Agefi Luxembourg - septembre 2026
Septembre 2026 45 AGEFI Luxembourg IA & Tech By Elena KAZMINA, Director, Risk and Regulatory Advisory & Andreas BRAUN, Managing Director, Artificial Intelligence Solutions – PwC Luxembourg A paradox that demands leadership A rtificial intelligence is res haping the risk land scape of European credit institutions with a speed few prior technologies havemat ched. It is simultaneously one of themost powerful tools available to risk teams and one of themost consequential risk drivers that boards and senior management must govern, with sup port fromCompliance andRisk. For credit institutions operating inLuxembourg, the stakes are particularly high. As a hub for crossbor der banking, asset management and payment ser vices, Luxembourg’s financial sector stands to gain considerablyfromAIadoption.Yetitoperateswithin one of the world’s most demanding regulatory en vironments, where the EU AI Act, DORA, the CRR/CRD and EBAGuidelines establish rigorous obligations for institutionsdeployingAI inregulated functions. In November 2025, the EBApublished a mapping exercise showingAI Act requirements on highrisk banking and payments systems are broadlyconsistentwithexistingprudential andgov ernance obligations. ThemessagetoCROsisclear:governanceinfrastruc ture built under existingprudential rules provides a strong foundation, butmust nowbedeliberatelyex tended to coverAIspecific risk drivers.At the same time,AI holds real transformativepotential as anen abler for the risk function itself. This article examines both sides and what they mean forCROs,whomust act proactivelybeforeAI deployment scales beyond their ability to govern it effectively. AI as an enabler: amplifying the risk function The risk function has always been dataintensive, modeldriven and analytically demanding. AI am plifies the speed, depthandbreadthwithwhich risk teams can execute theirmandate. The question is no longerwhetherAI can addvalue to credit risk, mar ket risk, liquiditymanagement or compliance—the evidence is now conclusive. Practical use cases for risk teams AI use cases with application to risk management are numerous. The table below illustrates a selec tion of five, showcasing the challenges AI can help solve. Spotlight: smarter credit decisions, more sensitive earlywarning signals Automated data pipelines, combined with a flexible ontology model, ensure rapidand consistent dataprocessing, ag gregation and transformation into expo sureorportfoliolevelmetrics.LLMsalso enable instant generation of credit mem oranda,benchmarkinganalysisandport folioscanning insights. Traditional covenantbasedmonitoring is inherently lagging— it identifies deterioration only after it has crystallised in financial state ments.AI changes this: LLMs cancontinuouslyscan news, regulatory filings and supply chain data for signals of borrower stress, correlating them with transaction patterns. This lets risk teams flag deteri oration months before traditional triggers fire, en abling dialoguewhile optionality remains. Spotlight: automation of the compliance risk monitoring Apersistent challenge for compliance riskmonitor ing is fragmentation: regulatory inventories main tained in isolation, weak linkages between regulations, risks, controls and policies, and risk as sessments, control testingand reporting that remain heavily manual. AI is reshaping this picture. LLMs can parse regulatory text into clear, actionable obli gations andmap themdirectly to risks, controls and business processes, closing gapsmanual interpreta tion typically leaves open. This connected structure lets RCSA cycles, control testing and management reporting be substantially automated. As a result, labourintensive assurance moves to