Systemic Risk
What is Systemic Risk?
The term ‘system risk’ denotes the potential for large-scale cascading effects of a malfunction across critical societal infrastructures. It is used to describe any risk which does not operate in isolation, but threatens to destabilize an entire sector or industry. The term first gained significance in the financial sector, and is subsequently used across environmental, health and now the AI sector. Since the term finds its roots in the finance sector, its dictionary definition states that is is the risk associated with the failure of one financial institution, which could cause grave harm to other interconnected institutions or the economy as a whole.[1] This term has been contextualized to apply to any sector wherein there are identifiable risks which have the ability to trigger massive detrimental side effects.
Systemic Risk in AI
Interestingly, the initial deliberations of systemic risk vis a vis AI/ AI adjacent technologies is also in connection to the finance sector, in 2010, when nearly 1 trillion in market value was wiped off within a matter of minutes in the US stock market due to flaws in the automated trading systems.[2] With the evolution of AI, the systemic risks in AI and AI Governance are being deliberated by culling out the possible large-scale detrimental effect of AI on essential sectors such as finance, health etc.
Official Definition of System Risk
There exists no internationally accepted definition of ‘systemic risk’ in AI. Though explicit verbatim usage or definition of the term is rare in legislations and courts, some international legislations have attempted to define the term. Indian legislations however, do not have any official legal definition for systemic risk in the context of AI. The only legislative definition for systemic risk exists in The Payment and Settlements Act, 2007, which defines it as a disruption of the stability of the entire system due to the shortfall of a participant of the system.[3]
Systemic Risk as Defined in Official Government Reports
National Strategy For Artificial Intelligence (2018) (Niti Aayog)
The National Strategy for Artificial Intelligence encouraged deliberation of the probable factors with respect to AI ecosystems that may undermine or affect the ethical conduct, individual privacy or national security protocols.[4] This explanation could be construed as Niti Aayog’s understanding of systemic risks when it comes to AI.
Discussion Paper for Responsible AI (2022) (Niti Aayog)
The Discussion Paper for adopting Facial Recognition Technology uses the term systemic risk in the context of any identified considerations that ought to be kept in mind and mitigated in using and deploying FRT.[5]
India AI Governance Guidelines (2025) (MeitY Guidelines)
The term ‘systemic risk’ is used, and reflected in the language of, emerging policy and regulatory discourse such as MEITY’s India AI Governance Guidelines. The Guidelines formulate an inclusive definition whereby systemic risk is said to include disruptions in the value chain of AI due to factors such as market concentration, geopolitical instability or changes in regulatory guidelines.[6]
Strengthening AI Governance Through Techno-Legal Framework (2026)(PSA)
The white paper proposes a framework to govern AI which integrates the obligations and restrictions of law into the system of technological design, contrary to the existing post deployment regulation. The paper proposes building AI tools that are responsible by design which adequately address the risks in all the stages of AI development. These stages are classified into AI data collection, usage, training, safety and even includes Agentic AI. The risk at each of these stages are determined based on the potential impact that would arise from the negligence of such risk. [7]
International Instruments
Reports by International Organisations
Policy Measures to Address Systemically Important Financial Institutions (2011)(Financial Stability Board)
At the outset, The Financial Stability Board proposed policy measures to address ‘Systemically Important Financial Institutions’. What this policy meant by ‘systemically important’ were the entities that had the influence to destabilize the economy if they were to be in distress or failure.[8] This exercise of categorisation is what translates to identification of risks that are systemic i.e., capable of immense detrimental effect.
Guidance for Risk Management of AI systems (2025)(European Data Protection Supervisor)
The report discusses the main risks associated with data protection in the context of Artificial Intelligence. Systemic Risk in this context is understood as any event that leads to a situation which would cause impediments to the exercise of the data subjects' fundamental rights. Such systemic risks are categorised on the basis of their effect on fairness, accuracy, security, data collection/ storage, and the inherent rights of the data subjects as per the GDPR.[9]
Recommendation of the Council of Artificial Intelligence (2019)(OECD AI principles)
Additionally, as per OECD AI Principles, any risk of harmful bias, risk to safety and security, to privacy and even intellectual property rights are to be considered as risks capable of causing grave injury to substantial verticals of the market.[10]
International Experience
Legislations in the European Union
Digital Services Act (2002)
The 2022 amendment to the Digital Services Act in EU categorises systemic risk vis a vis very large online platforms/ search engines. According to the amendment, any apprehension of societal or economic harm, and the severity of the potential impact of such harm denotes ‘systemic risk’.[11]
EU AI Act (2024)
In the context of AI, the only enforceable legislation to have culled out a definition for systemic risk is the EU AI Act. The Act defines systemic risk as the capability of general purpose AI models to have significant foreseeable negative effects on public health, safety, fundamental rights or the society as a whole. Such high-impact risk capabilities shall have the ability to scale across its existing value chain.[12] Article 51 of the EU AI Act provides a delimitation criteria for identifying General Purpose AI models with systemic risk. This provides insight as to what is considered ‘systemic risk’ under the EU AI Act, i.e., any risk which has high impact capabilities based on appropriate technical tools, indicators and methods.
