenders, bondholders and investors. They run on it, as customers of the same cloud and model providers. And they insure it, as underwriters of the physical and financial risks of its infrastructure. Each relationship lives in a different book: the asset side, the operational estate, the technical liabilities. Each book has its own supervisory framework. Herein lies the problem, because the risk factor underneath all three is the same one: the monetisation of artificial intelligence.

Book one: the assets

Follow the financing chain from the top. Banks arrange and syndicate the mega-loans: a $40 billion bridge loan to SoftBank, underwritten by JPMorgan, Goldman Sachs, Mizuho, SMBC and MUFG, with $30 billion of it earmarked for SoftBank’s investment in OpenAI; a record $38 billion construction package, led by JPMorgan and MUFG, funds the Oracle-linked Stargate sites in Texas and Wisconsin. Nor does the risk stay with the banks: the Financial Times has reported JPMorgan, Morgan Stanley and SMBC offloading data-centre exposure through significant risk transfers as internal limits approach. And the chain is global by construction: Mizuho, SMBC and MUFG underwrite the SoftBank bridge alongside their US peers, and MUFG co-leads the Stargate package with JPMorgan. Japan’s life insurers sit naturally downstream three times over: through the US credit stock built in the ultra-low-yield decades, through new allocations steered toward private credit as surging FX hedging costs made hedged public bonds unattractive, and, structurally, through the US life platforms they own outright: Nippon Life’s Resolution Life alone holds $20 billion of private credit, four times its parent’s standalone book. The centre of gravity migrates to private credit, where Blue Owl, PIMCO, Apollo and Blackstone have taken outstanding loans to AI-linked companies from roughly zero to more than $200 billion in a few years, with Morgan Stanley projecting a further $800 billion of data-centre financing from the sector over the next two years.

Where the banks and funds are: selected AI-complex debt instruments. Debt actually raised or issued; not additive with guarantees, commitments or equity.
Chart. Where the banks and funds are: selected AI-complex debt instruments. Debt actually raised or issued; not additive with guarantees, commitments or equity.

And from private credit, the risk reaches its final holders. Meta’s Hyperion campus in Louisiana is the prototype: an SPV, 80% owned by Blue Owl funds, issued $27 billion of debt anchored by PIMCO, rated A+ by S&P, maturing in 2049. Meta keeps operational control through a leaseback and keeps the debt off its balance sheet; life insurers and pension funds keep the bonds. This is not an anomaly, it is a rotation: private placements have grown from 18.3% to 23.4% of US life insurers’ admitted bonds since 2021, and a Federal Reserve study puts roughly $1 trillion of private credit inside the major life insurers. New York and Pennsylvania state pension plans are investors in the same $7 billion Blue Owl digital infrastructure fund that sits behind these structures. An AI shock enters the system as a language-model problem and lands in a mathematical reserve.

The transmission chain: how AI risk reaches the saver.
Chart. The transmission chain: how AI risk reaches the saver.

Book two: the operations

The second exposure needs less introduction, because Europe has already given it a name. Under DORA, the European Supervisory Authorities designated in November 2025 the first 19 critical ICT third-party providers on which financial institutions structurally depend, and the register, the exit strategies and the oversight regime exist precisely because the institutions run on this infrastructure. The UK has legislated its twin in the Critical Third Parties regime, and made its first four designations in July: AWS, Google Cloud, Microsoft, and Oracle itself; Australia has CPS 230; in the United States the same concern is scattered across agency guidance. This is real supervisory progress, and I have argued in a previous article that the foundations it demands are exactly where AI readiness is won. But notice what the register measures: it measures what happens if the provider stops. It does not measure what happens if the provider fails commercially while your investment portfolio holds its debt and your underwriting book covers its campuses. And this is not hypothetical: Oracle sits on the ESAs’ first CTPP list, and Oracle is the issuer that S&P and Moody’s have placed on negative watch, with credit default swaps at a sixteen-year high. The critical provider in your register and the stressed name in your portfolio are, in at least one case, the same company, seen by two systems that do not speak.

Book three: the liabilities

The third exposure belongs to my industry. Munich Re now describes single data-centre campuses carrying insured values up to $20 billion, and Swiss Re Institute estimates that their footprint is anything but neutral: more than a quarter of US capacity could sit in frequent large-hail zones and around 40% in significant tornado zones. Swiss Re expects data-centre premiums to more than double to $24 billion by 2030, and warns that large campuses reach insurers fragmented across separate programmes for buildings, equipment and power, so that a single event crosses several of them at once. Delay is the largest loss driver, and here the loop closes on itself: Munich Re lists “contractor financial reliability” among the critical underwriting factors. Read that phrase with the financing map in hand. The financial fragility of the chain that builds these assets, the same fragility Moody’s and Fitch flagged last week, is itself an insurable event on the liability side. The sector is underwriting the physical risk of an asset class it increasingly holds on its own asset side, while adopting the technology those assets produce.

Three ledgers, one risk factor

Three ledgers, three frameworks. Nothing sums across them.
Chart. Three ledgers, three frameworks. Nothing sums across them.