wardsacontinuouslyupdated,evidencebasedview on compliance risk. AI as a source of risk: start with identification Thebenefits ofAI adoptionare clear. Yet theproper ties that makeAI powerful also generate distinctive risks that demand a deliberate extension of gover nancearchitecture.TheCSSFandBCL“Thematicre view on the use of Artificial Intelligence in the Luxembourgfinancial sector” (May2025) highlights an important gap: only 43% of respondents have a formally approvedAI policy. AsingleAIsystemcansimultaneouslycreatearange of riskdrivers, dependingonhowit is designed, de ployed and used. Afirst step for risk functions is to ensure AIdriven risks are comprehensively cap tured across the risk taxonomy and integrated into multiple risk categories, shown below : Examples of AIspecific risk drivers for each risk category are summarised below: Systems Model/infrastructure failures ordowntimeaffect ingAIdependent processes Integration failures between AI systems and legacy IT infrastructure Lack of version control or rollback capability when a model update in troduces errors Model risk Model drift/decay as realworld data diverges from training data over time Lack of explainability/inter pretability making it harder to validate outputs Hallucinations or fabricated outputs (especially generativeAI) presented as fact Security Data poisoning attacks corrupting training data Prompt injection or jailbreaking of generative AI systems leading to unexpected/unwanted system behaviour Data Poor data quality (incomplete, mislabelled, out dated, unrepresentative) Data privacy violations (insufficient anonymisa tion, reidentification risk) Data leakage between training and test sets, or un intendedmemorisation of sensitive data Ethics andConduct Algorithmic bias leading to discriminatory out comes (race, gender, age, etc.) Absenceof clear accountabilitywhenAIdrivende cisions cause harm Conflictsof interest inAIdrivenrecommendations (e.g., steeringcustomers towardproductsbenefiting the institution) Thirdparty risks Lackof visibility intovendorʹs trainingdata,model architecture, or security practices Concentration risk from dependency on a small number ofAI providers Contractual gaps around liability, IPownership, or performance guarantees User and process risk Overreliance on AI outputs without adequate human review (automation bias) ShadowAI usage (employees using unauthorised AI tools with sensitive data) Process gaps between AI recommendation and final decisionmaking authority Legal / Copyright Use of copyrightedmaterial in training data with out authorisation IP infringement inAIgenerated outputs (text, images, code) Liability exposure for AIdriven decisions or advice (e.g., erro neous credit denials) Complianceandregulatory risks Noncompliance with regula tions such as EUAI Act, DORA, GDPR, sustainabilityrelated laws and regulations, etc. Lackof explainabilityconflicting with ʺright to explanationʺ re quirements Regulatorydivergenceacross ju risdictions creating compliance complexity Environmental harm High energy consumption and carbon footprint from training/running largemodels Water usage for data centres cooling Lack of transparency/reporting on AIʹs environ mental impact Reputational risks PublicfacingAI failures (biased outcomes, embar rassing generativeAI outputs) Gap between marketed AI capabilities and actual performance (AIwashing) Loss of customer trust following data breaches or biased decisionmaking Beyond risks arising fromdirect use ofAI, there is a range of broader impacts emerging across the econ omy. Examples include: Portfolio impacts AsAI reshapes entire industries, bankswithconcen trated lending exposure to affected sectors face a growing form of credit risk driven by technological displacement rather