Agentic AI Systems and Financial Stability, From Model Risk to Systemic Risk
The study shows that agentic AI systems sharing a foundation model create non-diversifiable common exposure whose systemic risk floor does not shrink as the fleet grows, shifting concern from individual model risk to population-level contagion.
Featured in No. 134 on 9 Oct 2026 · 1 day after release

- Released
- 8 Oct 2026
- First featured
- No. 134 · 9 Oct 2026
- Published in
- Not yet, as far as Semantic Scholar knows
- Fanfare
- 4 of 5
- Identifier
- arXiv:2610.08806
- Authors
- Sriram Nagaraj and Seung Jung Lee
Abstract
From arXiv (CC0).
Financial stability rests on the premise that distress is largely idiosyncratic and therefore diversifiable: when one institution errs, the rest of the system absorbs the shock. That premise fails when many decision-makers depend on the same infrastructure. Agentic AI systems, which take consequential actions rather than only emitting predictions, are becoming such a substrate, and the binding concern shifts from the model risk of a single deployment to the systemic risk of the population. We develop this account in six mathematical settings. Chapter 1 recasts the PD/LGD/EAD decomposition of expected loss as an expected-harm identity and introduces a set-valued containment-risk measure; under a lever-assignment axiom that review cannot intercept an irreversible action, no non-preventive control satisfies a coherent tail constraint. Chapter 2 lifts this to a fleet sharing a foundation model: the shared model is a non-diversifiable common exposure whose expected-shortfall floor holds however large the fleet grows, and a percolation threshold governs contagion. Chapter 3 recasts these dynamics as a marked, Hawkes-excited jump diffusion, identifying the robust stress problem with a time-consistent entropic risk measure. Chapter 4 treats runtime guardrails as partially observed stochastic control, giving an observability trichotomy, a detection floor, and, under commit exogeneity, a runtime-impossibility corollary. Chapter 5 makes the adversary a player, yielding an underinvestment wedge proportional to systemic reach. Chapter 6 makes capability a state variable in an arms race. One claim runs through all six: the systematic component of agentic risk cannot be diversified, detected away, or reversed, and only ex-ante structural prevention moves it.
Citations and venue from Semantic Scholar (ODC-BY), refreshed weekly. Summary: Quant Letter (CC BY 4.0).