Press Article - Initially published on AGEFI

The AI paradox: artificial intelligence as simultaneous enabler and risk driver

  • September 22, 2026

Introduction: a paradox that demands leadership

Artificial intelligence is reshaping the risk landscape of European credit institutions with a speed few prior technologies have matched. It is simultaneously one of the most powerful tools available to risk teams and one of the most consequential risk drivers that boards and senior management must govern, with support from Compliance and Risk.

For credit institutions operating in Luxembourg, the stakes are particularly high. As a hub for cross-border banking, asset management and payment services, Luxembourg's financial sector stands to gain considerably from AI adoption. Yet it operates within one of the world's most demanding regulatory environments, where the EU AI Act, DORA, the CRR/CRD and EBA Guidelines establish rigorous obligations for institutions deploying AI in regulated functions. In November 2025, the EBA published a mapping exercise showing AI Act requirements on high-risk banking and payments systems are broadly consistent with existing prudential and governance obligations.

The message to CROs is clear: governance infrastructure built under existing prudential rules provides a strong foundation, but must now be deliberately extended to cover AI-specific risk drivers. At the same time, AI holds real transformative potential as an enabler for the risk function itself.

This article examines both sides and what they mean for CROs, who must act proactively before AI deployment scales beyond their ability to govern it effectively.

The AI paradox: artificial intelligence as simultaneous enabler and risk driver

AI as an enabler: amplifying the risk function

The risk function has always been data-intensive, model-driven and analytically demanding. AI amplifies the speed, depth and breadth with which risk teams can execute their mandate. The question is no longer whether AI can add value to credit risk, market risk, liquidity management or compliance — the evidence is now conclusive.

Practical use cases for risk teams

AI use cases with application to risk management are numerous. The table below illustrates a selection of five, showcasing the challenges AI can help solve.

Use case

The challenge

How AI helps

From manual reporting to instant, audit‑ready insights

  • Periodic risk reporting is a hybrid between manual and system-driven inputs, slow, and error‑prone
  • Data scattered across emails, PDFs, reports, and spreadsheets
  • High effort, low value for senior risk teams
  • Automatically pulls and analyses structured and unstructured data
  • Applies standardised queries for consistent outputs
  • Produces complete risk reports in minutes, not weeks

Smarter credit decisions, more sensitive early warning signals

  • Multiple data sources, complex data processing
  • Time‑intensive analysis and documentation
  • Need for timely early warning signals and explainability
  • Automated data ingestion and quality checks
  • AI-driven credit analysis (trends, peer benchmarking, etc.) and memo generation
  • Continuous monitoring and wide-ranging early warning signals

Automation of the compliance risk monitoring

  • Fragmented regulatory inventories, slow and complex analysis of changes
  • Weak linkage between regulations, risks, controls and policies
  • Delayed reporting
  • Automated pipelines and alerts on regulatory changes
  • Accelerated applicability mapping to downstream processes, risks, controls and policies
  • Automated controls and tech-enabled testing with data-driven results

Rapid stress-testing and scenario analysis

  • Traditional stress testing is statistical-model based, making it complex and time-consuming to execute.
  • Scenario narratives are not easily adaptable and require involvement of macroeconomists.
  • A combination of LLMs and econometric models enables a more user-friendly experience — scenarios described in plain English — with fast results delivery
  • Scenario narratives can be formulated by users or suggested by the LLMs based on observable context

Risk identification and remediation

  • Unstructured incidents reporting delivering fragmented insights
  • Limited lessons learned analysis and inconsistent response pattern
  • Automated clustering of incidents and detection of associated risks, highlights those requiring urgent attention
  • Instant mapping of newly identified risks to closest historical “look-alikes” and auto-generated response actions based on historical patterns.

Spotlight: smarter credit decisions, more sensitive early warning signals

Automated data pipelines, combined with a flexible ontology model, ensure rapid and consistent data processing, aggregation and transformation into exposure- or portfolio-level metrics. LLMs also enable instant generation of credit memoranda, benchmarking analysis and portfolio-scanning insights.

