
The Same Governance Test, A Different Risk
TL;DR
Financial institutions' balance sheet exposure to the AI infrastructure buildout (direct lending, commercial real estate financing, NBFI and private credit counterparty exposure, and market risk holdings) now totals roughly $450 billion in committed large-bank C&I exposure alone, about 25% of tier 1 capital on a committed basis, against a global data centre capital requirement projected at $3 trillion through 2028. Most mid-tier institutions have not named this as a distinct, correlated risk category, aggregated it across the sector codes where it hides, or brought it inside the same governance architecture already applied to climate risk. Selling exposure down through significant risk transfer changes where the risk sits, not whether it is governed.
The industry spent the better part of a decade learning to integrate climate risk into its risk taxonomy. It is about to relearn the same lesson, faster, about AI infrastructure.
A familiar shape, five years later
Five years ago, climate risk sat in a sustainability report. It was acknowledged, disclosed, discussed at committee level, and largely absent from the credit, capital, and market risk frameworks that actually govern financial exposure. It took years of supervisory pressure, several thematic reviews, and a number of expensive lessons before that started to change. The earlier articles in this series have traced exactly how, and how incompletely, that change has happened.
AI infrastructure exposure is following an almost identical path, only faster. Financial institutions are extending credit to, investing in, underwriting, and increasingly depending on a buildout of AI infrastructure, data centres, power generation, chip financing, that now ranks among the largest capital allocation cycles in corporate history. Cloud and hyperscale companies are expected to spend in the region of three trillion dollars on data centre projects through 2028. Most of that is being financed with debt, not cash flow.
This article is not about whether an institution's own use of AI is well governed. That is a live and separate question. It is about something narrower, and for most boards, considerably less visible: whether the institution's balance sheet exposure to the AI infrastructure buildout, as a lender, investor, insurer, or counterparty, has been named as a risk category, aggregated across the places it hides, and brought inside the same governance architecture that already governs climate risk. In most mid-tier institutions, the honest answer is no.
Where the exposure actually sits
The exposure is not exotic. It sits in places most institutions already have, spread across categories that were never designed to be read together.
Direct lending is the largest and most visible piece. Recent Federal Reserve Bank of Chicago analysis puts large US banks' commercial and industrial commitments to AI-adjacent borrowers at roughly $450 billion, with around $150 billion outstanding as of late 2025. That is a modest 0.8 percent of average bank total assets. On a committed basis, against tier 1 capital, it reaches roughly 25 percent, a very different picture.
Commercial real estate is the second piece. Banks are financing data centre construction directly, including single loans of striking scale, Stargate's construction financing alone runs to $7.1 billion. Taken in isolation, this exposure looks manageable against tier 1 capital. Taken together with the direct lending above, it starts to describe a concentrated bet on one capital cycle.
The third piece is the hardest to see. Banks lend to non-bank financial institutions, private credit funds, and infrastructure vehicles that themselves hold AI-adjacent debt and equity. This indirect exposure is, in the Federal Reserve's own words, difficult to quantify with existing regulatory data. That is precisely the description that used to apply to transition risk in a loan book before institutions began screening for it.
The scale of the exposure
A handful of figures make the scale concrete.
Metric | Figure |
|---|---|
Large-bank C&I commitments to AI-adjacent borrowers, late 2025 | ~$450bn committed, ~$150bn outstanding |
Those commitments as a share of tier 1 capital, committed basis | ~25% |
Software C&I commitments rated B or below | ~$50bn, ~26% of the book |
Projected global data centre capital requirement through 2028 | ~$3 trillion |
Projected annual growth of the global significant risk transfer (SRT) market | ~11% a year |
None of these figures, on their own, describes a crisis. Together, they describe an exposure large enough, concentrated enough, and fast-growing enough to need a name, an owner, and a place inside the risk taxonomy, exactly the standard this series has argued climate risk should meet.
Where it is already showing strain
Three specific weaknesses are visible in the data today, not as forecasts but as current conditions.
Credit quality. Roughly 26 percent, around $50 billion, of software commitments to AI-adjacent borrowers are rated B or below: speculative-grade credits dependent on continued capital injections and vulnerable to any tightening in financing conditions.