Now put the three books side by side and ask who adds them up. Prudential frameworks, Solvency II in Europe and the NAIC regime in the United States, see the asset side, and they measure concentration by issuer. DORA and its siblings see the operational side, and they measure resilience by provider. Accumulation control sees the underwriting side, and it measures exposure by event. Each framework is competent within its book. None aggregates exposure to the AI factor across the three, inside a single institution or across the system. The honest caveat is that a container for the sum already exists: the ORSA in insurance and the ICAAP in banking ask precisely for an own view of all material risks. And the questions have started arriving, one book at a time: the Bank of England has begun stress testing banks’ private-market exposures, flagging lending to AI companies as a contagion channel; the PRA’s 2026 supervisory priorities put AI adoption and third-party model concentration on the dialogue agenda; EIOPA has put a potential AI bubble on its scenario-preparedness list. Each question lands in one book. Nobody is yet asked for the sum. The closest anyone has come: AM Best noted in June that insurers with private-credit exposure to data-centre projects face asset-side risks alongside the underwriting opportunity, one sentence inside a sector report. The FSB, for its part, has acknowledged that for existing policy frameworks, “more work may be needed” for them to be sufficiently comprehensive. I would put it less diplomatically: issuer diversification is real, factor diversification is not. Meta, Oracle, CoreWeave, a Blue Owl fund and an Alphabet bond are different structures, carrying very different risk, built on the same underlying factor: the monetisation of artificial intelligence. And a portion of the collateral, GPUs with an economic life of a few years, has no actuarial precedent as security for debt maturing in 2049.

If this architecture sounds familiar, it should. In 2008, exposures to structured credit were spread across banking books, trading books, off-balance-sheet vehicles and liquidity lines, each under its own radar, and the correlation stayed invisible until it manifested everywhere at once. The uncomfortable lesson of that episode was not about junk: it was the AAA rating that carried the risk into regulated balance sheets. Apparent quality is not the mitigation of concentration risk. It is its vector.

Only AI fills all three books

Emerging technologies and the three books: only AI fills them all. Telecom leveraged one book and cost a trillion. Crypto was fenced out of all three, and its crash was absorbed.
Chart. Emerging technologies and the three books: only AI fills them all. Telecom leveraged one book and cost a trillion. Crypto was fenced out of all three, and its crash was absorbed.

The obvious objection deserves a direct answer: technology bubbles come and go, and finance has survived them. True, but look at which books they occupied. The telecom bubble leveraged exactly one book. Vendor financing existed, Lucent committed $8 billion, Nortel $3 billion, Cisco $2.4 billion, and when it ended, the industry owed a trillion dollars “much of which will never be repaid”, as the FCC chairman told the US Senate in 2002, with bondholders recovering roughly twenty cents. Painful, but visible, rated as ordinary corporate credit, and contained to one book. Nvidia alone is now discussing guarantee and financing vehicles of $250 billion and $350 billion, more than forty times the disclosed vendor financing of the entire telecom equipment industry at its peak, in nominal terms.

Crypto is the control group. Regulators fenced it out of all three books before the crash: Basel’s SCO60 standard assigns a 1,250% risk weight to unbacked cryptoassets, capital dollar for dollar, with exposure capped near 1% of Tier 1; banks and insurers did not run their operations on it; underwriting stayed marginal. By the time FTX collapsed, at the end of a slide that had erased some two trillion dollars of crypto market value from the 2021 peak, the academic evidence is consistent: no contagion to traditional finance. The fence worked. Which makes the asymmetry the single most striking regulatory fact of this cycle: the same prudential system that prices bitcoin at 1,250% welcomes AI data-centre SPV debt at A+, precisely the long-dated, amortising paper that matching adjustment portfolios are built from, with no concentration limit on the factor. Crypto was too ugly to be dangerous. AI is beautiful enough to be everywhere. And the strength of today’s borrowers, the most solid corporate balance sheets in history, is not a rebuttal of this argument; it is the mechanism of it. Nobody fences what looks safe. Ask 2008.

What a board should ask

If I were sitting on your risk committee, these are the five questions I would want answered before the next quarterly cycle. One: what is our aggregate exposure to the AI factor across investments, operations and underwriting, and who owns that single number? Two: if our A+ rated data-centre debt were assessed on the factor rather than the structure, would our concentration limits even notice? Three: which stress scenario runs across all three books simultaneously, and when did we last run it? Four: how does GPU-backed and technology-obsolescence-exposed collateral behave in a run-off, and on whose model? Five: if a critical AI provider failed commercially rather than operationally, which of our three frameworks would catch it first, and would the other two find out before the market did?

None of these questions requires new regulation to answer. They require only that someone in the institution be given the mandate to add three numbers that today live in three different rooms.

The deadline moved. The exposure did not.

This is the third piece in a sequence. The first argued that the AI Act’s new December 2027 deadline changes the calendar but not the supervisory expectations, and that readiness is built on unglamorous foundations. The second argued that IT has taken the driver’s seat of the business, with regulation climbing in next to it. This one completes the picture from the balance-sheet side: while we were building registers and readiness, the exposure quietly built itself, three times over. The institutions that will navigate the next phase well are not the ones predicting whether the AI cycle ends in triumph or in correction. They are the ones that can answer, today, a question their supervisor has not yet asked but inevitably will: what is your total exposure to this factor? The deadline moved. The exposure did not.

Sources: Bloomberg (7 Oct 2025; Bloomberg Graphics, Jan 2026; 27 Jul 2026), Wall Street Journal, Moody’s Ratings (Feb and 23 Jul 2026), Fitch Ratings (27 Jul 2026), Federal Reserve, NAIC and Forbes, AM Best, FSB (Nov 2024, May and Jun 2026), Meta Investor Relations, GIC, McKinsey, Bain, Munich Re, Swiss Re Institute, BCBS SCO60, FCC Senate testimony (2002). Full references available on request.

This is the edition of record of the article first published on LinkedIn on 10 August 2026.

Updated 27 September: the hail and tornado shares in Book three are now attributed to Swiss Re Institute (sigma insights 07/2026), which published them.