The three EU supervisors name non-EU ICT providers as a system-level risk
The three European Supervisory Authorities — EBA, EIOPA and ESMA — published their Autumn 2026 Joint Committee update on Risks and Vulnerabilities on 23 September 2026, naming external dependencies, emerging technologies and private credit as the key vulnerabilities for the EU financial system. The findings were presented to the Financial Stability Table of the EU's Economic and Financial Committee on 10 September.
On dependencies, the ESAs warn that reliance on non-EU providers and infrastructures could amplify geopolitical shocks and operational disruptions, with ICT service providers outside the European Economic Area a particular concern — alongside growing cyber risk linked to "increasingly capable AI models". Investment funds are named as having substantial exposure to the US, particularly equity UCITS and alternative funds, while bond funds are more geographically diversified.
On private credit: small in the EU, but rapid growth, limited transparency and increasing links with the wider financial system could create stress-period risks.
The headline conclusion is nonetheless that the system held. EU equities reached record highs, bond spread widening was limited, funds stayed resilient through the volatility, and banks operated with strong profitability and high capital ratios — with expected asset-quality deterioration flagged in commercial real estate and SME portfolios.

What it means for this sector
"Continued crypto-asset volatility" appears in the resilience paragraph, not the vulnerability list — and that placement is the news for anyone reading this from inside the industry. The ESAs are describing crypto as part of the volatile environment the system absorbed, rather than as one of the three things that could transmit stress. A year of MiCA supervision has evidently not produced a systemic-risk framing.
Where the sector does appear, it appears indirectly, under external dependencies. The concern about ICT providers outside the EEA is about concentration in a handful of non-European infrastructure operators, and crypto-asset service providers are among the most concentrated users of exactly that infrastructure. The warning is not addressed to them, but the exposure it describes is theirs too.
📌 This is a risk update, not a rule. Nothing in it changes an obligation; it signals where supervisory attention is going, which is the thing worth tracking a quarter ahead of any consultation.