Traditional covenant-based monitoring is inherently lagging — it identifies deterioration only after it has crystallised in financial statements. AI changes this: LLMs can continuously scan news, regulatory filings and supply chain data for signals of borrower stress, correlating them with transaction patterns. This lets risk teams flag deterioration months before traditional triggers fire, enabling dialogue while optionality remains.

Spotlight: automation of the compliance risk monitoring

A persistent challenge for compliance risk monitoring is fragmentation: regulatory inventories maintained in isolation, weak linkages between regulations, risks, controls and policies, and risk assessments, control testing and reporting that remain heavily manual. AI is reshaping this picture.

LLMs can parse regulatory text into clear, actionable obligations and map them directly to risks, controls and business processes, closing gaps manual interpretation typically leaves open. This connected structure lets RCSA cycles, control testing and management reporting be substantially automated.

As a result, labour-intensive assurance moves towards a continuously updated, evidence-based view on compliance risk.

AI as a source of risk: start with identification

The benefits of AI adoption are clear. Yet the properties that make AI powerful also generate distinctive risks that demand a deliberate extension of governance architecture. The CSSF and BCL "Thematic review on the use of Artificial Intelligence in the Luxembourg financial sector" (May 2025) highlights an important gap: only 43% of respondents have a formally approved AI policy. 

A single AI system can simultaneously create a range of risk drivers, depending on how it is designed, deployed and used. A first step for risk functions is to ensure AI-driven risks are comprehensively captured across the risk taxonomy and integrated into multiple risk categories, shown below:

The AI paradox: artificial intelligence as simultaneous enabler and risk driver

Examples of AI-specific risk drivers for each risk category are summarised below:

Risk category

Examples of AI-specific risk drivers

Systems

  • Model/infrastructure failures or downtime affecting AI-dependent processes
  • Integration failures between AI systems and legacy IT infrastructure
  • Lack of version control or rollback capability when a model update introduces errors

Model risk

  • Model drift/decay as real-world data diverges from training data over time
  • Lack of explainability/interpretability making it harder to validate outputs
  • Hallucinations or fabricated outputs (especially generative AI) presented as fact

Security

  • Data poisoning attacks corrupting training data
  • Prompt injection or jailbreaking of generative AI systems leading to unexpected/unwanted system behaviour

Data

  • Poor data quality (incomplete, mislabelled, outdated, unrepresentative)
  • Data privacy violations (insufficient anonymisation, re-identification risk)
  • Data leakage between training and test sets, or unintended memorisation of sensitive data

Ethics and Conduct

  • Algorithmic bias leading to discriminatory outcomes (race, gender, age, etc.)
  • Absence of clear accountability when AI-driven decisions cause harm
  • Conflicts of interest in AI-driven recommendations (e.g., steering customers toward products benefiting the institution)

Third-party risks

  • Lack of visibility into vendor's training data, model architecture, or security practices
  • Concentration risk from dependency on a small number of AI providers
  • Contractual gaps around liability, IP ownership, or performance guarantees

User and process risk

  • Over-reliance on AI outputs without adequate human review (automation bias)
  • Shadow AI usage (employees using unauthorised AI tools with sensitive data)
  • Process gaps between AI recommendation and final decision-making authority

Legal / Copyright

  • Use of copyrighted material in training data without authorisation
  • IP infringement in AI-generated outputs (text, images, code)
  • Liability exposure for AI-driven decisions or advice (e.g., erroneous credit denials)

Compliance and regulatory risks

  • Non-compliance with regulations such as EU AI Act, DORA, GDPR, sustainability-related laws and regulations, etc.
  • Lack of explainability conflicting with "right to explanation" requirements
  • Regulatory divergence across jurisdictions creating compliance complexity

