
We spent the years after the financial crisis worrying about banks that were too big to fail. We forced them to hold more capital, more liquidity, write living wills, run stress tests and prove that governments would never again have to rescue the financial system because one enormous institution collapsed.
Meanwhile, almost unnoticed outside technology departments, banking created another concentration risk that sits underneath the entire financial system.
The cloud.
The uncomfortable reality is that banks have spent the past decade dismantling their technological independence and moving critical operations onto infrastructure controlled by a tiny number of global technology companies.
Customer onboarding, payments, data, fraud detection, trading systems, risk management, artificial intelligence and increasingly core banking processes now depend upon cloud infrastructure that banks neither own nor ultimately control.
The banking industry solved one concentration problem and created another.
Except this one is bigger.
The traditional systemic risk was that a large bank failed and infected other banks through loans, derivatives, funding markets and collapsing confidence. The new systemic risk is that the technological infrastructure underneath many banks fails simultaneously.
That is an entirely different crisis.
Research into the possibility of a cyber-financial crisis makes the point clearly.
Digitalisation has created extraordinary efficiency, speed and connectivity, but the same connectivity creates systemic vulnerability because banks, payment systems, fintech companies, data providers and cloud platforms are now deeply interconnected. A cyberattack or infrastructure failure no longer stops at the walls of one institution. It travels through the digital networks connecting the financial system.
This changes the meaning of systemic risk.
After 2008 we talked about institutions being too big to fail and then too interconnected to fail. Cloud computing introduces something else: too concentrated to fail.
The danger is not cloud computing itself.
The cloud is one of the best things that happened to banking technology. It gives banks extraordinary computing power, scalability, resilience, cybersecurity capabilities and access to technologies that would cost billions to reproduce internally.
The problem is that everyone is buying those capabilities from the same companies.
The UK has noted this in July 2026 when HM Treasury designated four technology companies as the country's first Critical Third Parties to the financial sector: Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK.
The Bank of England, PRA and FCA explicitly state that disruption or failure at these providers could affect multiple financial institutions or markets simultaneously and therefore threaten UK financial stability.
Think about what that means. We now have technology companies that are more systemically important to banking than banks. They do not take deposits. They do not make mortgages. They do not operate traditional payment accounts. They are not banks. Nevertheless, if one of them suffers a catastrophic failure, large parts of banking will stop working.
That makes cloud providers part of the financial infrastructure whether we call them financial institutions or not.
The United States reached much the same conclusion. The US Treasury warned that the cloud market is concentrated among a small number of providers and that an incident at one provider could hit many financial institutions concurrently. It also identified something banks rarely like discussing: moving critical operations away from a cloud provider during a crisis is difficult.
In other words, diversification looks easier on a PowerPoint slide than it does at three o'clock in the morning when your primary infrastructure has disappeared.
That is where the cloud argument gets interesting.
Banks originally moved to the cloud because their own infrastructure was fragmented, expensive, ageing and difficult to maintain. Cloud providers offered better engineering, better resilience, better security and massive economies of scale.
Individually, that decision makes perfect sense. Systemically, it creates a paradox.
Every bank becomes safer by moving to the cloud while banking becomes more vulnerable because they are moving to the same clouds.
That is the systemic risk regulators now have to confront.
An individual bank might have excellent resilience. Its cloud provider might have extraordinary resilience. But if hundreds of banks, payment companies, exchanges and financial infrastructure providers depend upon the same underlying technological ecosystem, the failure of that ecosystem is no longer an IT incident … it is a financial stability event.
We have already seen glimpses of this dependency.
AWS outages have affected banking services, Microsoft cloud failures have disrupted institutions around the world and the CrowdStrike incident in 2024 stopped operations across numerous industries, including financial services. These incidents were manageable, but they demonstrated the architecture we have constructed: enormous numbers of supposedly independent organisations sitting on common technological foundations.
Now add artificial intelligence.
That is where cloud concentration becomes even more important because the next generation of banking will be vastly more computationally dependent than the last one.
AI agents, autonomous payments, real-time fraud detection, algorithmic risk management, tokenised assets, programmable money and intelligent banking all require enormous computing infrastructure.
Banks are therefore not becoming less dependent upon cloud providers but becoming far more dependent upon them.
At exactly the same time, AI is increasing the sophistication and speed of cyber threats.
The Bank of England's Financial Policy Committee warned in July that, in a severe scenario, financial firms and key third-party providers could fail to keep pace with rapidly advancing attack capabilities, allowing vulnerabilities to accumulate until the risk of a systemic cyber event rises materially.
Put those two trends together and the architecture becomes obvious.
Banking is concentrating its technological infrastructure while cyberattacks become faster, more automated and more powerful.
That is not merely operational risk.
That is systemic risk.
A serious cloud failure would also behave differently from the banking crises we understand. A bank collapse develops through capital losses, liquidity problems and collapsing confidence. Regulators have tools for those situations. They inject liquidity, guarantee deposits, arrange mergers, recapitalise institutions and, ultimately, deploy central bank balance sheets.
But what happens when the problem is not money?
Imagine several major banks cannot process payments because their common technological infrastructure is unavailable. Their balance sheets remain solvent. Their capital ratios remain healthy. Their liquidity coverage ratios look beautiful.
None of it matters when the computers are not working.
You cannot solve that crisis with quantitative easing.
The central bank cannot print cloud capacity.
That is why the concept of systemic resilience has to expand beyond banks themselves, and the next logical step is much bigger. If cloud providers are systemically important to banking, they need to be treated as systemically important financial infrastructure.
Banks need genuine multi-cloud resilience rather than contractual multi-cloud theatre. They need tested exit strategies rather than documents claiming workloads can be moved. Regulators need visibility across the entire financial system to understand where thousands of institutions share the same providers, software, data centres, cybersecurity tools and technological dependencies.
Most importantly, cloud concentration needs to enter financial stress testing.
We stress banks against recessions, property crashes, unemployment, market collapses and liquidity shocks. We should also ask what happens when a major cloud region disappears for twenty-four hours, when a hyperscaler suffers a catastrophic cyberattack, when critical data becomes corrupted, or when several financial institutions simultaneously discover that their supposedly independent backup arrangements depend upon the same underlying infrastructure.
Research into cyber-financial crises argues precisely this point: cyber resilience has to move from microprudential operational risk into macroprudential financial stability, alongside capital and liquidity.
That is the fundamental shift.
For two hundred years, systemic banking risk sat inside banks.
Today, some of the greatest systemic risks sit underneath them.
The next financial crisis does not have to begin with bad mortgages, collapsing bond portfolios, rogue traders or excessive leverage. It can begin with a software vulnerability, corrupted update, cyberattack or cloud infrastructure failure that simultaneously removes critical services from dozens of financial institutions.
And therein lies the irony.
Banks spent decades being told they were too big to fail. They responded by moving more and more of their infrastructure into a handful of technology companies. Now we have built something even more concentrated. The cloud is too critical to fail.
[3]: https://home.treasury.gov/news/press-releases/jy1252
[6]: https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026
Chris M Skinner
Chris Skinner is best known as an independent commentator on the financial markets through his blog, TheFinanser.com, as author of the bestselling book Digital Bank, and Chair of the European networking forum the Financial Services Club. He has been voted one of the most influential people in banking by The Financial Brand (as well as one of the best blogs), a FinTech Titan (Next Bank), one of the Fintech Leaders you need to follow (City AM, Deluxe and Jax Finance), as well as one of the Top 40 most influential people in financial technology by the Wall Street Journal's Financial News. To learn more click here...