Correlated Risk: The AI Concentration Problem the Central Banks Are Really Warning About

This month the world’s most sober financial institutions said something startling in the flattest possible language. The Bank of England, in its latest Financial Stability Report, judged that AI-related equity valuations are close to the most stretched they’ve been since the dot-com bubble in the US, and since the 2008 crisis in the UK, and warned that a sharp correction could knock as much as 2.2 percentage points off British GDP. The Bank for International Settlements (BIS), the central bank for central banks, went further, drawing an explicit line from today’s roughly trillion-dollar AI spending spree back through the dot-com crash, the railway mania of the 1840s, and the roaring twenties before the Depression. When the institutions whose entire job is to be boring start invoking 1929, it’s worth putting down the hype for a moment and reading what they actually said.

And here is the thing most of the coverage got wrong. It turned this into another round of the question everyone’s already sick of: is the AI bubble about to pop? That’s the wrong question, or at least it’s the question you can’t do anything useful with. Nobody can reliably time a correction, not Michael Burry, not the Bank of England, not me. If you read these reports as a market-timing call, you’ll either panic or dismiss them, and both are mistakes. Read properly, they are not really about whether the bubble bursts. They are about how the whole thing is wired, and the wiring is a risk story a security person recognises instantly, because it’s the same failure mode we’ve spent years learning to fear in every other system.

The danger isn’t the height of valuations. It’s the correlation.

Every bubble commentary fixates on how high valuations have climbed, as if the only question were the size of the drop. But the BoE report keeps returning to a different and more revealing word: concentration. Correlated, momentum-driven positions. Herding behaviour. The worry that “if many firms rely on the same models, the same data sources, or very similar system designs, they may react in similar ways when conditions change.”

Sit with that sentence, because it is not a markets observation. It is a systems-resilience observation, and it describes the exact vulnerability that defines modern catastrophic risk. A security engineer doesn’t ask only “how valuable is this asset.” They ask “what happens to everything else when this one thing fails.” A system where every participant runs the same model, on the same handful of cloud providers, holding the same positions, funded through the same channels, is not a diverse market that can absorb a shock by having some players zig while others zag. It is a monoculture. And a monoculture doesn’t correct; it cascades. In calm weather, everyone doing the same efficient thing looks like efficiency. In a storm, everyone doing the same thing at the same time is a stampede toward the same exit.

We already know this pattern from cyber security, and it’s worth naming the parallel because it’s exact. When everyone runs the same operating system, one vulnerability compromises everyone. When everyone depends on the same cloud region, one outage takes down half the internet. Concentration converts a local failure into a systemic one. The central banks are describing the financial version of a shared software dependency, and warning that we’ve built the global economy on top of it.

The wiring is worse than the height, and more hidden

The BIS put its finger on the part that should genuinely unsettle you, and it isn’t the valuations. It’s what it called the opacity of AI-sector financing, and the phrase to learn is “circular financing.” The relationships binding the AI economy together have become a tangle in which the same firms are, simultaneously, each other’s investors, customers, and counterparties. A cloud provider funds an AI startup that commits to buy that provider’s computing power. A chipmaker extends favourable terms backed by expected future demand that its own customers’ spending is supposed to create. Money flows in loops, and each loop makes the reported numbers look stronger while quietly increasing how tightly every player is bound to every other.

For a security mind, this is a familiar and alarming shape. It is a densely interconnected system with hidden dependencies, where you cannot see, from the outside, where the load actually rests or what fails if one node goes. The BIS warns that if the biggest spenders slow down even a little, “many borrowers across the supply chain could struggle to replace lost revenue and service their debt,” and that the opacity “compounds these vulnerabilities.” Translated out of central-bank prose: nobody, possibly not even the participants, can fully map what brings down what. That is not a description of an overpriced market. It is a description of an unauditable one, and unauditable interconnection is precisely the condition in which a small, local problem becomes a large, systemic surprise.

Why this lands on your desk even if the boom pays off

Here’s the point I want to leave you with, and it’s the reason this matters to a security or operational leader rather than only to a fund manager. The concentration risk is real <em>whether or not the bubble ever bursts</em>. Even in the optimistic world where AI delivers everything promised and the valuations turn out justified, you are still operating in an economy, and probably an organisation, that has quietly consolidated its dependencies onto a tiny number of AI models, cloud platforms, and providers. The BoE has flagged exactly this on the operational side: financial firms increasingly lean on the same small set of outside providers for models, compute, and data, so that a failure or a successful attack at one provider could ripple across many institutions at once. It even notes that the same AI advances arming defenders are arming attackers, raising the odds that a single exploited weakness in a shared model becomes everyone’s incident simultaneously.

So the useful response is not to bet on the crash or against it. It’s to treat concentration as the risk it is, in your own house. Ask the resilience questions the central banks are asking, one level down: How many of your critical processes now depend on a single AI provider? What is your actual exposure if your primary model, or the cloud under it, goes down, gets breached, or simply gets repriced out of your budget overnight? Do you have a fallback, or have you quietly wired everything to one supplier because it was the efficient thing to do? These are the same questions a good security function has always asked about single points of failure. AI has just made them urgent at a scale that now worries the people who watch the whole system.

The bubble may burst or it may not; that argument will run and run, and it is mostly a distraction. The durable warning in these reports is quieter and does not depend on calling the top. We have built something enormous, fast, and interconnected on a very narrow base, and narrowness is fragility whether or not today is the day it’s tested. The central banks are not really telling you to time the market. They are telling you to look at what everything now rests on, and to notice how few things that is. That is a security question, and it deserves a security answer, before the weather changes rather than after.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

Responses