Environmental harm

  • High energy consumption and carbon footprint from training/running large models
  • Water usage for data centres cooling
  • Lack of transparency/reporting on AI's environmental impact

Reputational risks

  • Public-facing AI failures (biased outcomes, embarrassing generative AI outputs)
  • Gap between marketed AI capabilities and actual performance (AI-washing)
  • Loss of customer trust following data breaches or biased decision-making

Beyond risks arising from direct use of AI, there is a range of broader impacts emerging across the economy. Examples include:

  • Portfolio impacts

As AI reshapes entire industries, banks with concentrated lending exposure to affected sectors face a growing form of credit risk driven by technological displacement rather than traditional cyclical factors. Borrowers may see declining revenues or business model obsolescence within timeframes shorter than the tenor of existing loans — a five- or ten-year loan underwritten on historical cash flows may no longer reflect a borrower's ability to repay if its industry is disrupted mid-term, and defaults could cluster rather than remain idiosyncratic.

  • Collateral impacts

AI-driven industry transformation also threatens collateral values and raises concentration concerns. Loans secured against physical assets — commercial real estate, specialised manufacturing equipment displaced by AI, or retail inventory disrupted by AI-driven e-commerce — may see collateral values decline faster than amortisation schedules assume, increasing loss-given-default.

  • Strategic / business impact

Competition among AI developers or state-like actors racing to develop, deploy and apply AI systems for strategic or economic advantage increases the risk of long-term impact on business sustainability and strategic relevance.

The CRO's imperative: act before scale, not after

AI as enabler and AI as risk source both deserve high prominence on CROs' and risk teams' agendas.

Indeed, the institutions that will successfully navigate this AI paradox are those that build governance architecture before AI deployment scales. Retrofitting governance onto AI systems already in production is dramatically harder — technically, operationally and politically — than designing it in from the outset.

The CRO who positions their function to lead on AI governance will earn a strategic seat at the table as their institution's AI capabilities expand. The CRO who waits will find the function defining AI governance without them.

Five “non-regret” actions for CROs

The CRO should support AI risk awareness across the three lines of defence, ensuring business units, model developers, and risk and control functions understand AI-specific risks and build AI literacy progressively. A genuinely risk-aware culture will prove a more durable safeguard than any single control or policy.

Commission a comprehensive inventory of all AI-based tools in use across the institution and classify each application against the AI Act's risk tiers. This inventory is the foundation of everything else.

Existing MRM frameworks covering model development, validation, monitoring and decommissioning must be extended to address ML-specific challenges — explainability, feature importance, performance stability under distributional shift, and bias testing.

AI oversight should be integral to the board risk committee, which must be equipped to challenge AI-related risk decisions — how a model was validated, its performance boundaries, what override mechanisms exist — with KRIs integrated into risk appetite statements.

For every AI tool procured externally, due diligence must answer questions like

  • Can we audit this model?
  • Do we have access to training data documentation, validation evidence and ongoing performance monitoring?
  • Does the vendor's contractual framework give us the rights that DORA, AI Act require?

Where the answer is no, the institution must either negotiate the necessary access or consider building the capability internally.

Conclusion

The paradox is real, but it is manageable with the right leadership at the right time. AI is genuinely transformative for the risk function, while also introducing risks that are distinctive and require deliberate governance responses.

The CRO's role is to be the institutional anchor for responsible AI adoption — not to block innovation, but to ensure AI systems are understood, validated and governed, especially for high-risk use cases, and that regulatory compliance is not undermined.

The institutions that build this capability now, before their AI footprint scales, will find that governance and innovation are not in tension. They are, properly understood, the same thing.

Contact us

Elena Kazmina

Director, Banking Risk, Regulatory & Compliance, PwC Luxembourg

Tel: +352 49 48 48 3620

Andreas Braun

Advisory Managing Director, Data Science & AI Team Lead​, PwC Luxembourg

Tel: +352 62133 23 66

Follow us