Summary
- ESMA says stretched technology valuations and deteriorating macroeconomic conditions leave European markets vulnerable to an abrupt correction.
- Frontier AI is adding to operational risk as attackers gain more capable tools for identifying and exploiting cyber weaknesses.
- AI investment, tokenisation, decentralised finance, crypto links, and quantum funding are moving technology deeper into mainstream financial supervision.
Cybersecurity and frontier artificial intelligence are moving deeper into European financial-market supervision, with the European Securities and Markets Authority warning that operational risks are rising while technology-heavy asset valuations remain exposed to a sudden change in investor sentiment.
ESMA’s second risk-monitoring report of 2026 describes markets that have remained resilient despite geopolitical conflict, energy pressure, persistent inflation, and weaker economic growth, although strong performance in technology and AI-related sectors has helped investor optimism and valuations recover quickly.
That resilience is creating two different forms of technology exposure. Highly valued AI and technology assets could amplify a market correction if expectations weaken, while increasingly capable AI systems are changing the operational threat faced by exchanges, financial institutions, infrastructure providers, and the technology companies supporting them.
Financial markets already depend on dense networks of exchanges, clearing houses, settlement systems, cloud providers, identity services, data suppliers, communications networks, and software platforms. Vulnerabilities in a widely used technology supplier can therefore reach organisations that appear commercially separate, turning supplier concentration into a potential market-resilience issue.
ESMA describes operational risk as very high and points to the changing cyber landscape as frontier AI makes vulnerability discovery and exploitation more capable. The concern is not limited to AI-generated phishing or malicious code; more capable automation can reduce the cost of reconnaissance and adaptation while financial institutions continue consolidating workloads around shared cloud and software infrastructure.
The assessment follows a wider regulatory shift towards treating technology dependency as part of financial stability rather than simply an IT-management issue. Techopia recently examined the Financial Stability Board’s warning that frontier AI could accelerate systemic cyber disruption, particularly when common suppliers create correlated exposure across institutions.
European financial regulation already reflects some of that thinking through the Digital Operational Resilience Act, which places more explicit requirements on financial organisations and important third-party technology providers. ESMA’s latest analysis shows why compliance with one resilience framework does not settle the underlying problem when new technologies alter both the threat environment and the structure of financial markets.
Technology enters both sides of the risk ledger
Artificial intelligence is also appearing as an investment theme. ESMA says investment continues to expand through AI-focused funds, particularly those targeting infrastructure, while stretched technology valuations remain an important contributor to wider market optimism.
That creates an unusual feedback loop because AI can simultaneously be an asset attracting capital, a tool used inside financial organisations, and an operational risk affecting the infrastructure on which markets depend. Different institutions can therefore be exposed to the same technology trend through entirely different channels.
A bank may use models for software development or fraud analysis, an asset manager may hold companies benefiting from AI spending, an exchange may depend on shared cloud infrastructure, and a clearing house may rely on external technology suppliers. None of those exposures is identical, but a serious disruption can connect them more quickly than organisational charts imply.
Other forms of digital finance are widening the supervisory agenda. ESMA says tokenised equities remain at an early stage but are gaining momentum, while recent decentralised-finance exploits have renewed concerns about interconnectedness and spillovers. Crypto markets are also becoming more connected with traditional finance, increasing the number of routes through which stress can move beyond the original asset class.
Prediction markets present another challenge because platforms offering event-linked contracts can sit uncomfortably between derivatives, gambling, and information markets depending on their structure and jurisdiction. Digital distribution and blockchain settlement make those boundaries harder to enforce consistently, while insider knowledge and manipulation create familiar market-abuse problems in a newer format.
Quantum computing is further from widespread commercial deployment, but capital is already being allocated around the technology. ESMA says global and European quantum startup funding reached record levels in 2025, meaning financial markets are pricing future computing capability long before the technology’s eventual economic and cybersecurity impact can be known with confidence.
Combining those developments into a single category of “innovation” would obscure their differences. Tokenisation changes market plumbing, frontier AI affects operations and asset valuations, decentralised finance alters intermediation, and quantum computing raises a longer-term challenge around cryptography and investment expectations.
The common thread is that technology decisions once handled largely within technology departments are becoming visible in market structure, valuation, operational resilience, and prudential oversight. Regulators increasingly need to understand not only whether individual institutions operate safely, but whether many organisations depend on the same suppliers, models, infrastructure, or assumptions.
That becomes harder when innovation and concentration develop together. Shared cloud platforms and common enterprise software can lower costs and improve capability across financial services, but they also mean a smaller number of technology failures can affect a larger proportion of the market at once.
Traditional financial resilience will continue to revolve around capital, liquidity, settlement, leverage, and counterparty exposure. ESMA’s latest report does not displace those concerns, but it shows that software dependency, cyber threats, and technology-driven asset cycles are becoming sufficiently important to sit alongside them rather than in a separate technology-risk annex.












