Andreas Viljoen
Financial crises rarely begin with one self-contained weakness. They emerge when vulnerabilities connect: leverage meets a margin call; a margin call meets an illiquid market; falling prices meet common collateral; and a funding concern becomes a run. Before the event, each link may sit in a different spreadsheet, institution or jurisdiction. Afterwards, the route through them can look obvious. This post explores a possibility raised by advances in artificial intelligence (AI): that the financial system could become searchable, making more of those routes visible beforehand. It outlines two specific scenarios and their implications for financial authorities. First, system-wide testing by authorities should learn to search the way agents will. And consequential agent decisions and actions should be observable in operation, unlike today.
Cyber security offers a preview of this capability. In April, the UK’s AI Security Institute reported that a frontier model had, for the first time, completed a simulated 32-step corporate network attack end to end, chaining individually modest vulnerabilities in the code base into a route to full network takeover. Commentators dubbed this the ‘Mythos moment’ after the Anthropic model that first completed the simulation. The lesson was composition rather than any single flaw. Weaknesses tolerable in isolation become critical when something can search across and connect them. This post asks what happens when the terrain across which those actions are chained is not a computer network but a financial network.
Scenario one: finding a route through the system
Imagine a powerful agent deployed by a trading firm to find mispriced assets. Its objective sounds familiar: use lawful information to identify profitable opportunities within specified limits.
The agent reads filings and earnings calls, but does not stop there. It compares banks’ funding profiles, fund mandates, collateral eligibility, margin schedules, payment cut-off times, short positions and the speed at which different groups respond to news. Human teams already analyse each category. What changes is the breadth with which an agent could hold them together, how many candidate routes it could search, and how fast it could update the map. To do this it needn’t have access to every balance sheet or contract in the system – the question is whether it can combine enough fragmented information to infer connections that others have not recognised.
Suppose it finds this route. A bank has depositors who may react quickly to bad news. Its readily saleable assets overlap with those of leveraged funds. A modest fall in those assets would trigger margin calls, forcing sales into a shallow market. Lower prices would reduce collateral values elsewhere, prompting higher haircuts and counterparty retreat. The bank is not insolvent at the start and the funds do not look unusually risky in isolation. The fragility lies in the connection.
An agent might simply recommend trades that profit if an unrelated shock exposes the route. More concerningly, it could learn to adjust small positions or public signals, observe the response, and update its estimate of which link matters most. A poorly controlled agent might take such steps because they serve its commercial objective, even if nobody asks it to destabilise anything.
If stress arrives, the pathway could run quickly:
funding concern → withdrawals → asset sales → price falls → margin calls → further sales → tighter haircuts → wider counterparty caution.
Authorities already study runs, fire sales, margin spirals and contagion. What advanced AI adds is the capacity to combine these mechanisms in a cross-domain model, search many possible pathways, learn from feedback and adapt as other participants respond. What was once an artisanal exercise in financial reconnaissance could become cheap, broad and persistent.
This extends an observation in Daníelsson, Macrae and Uthemann’s work on AI and systemic risk: an advanced system might not merely optimise within financial rules, but against the system that created them. Recent Bank work considers how agents could accelerate contagion after a shock. The possibility here is that an agent first discovers the route the shock will take.
Scenario two: creating a route nobody can see
The first scenario discovers a transmission channel that already exists. The second creates one.
Imagine a financial group using an agent to improve return on capital while respecting every limit it has been given. Regulatory arbitrage long predates AI; the difference is combinatorial reach. Searching across legal entities, contracts, accounting treatments and jurisdictions, an agent might find that an exposure can be split among derivatives, repo, collateral transformations and affiliated vehicles so that every component looks modest. Economic exposure moves without appearing in the same place as accounting leverage, and each counterparty and authority sees only part of the structure.
The interesting case need not involve a breach of any individual rule. The agent may be unusually good at formal compliance, satisfying each constraint it was given while weakening the purpose those constraints collectively serve. Human reviewers approve the parts without reconstructing the economic exposure as a whole.