Correlation, not diversification. Stress in one AI-adjacent industry does not stay contained to it. A slowdown in software spending affects the semiconductor manufacturers building the chips, the energy providers powering the data centres, and the developers financing the buildings themselves. An institution with lending relationships across all four may believe it is diversified. It may simply be holding one bet, filed under four different sector codes.
Obsolescence and exit risk. Data centre construction is specialised, which limits what a lender can do with the collateral if a borrower fails. AI hardware generations turn over quickly. A loan underwritten against today's equipment and today's demand assumptions carries a shorter effective duration than its stated term.
The risk did not leave the system. It just left your balance sheet.
When a single borrower's capital programme is large enough, it can push several major lenders toward their own concentration limits. Oracle's roughly $300 billion buildout commitment has done exactly this, and banks have responded by shifting new AI infrastructure financing away from traditional syndication and into Rule 144A private placements, private credit funds, and infrastructure debt vehicles backed by pension and insurance capital.
The Bank for International Settlements has flagged this migration as a systemic concern in its own right. The entities now absorbing this exposure, pension funds, insurers, and private credit vehicles, do not carry the same capital requirements or resolution mechanisms as the banks the exposure came from. A project failure inside one of these vehicles flows more directly to the retirement assets of ordinary savers than a failure inside a regulated bank would.
Banks are also using significant risk transfer, selling credit-linked notes referencing AI-adjacent and data centre loan books to institutional investors, to manage concentration and free up balance sheet capacity. Morgan Stanley, Citigroup, JPMorgan Chase, and Goldman Sachs are all active in this market, and the global SRT market is projected to grow at roughly 11 percent a year over the next two years.
Significant risk transfer moves a loan off your balance sheet. It does not move the borrower out of the AI capex cycle, and it does not remove your counterparty's exposure to the same correlated shock.
This is the AI infrastructure version of a lesson this series has already drawn from the CSRD Omnibus: a mechanism that changes where an exposure is recorded does not change whether it is governed. An institution that has sold down its AI-adjacent loan book through significant risk transfer, and stopped tracking the underlying concentration once the loans left its books, has not reduced its risk. It has made the risk harder to see, for itself and for anyone assessing its governance from the outside.

The capital cycle behind the exposure: data centre buildout financed largely with debt, not cash flow.
What this looks like in practice
Take a mid-tier bank with a growing commercial and industrial book across software, semiconductor, and energy borrowers riding the AI infrastructure buildout. Each relationship sits with a different sector team. Each credit is approved individually, against strong current cash flow and a compelling growth narrative. Nobody in the institution has been asked to look at the four relationships together.
A large AI-adjacent software borrower restructures, or a hyperscaler pauses a capital programme. Within the same quarter, the semiconductor supplier, the regional data centre developer, and the energy project the bank financed all show stress. The credit committee discovers, only at that point, that four relationships it had underwritten as unrelated were, in substance, the same correlated bet.
None of that exposure was created by the quarter in which it surfaced. It was created months or years earlier, at origination, by a risk framework that had no category for AI infrastructure concentration and therefore never asked the aggregation question.
The supervisory attention is already forming
The Bank of England's Financial Stability Report, published in July 2026, flagged AI-related market concentration, leverage, and debt-financed infrastructure build-out as a genuine risk to financial stability, not a niche technology concern. The Financial Stability Board warned on private credit vulnerabilities in May 2026. The Federal Reserve Bank of Chicago has published bank-specific tail-risk analysis quantifying precisely the exposure described in this article.
None of this is a proposed AI-specific directive still working its way through a legislature. It is existing supervisory and central-bank attention, applied right now to an exposure that most mid-tier institutions have not yet named internally. Institutions that wait for a dedicated AI risk regulation before building governance around this exposure will find, as they did with climate risk, that the supervisory expectation existed well before the legislation caught up to it.
Where this sits for insurers and asset managers
The exposure is not confined to banks. Insurers carry it on two fronts at once: underwriting data centre construction and property risk directly, and holding AI-adjacent corporate bonds and hyperscaler equity inside investment portfolios, often without those two exposures ever being reconciled against each other or against reinsurance capacity.
