The Reserve Bank of New Zealand has warned that the rapid adoption of artificial intelligence across banks, insurers and payment systems is opening up a new front of financial stability risk, with heavy reliance on a small handful of overseas AI providers and the arrival of frontier models like Anthropic’s Mythos amplifying both cyber threats and the risk of borrower harm.
The warning comes from a dedicated chapter in the Reserve Bank’s May 2026 Financial Stability Report, which says AI is now beginning to have a significant impact on the New Zealand financial system. The chapter, written by senior analyst Matthew Hankin, sits alongside the report’s separate findings on bank resilience, insurance affordability and uninsured housing that have already shaped this week’s economic news cycle.
In the chapter, the Reserve Bank says relying on only a small number of third party AI providers could create dependencies and increase the risk that models produce biased, misleading or fraudulent outputs. Most New Zealand banks and insurers buy their generative AI capability from a handful of global suppliers, which the central bank warns concentrates technical, legal and reputational exposure into a very small number of upstream points. If one of those providers suffers an outage, suffers a data breach or quietly changes how a model behaves, the impact would ripple through every regulated entity that uses the same service.
The Reserve Bank also flagged the rise of frontier AI models as an emerging cyber risk, naming Anthropic’s Mythos as a specific example. The chapter says emerging frontier models such as Anthropic’s Mythos highlight how increasingly capable AI systems could materially amplify cyber risks from malicious actors. The Reserve Bank adds that it is actively monitoring the risks that Mythos and similar models may pose, and is engaging with domestic and Trans-Tasman partners on a coordinated response.
That cyber concern is not theoretical. The chapter discloses that the Exchange Settlement Account System, the high-value payment rail run by the Reserve Bank itself, experienced a material cyber incident affecting roughly $4.5 billion of transactions. That figure represents about 15 percent of the $29.8 billion daily average across the system based on 2025 data. The Reserve Bank says the outage disrupted all ESAS participants and cascaded across three additional financial market infrastructure providers before being resolved within three hours, a useful real world test of an operational playbook that until recently had been only tabletop exercises.
Beyond cyber, the report draws a direct line from AI adoption to household lending. The Reserve Bank warns that if AI leads to job losses in some sectors, more borrowers may struggle to pay their mortgages. New Zealand banks have lifted their use of AI in marketing, credit scoring and back office automation over the past two years, and several of the largest lenders have publicly signalled further productivity savings. The Reserve Bank’s concern is that the same productivity story plays out in customer facing industries such as call centres, professional services and parts of retail, with people displaced from those jobs likely to be carrying mortgages booked at the higher interest rates of the early 2020s.
The chapter also lists data privacy issues, market distortions and AI-driven errors among the risks worth watching. Reporting from interest.co.nz’s Gareth Vaughan notes that the Reserve Bank still expects regulated entities to manage AI risks themselves, rather than relying on the central bank to set new prescriptive rules. That is consistent with the Reserve Bank’s broader operational resilience framework, which puts the obligation on each bank’s board to understand the systems it has outsourced to overseas providers and to plan for a world where those providers fail or are compromised.
The Reserve Bank is not arguing that the financial sector should slow down its use of AI. The chapter explicitly recognises the upside, pointing to more resilient risk management, greater productivity, innovation and the ability to offer customers more personalised products. Several New Zealand banks now use AI to detect mule accounts and scam payments in real time, and the central bank acknowledges that those tools have already prevented losses that would otherwise have shown up on the financial stability ledger. The argument is that the upside and the downside are growing together, and that governance, model monitoring and contractual controls need to grow at the same rate.
For the wider business sector, the Reserve Bank’s warning is a signal that AI risk is moving from a technology committee issue to a board level financial issue. Insurers writing cyber policies are already pushing up premiums on companies that cannot demonstrate solid AI governance, and trade credit underwriters are starting to ask questions about supplier dependence on a single AI vendor. New Zealand businesses that have rolled generative AI into customer service, contract review or financial reporting can expect those questions to find their way into bank covenants and audit conversations over the coming year.
The Financial Stability Report’s headline message remains that the New Zealand financial system is resilient, with banks and insurers well capitalised and able to keep lending through the global turbulence of 2026. The AI chapter is a deliberate stretching of the lens to the rest of this decade. The Reserve Bank’s view is that an industry already running on overseas cloud providers and overseas core banking software is now layering an overseas AI dependency on top of it, and the central bank wants that dependency mapped and managed before, not after, the first big headline incident.
What does AI risk look like inside your business or your bank, and is your provider one of the big global names the Reserve Bank is worried about? Let us know in the comments below.
This article was written by AI, briefed to report the facts, hopefully without some of the bias people bring to the job π

Leave a Reply