than traditional cyclical factors. Borrowers may see declining revenues or business model obsolescencewithin timeframes shorter than the tenor of existing loans—a fiveor tenyear loan underwrittenonhistorical cashflowsmayno longer reflect a borrower’s ability to repay if its industry is disrupted midterm, and defaults could cluster rather than remain idiosyncratic. Collateral impacts AIdrivenindustrytransformationalsothreatenscol lateral values and raises concentration concerns. Loans securedagainst physical assets—commercial real estate, specialised manufacturing equipment displacedbyAI, or retail inventorydisruptedbyAI driven ecommerce—may see collateral values de cline faster than amortisation schedules assume, increasing lossgivendefault. Strategic / business impact Competition among AI developers or statelike ac tors racing todevelop, deployandapplyAI systems forstrategicoreconomicadvantageincreasestherisk of longterm impact on business sustainability and strategic relevance. TheCRO’s imperative: act before scale, not after AIasenablerandAIasrisksourcebothdeservehigh prominence onCROs’and risk teams’agendas. Indeed,theinstitutionsthatwillsuccessfullynavigate thisAIparadoxarethosethatbuildgovernancearchi tecturebeforeAIdeploymentscales.Retrofittinggov ernanceontoAIsystemsalreadyinproductionisdra matically harder — technically, operationally and politically—than designing it in fromthe outset. The CROwho positions their function to lead onAI governance will earn a strategic seat at the table as their institution’s AI capabilities expand. The CRO who waits will find the function definingAI gover nancewithout them. Five “nonregret” actions for CROs Promote risk awareness across the organisation . The CRO should supportAI risk awareness across the three lines of defence, ensuring business units, model developers, and risk and control functions understand AIspecific risks and build AI literacy progressively. A genuinely riskaware culture will prove a more durable safeguard than any single control or policy. Establisha formalAI inventoryandriskclassifica tion . Commission a comprehensive inventory of all AIbased tools in use across the institution and clas sify each application against the AI Act’s risk tiers. This inventory is the foundation of everything else. Extend model risk management to cover AIspe cificcharacteristics .ExistingMRMframeworkscov ering model development, validation, monitoring anddecommissioningmust be extended to address MLspecific challenges—explainability, feature im portance, performance stabilityunderdistributional shift, and bias testing. MakeAI governanceaboardlevelmatter .AI over sight shouldbe integral to the board risk committee, whichmust beequipped tochallengeAIrelatedrisk decisions—how a model was validated, its perfor manceboundaries,what overridemechanisms exist —withKRIsintegratedintoriskappetitestatements. Enhance thirdparty due diligence . For every AI tool procuredexternally, duediligencemust answer questions like: Canwe audit thismodel? Dowehave access to trainingdatadocumentation, validationevidenceandongoingperformancemon itoring? Does the vendor’s contractual framework give us the rights that DORA,AIAct require? Where the answer is no, the institution must either negotiate the necessary access or consider building the capability internally. Conclusion The paradox is real, but it is manageable with the right leadership at the right time. AI is genuinely transformative for the risk function,whilealso intro ducing risks that are distinctive and require deliber ate governance responses. TheCRO’s role is tobe the institutional anchor for re sponsibleAIadoption—nottoblockinnovation,but to ensureAI systems are understood, validated and governed, especially