Asset managers and private equity firms sit closest to where the risk is migrating. The private credit and infrastructure debt vehicles now absorbing the exposure banks are shedding are frequently marketed to institutional and, increasingly, retail-adjacent investors as stable, diversified infrastructure debt. A fund concentrated in AI infrastructure lending carries the same correlated exposure as the bank loan book it replaced, without the bank's capital requirements standing behind it, and often without investors being shown the concentration in terms that make it visible.
This is exactly the exposure category that belongs inside a firm's risk taxonomy alongside climate risk, not inside a separate AI policy owned by a technology or innovation function.
What integration requires
None of this requires new infrastructure. It requires the same four steps this series has already argued climate risk requires, applied to a different exposure.
Name the category. AI infrastructure exposure should be defined as a distinct, correlated risk category, not left scattered across unrelated sector codes where no one is asked to add it up.
Aggregate it. Exposure should be summed across direct lending, commercial real estate, NBFI and private credit counterparty exposure, market risk holdings, underwriting, and operational dependency on AI and cloud vendors, so the institution has a single figure, not five partial ones.
Assign an owner. Ideally the same risk function already accountable for climate risk integration, since the diagnostic questions, financial materiality, correlation, concentration, documented challenge, are identical.
Test it as one shock. Stress testing, ICAAP, and ORSA processes should model AI infrastructure exposure as a single correlated event, the way climate scenarios now are, rather than as isolated sector-by-sector assumptions. And significant risk transfer or private credit distribution should be tracked as risk mitigation, not treated as risk elimination, with the institution maintaining a view of where the transferred risk has actually landed.
Questions before the next board risk committee
Before the next Board Risk Committee or ICAAP cycle, six questions are worth putting on record.
Aggregate exposure. Could we produce, today, a single figure for our institution's total exposure to the AI infrastructure buildout across direct lending, commercial real estate, market risk holdings, NBFI counterparties, and underwriting?
Named ownership. Who owns AI infrastructure exposure as a risk category, and is it the same function accountable for climate risk integration, or an entirely different one?
Correlation, not diversification. Have we tested whether our AI-adjacent lending across software, semiconductor, and energy borrowers is genuinely diversified, or one correlated bet spread across several sector codes?
The transfer question. Where we have used significant risk transfer or private credit distribution to manage AI-adjacent exposure, do we still track where that risk actually landed, or did we stop watching once the loans left our books?
Concentration limits. Do our credit appetite and concentration limits treat AI infrastructure exposure as a distinct, correlated category, or does it still sit unnoticed inside ordinary sector-by-sector limits?
Stress testing. Has AI infrastructure exposure been modelled as a single correlated shock in our ICAAP, ORSA, or stress testing process, the way climate scenarios now are?
If those questions produce hesitation, the governance gap is already there.
Closing
The financial system has seen this pattern before. A financially material exposure grows quickly, sits outside the principal risk taxonomy because it does not fit neatly into any single existing sector code, and is treated as someone else's problem, the technology function's, the growth business's, the private credit market's, until a supervisor, a rating agency, or a correlated shock proves otherwise. Climate risk took the better part of a decade to move from acknowledged to governed. AI infrastructure exposure does not have a decade. The capital cycle it sits inside is measured in quarters.
Not sure whether your AI infrastructure exposure has been named, aggregated, and integrated into your existing risk taxonomy, or whether it is still scattered across sector codes nobody has connected? The ARCHITECT™ Governance Maturity Assessment gives mid-tier financial institutions a structured diagnostic over two to three weeks, applying the same rigour to this exposure that regulators already apply to climate risk.
Start the ARCHITECT™ Governance Maturity Assessment →
Sources
Author bio
Brendan Walsh is the founder of Walsh SRA and creator of the ARCHITECT™ Governance System. He brings more than 30 years of global executive leadership at American Express across the US, Europe and Asia, including as Chairman of American Express Services Europe and American Express Bank Russia. He has served as a Board Advisor to OFGEM, the UK energy regulator, and as a Board Member of the ECB's Euro Retail Payments Board. He holds a Master's in Sustainability from Harvard and GARP certifications in Sustainability & Climate Risk and AI Risk. Walsh SRA advises mid-tier banks, insurers, asset managers and private equity firms on governance for climate, sustainability and AI risk.