When volatility rises, apparently separate positions may demand the same collateral at the same time:
distributed leverage → common collateral demand → margin calls → asset liquidation → lower collateral values → further calls.
Firms are unlikely to remain passive. They may use equally capable agents to test transactions, monitor exposures and challenge structures proposed by other systems. That could reduce risk. But it does not remove the co-ordination problem: each firm’s defensive agent may still see only its own data and counterparties, while the relevant exposure is distributed across the system. Authorities’ comparative advantage is the ability to examine connections across institutions and markets.
It is worth recognising that this remains a scenario rather than a forecast. Today’s models are unreliable, and firms remain responsible for the systems they deploy. But an agent need not understand the wider consequences of a structure to discover it. The concern is therefore not necessarily malicious intent or even a failure of formal compliance. It is that commercial optimisation across fragmented rules and oversight could produce aggregate exposures that no participant can see in full.
Searchability should run both ways
If frontier AI can make the system more searchable for private actors, it can also make it more searchable for authorities. That is how cyber defenders answered the Mythos moment – the model behind it was pointed first at defence, scanning critical software to find and fix flaws before attackers could reach them.
Central banks can combine information that no individual firm sees. The Bank’s system-wide exploratory scenario already tests how individually rational actions interact under stress. One extension is AI-assisted financial red teaming: giving controlled agents access to secure, system-wide data and asking them to search for plausible routes through leverage, liquidity, collateral and operational dependencies.
This is more than asking a chatbot for a list of risks. Agents would operate in a simulation, other agents would respond, and strategies would adapt. Early building blocks exist. Project Logos, a BIS Innovation Hub collaboration with the Bank and the Bundesbank, is developing a simulated market environment for observing how LLM-based agents behave.
Require observability, not just explanations
Pre-deployment testing is only part of the answer. Firms and authorities must also be able to reconstruct what important agents did in operation. Yet firms may receive only summaries or protected artefacts from model providers, rather than the underlying information needed to audit a model’s actions.
Raw reasoning traces are neither complete nor conclusive, and intuitive explanations can create false confidence. But appropriate reasoning and action telemetry logs could still provide evidence of an agent’s intermediate decisions, tool use and actions, as noted in the Financial Stability Board’s 2026 consultation on responsible AI.
The unresolved supervisory questions are at both the firm and system level, starting with the appropriate explanatory information needed at each. At firm level, supervisors may need assurance that material agents are subject to appropriate access controls, testing, human oversight and auditable records. At system level, authorities may need mechanisms for identifying common models, strategies or dependencies across firms, conducting co-ordinated stress exercises, and obtaining consistent information following an incident. The immediate could be to preserve the information needed to assess whether more substantive measures are warranted.
Looking for the chain before it is pulled
The financial system has always been searchable in a limited sense. Investors hunt for mispricing, firms optimise around rules and supervisors map vulnerabilities. Frontier AI could change the scale and nature of that search, connecting facts scattered across disciplines and institutions, exploring more possible routes and adapting at machine speed as conditions change. The scenarios in this post are conditional, not forecasts, but financial stability policy must consider new capabilities before their effects become visible in historical data.
Searchability should therefore run both ways. Firms should control agents’ access and actions, test material uses and retain records sufficient to reconstruct consequential decisions. Authorities should explore AI-assisted system-wide stress testing, examine common dependencies and establish consistent expectations for incident reporting and auditability.
If the financial system is becoming searchable, defenders must be able to read the map.
Andreas Viljoen works in the Bank’s Policy and Strategy Division, International Directorate.
If you want to get in touch, please email us at bankunderground@bankofengland.co.uk or leave a comment below.
Comments will only appear once approved by a moderator, and are only published where a full name is supplied. Bank Underground is a blog for Bank of England staff to share views that challenge – or support – prevailing policy orthodoxies. The views expressed here are those of the authors, and are not necessarily those of the Bank of England, or its policy committees.
Share the post “When the financial system becomes searchable”