forhighriskuse cases, and that regulatory compliance is not undermined. The institutions that build this capabilitynow, before their AI footprint scales, will find that governance and innovationarenot in tension. Theyare, properly understood, the same thing. TheAI paradox: artificial intelligence as simultaneous enabler and risk driver Use ȱ c ase ȱ ȱȱȱ The ȱ c hallenge ȱȱ ȱȱ H ow ȱ AI ȱ helps ȱ Ȭȱ Periodic ȱ risk ȱ reporting ȱ is ȱ a ȱ hybrid ȱ between ȱ manual ȱ and ȱ system Ȭ driven ȱ inputs, ȱ slow, ȱ and ȱ error Ȭ prone ȱ Ȭȱ Automatically ȱ pulls ȱ and ȱ analyses ȱ structured ȱ and ȱ unstructured ȱ data ȱ Ȭȱ Data ȱ scattered ȱ across ȱ emails, ȱ PD F s, ȱ reports, ȱ and ȱ spreadsheets ȱ Ȭȱ Applies ȱ standardised ȱ queries ȱ for ȱ consistent ȱ outputs ȱ F r o m ȱ m an u al ȱ r epo rti ng ȱ t o ȱ i ns t an t, ȱ a udit Ȭ r ea d y ȱ i ns i gh t s ȱ Ȭȱ High ȱ effort, ȱ low ȱ value ȱ for ȱ senior ȱ risk ȱ teams ȱ Ȭȱ Produces ȱ complete ȱ risk ȱ reports ȱ in ȱ minutes, ȱ not ȱ weeks ȱ Ȭȱ Multiple ȱ data ȱ sources, ȱ complex ȱ data ȱ processing ȱȱ Ȭȱ Automated ȱ data ȱ ingestion ȱ and ȱ quality ȱ checks ȱ Ȭȱ Time Ȭ intensive ȱ analysis ȱ and ȱ documentation ȱ Ȭȱ AI Ȭ driven ȱ credit ȱ analysis ȱ (trends, ȱ peer ȱ benchmarking, ȱ etc . ) ȱ and ȱ memo ȱ generation ȱ Sm a rt e r ȱ cr e dit ȱ d e ci s i ons , ȱ m o r e ȱ sens itiv e ȱ ea r ly ȱ wa r n i ng ȱ s i gnals ȱ Ȭȱ Need ȱ for ȱ timely ȱ early ȱ warning ȱ signals ȱ and ȱ explainability ȱ Ȭȱ Continuous ȱ monitoring ȱ and ȱ wide Ȭ ranging ȱ early ȱ warning ȱ signals ȱ Ȭȱ F ragmented ȱ regulatory ȱ inventories, ȱ slow ȱ and ȱ complex ȱ analysis ȱ of ȱ changes ȱ Ȭȱ Automated ȱ pipelines ȱ and ȱ alerts ȱ on ȱ regulatory ȱ changes ȱ Ȭȱ Weak ȱ linkage ȱ between ȱ regulations, ȱ risks, ȱ controls ȱ and ȱ policies ȱ Ȭȱ Accelerated ȱ applicability ȱ mapping ȱ to ȱ downstream ȱ processes, ȱ risks, ȱ controls ȱ and ȱ policies ȱ Aut o m a ti on ȱ o f ȱ t he ȱ c o m pl i an c e ȱ ri sk ȱ m on it o ri ng ȱ Ȭȱ Delayed ȱ reporting ȱ Ȭȱ Automated ȱ controls ȱ and ȱ tech Ȭ enabled ȱ testing ȱ with ȱ data Ȭ driven ȱ results ȱ Ȭȱ Traditional ȱ stress ȱ testing ȱ is ȱ statistical Ȭ model ȱ based, ȱ making ȱ it ȱ complex ȱ and ȱ time Ȭ consuming ȱ to ȱ execute . ȱ Ȭȱ A ȱ combination ȱ of ȱ LLMs ȱ and ȱ econometric ȱ models ȱ enables ȱ a ȱ more ȱ user Ȭ friendly ȱ experience ȱ — ȱ scenarios ȱ described ȱ in ȱ plain ȱ English ȱ — ȱ with ȱ fast ȱ results ȱ delivery ȱ R ap id ȱ s tr ess Ȭ t es ti ng ȱ an d ȱ s c ena ri o ȱ analys i s ȱ Ȭȱ Scenario ȱ narratives ȱ are ȱ not ȱ easily ȱ adaptable ȱ and ȱ require ȱ involvement ȱ of ȱ macroeconomists . ȱ Ȭȱ Scenario ȱ narratives ȱ can ȱ be ȱ formulated ȱ by ȱ users ȱ or ȱ suggested ȱ by ȱ the ȱ LLMs ȱ based ȱ on ȱ observable ȱ context ȱ Ȭȱ Unstructured ȱ incidents ȱ reporting ȱ delivering ȱ fragmented ȱ insights ȱ Ȭȱ Automated ȱ clustering ȱ of ȱ incidents ȱ and ȱ detection ȱ of ȱ associated ȱ risks, ȱ highlights ȱ those ȱ requiring ȱ urgent ȱ attention ȱ Ri sk ȱ id en tific a ti on ȱ an d ȱ r e m e di a ti on ȱ Ȭȱ Limited ȱ lessons ȱ learned ȱ analysis ȱ and ȱ inconsistent ȱ response ȱ pattern ȱ Ȭȱ Instant ȱ mapping ȱ of ȱ newly ȱ identified ȱ risks ȱ to ȱ closest ȱ historical ȱ “ look Ȭ alikes ” ȱ and ȱ auto Ȭ generated ȱ response ȱ actions ȱ based ȱ on ȱ historical ȱ patterns . ȱ Validity&Accuracy Probabilisticresults’pattern;hallucinations Ethical Biasandconflictswithethicalstandards Privacy&security Sensitivedataexposureormisuse;privacyviolations Explainability&Transparency Blackboxdecisions;lowtraceabilityandauditability Accountability UnclearownershipfortheAIoutputandmonitoring Legal ViolationsofIPrights,unfairuse AI Risk Considerations AI Integration into Risk Taxonomy
Made with FlippingBook
RkJQdWJsaXNoZXIy Nzk5MDI=