Judicial Analysis
Indian Courts
Judicial deliberations describe systemic risks in the context of profiling, bias and hallucinated content as a resultant of implementation of AI. The judicial language may not always contain the verbatim replication but the contextuality of the discussion shows that large scale negative implications of AI are considered systemic risk. The Puttaswamy judgment [13] could be extrapolated to be applicable in the context of AI as well. The judgment considers technological intrusion of autonomy or privacy of individuals as a violation of fundamental rights. In this context, systemic risk includes any AI related risk that violated the fundamental rights of individuals. The Supreme Court recently observed that relying on AI generated judgments in orders threatens the integrity of the entire adjudicatory process.[14] Kerala HC’s AI policy deliberates systemic risk along the lines of violation of privacy rights, data security risks and the erosion of trust in judicial decision making.[15]
International Deliberation
Internationally courts have deliberated risks in AI across various industries including the judiciary. In Mata Vs Avianca, the US District Court recognised that hallucination effects i.e., creation of fake precedents and citations challenges the foundation of legal research and poses a threat to the fabric of the judiciary.[16] In State Vs Loomis, the use of AI profiling tool highlighted bias and opacity of decision-making to impact credibility of AI tools.[17] Several cases across jurisdictions are confronting the harms arising from AI usage that transcend individual harms to ones that have the potential to destabilize industries and economies. While ascertaining these risks however, the courts fail to explicitly establish the nature of such risks. A clear identifiable definition for what attributes a ‘systemic risk’ would benefit a holistic approach to AI risk-identification as opposed to the current fragmented scenario.
Research that engages with ‘systemic risk’
AI, Digital Platforms, and the New Systemic Risk
The paper defines ‘systemic risks’ as risks that are highly complex, consisting of multiple uncertainties and ambiguities, and having a transgressive effect on the system it originates from and potentially other systems as well. It is said to denote interdependent, cascading failures across interconnected systems.[18]
Machine Intelligence, Systemic Risks, and Sustainability
The paper defines systemic risk as risks that evolve from complex interactions amongst humans, machines and the environment that could possibly lead to disruption that propagates through these different systems through the process of contagion.[19]
Systemic AI Risk is Slipping Off the International Agenda. Should we care?
The paper discusses the oversight of systemic risk in the fast paced technological race of AI. The requirement of pre-deployment regulation of AI to mitigate risks may seem extreme but it is deemed required in order to outweigh the catastrophic effects of such risks. The regulation of 'frontier models' i.e., models that are closest to mimicking human intelligence is deemed most crucial due to the elevated risk in such systems.[20]
Charting Systemic Risk Management as a regulatory paradigm in EU digital legislation
The paper traces the systemic risk centric approach of EU legislations in the sphere of technology and innovation. It proposes framing of a central, single risk management regime for AI which would enable comprehensive implementation of the framework established through multiple legislations.[21]
AI Governance in India: A Case Study
The case study, developed by the National e-Governance Division, points out the inadequacies of the policies in setting up of a comprehensive regime to mitigate or manage systemic risks. The need for clear demarcation of responsibilities, standards of procedure, accountability and inter-departmental coordination is highlighted. Significant AI systemic risk is observed in the sectors of healthcare, finance and agriculture. [22]
Challenges and Way Forward
The main challenge is that systemic risk due to AI is ever growing and ever changing due to the speed at which technology grows. Artificial Intelligence is being incorporated in every avenue, vertical and industry be it arts, law, design, health or technology. Such extensive incorporation requires prior considerations which were not undertaken. Once AI has already been incorporated, the systemic risk is no longer conceptual but a study of reality. Pre-emptive deliberations to define what entails ‘systemic risks’ in the context of AI would have provided the systems with enough safeguards and information to protect themselves. We are now at a crossroads wherein the systemic risks of AI are being studied and identified in real time through any and all instances of rampant negative impacts.
Though the EU AI Act defining systemic risk is a step in the right direction, the focus of the act is mainly on technology and platforms. Many countries including India have deliberations of systemic risk in their reports and discussions but no formal definition of the same. Any discussion or resulting legislation in that manner would prove futile without firstly defining systemic risk in the context of AI. A comprehensive definition of the term would guarantee uniform, successful implementation of the intended protection or procedure. Formulation of legislations which properly define systemic risk in AI, its scope, applicability and protections available vis a vis such systemic risk is extremely crucial. Global agreement on the term’s definition would also greatly aid effective AI risk management.
- ↑ Merriam-Webster Dictionary, ‘Systemic risk’ https://www.merriam-webster.com/dictionary/systemic%20risk accessed 18 March 2026
- ↑ Goehmann M, ‘AI and the stock market: are algorithmic trades creating new risks?’ (London School of Economics and Political Science, 23 September 2025) https://www.lse.ac.uk/research/research-for-the-world/ai-and-tech/ai-and-stock-market accessed 20 March 2026
- ↑ Payment and Settlement Systems Act 2007, s 2(o)
- ↑ NITI Aayog, National Strategy for Artificial Intelligence (#AIforAll) (June 2018) https://www.niti.gov.in/sites/default/files/2023-03/National-Strategy-for-Artificial-Intelligence.pdf accessed 18 March 2026
- ↑ NITI Aayog, Responsible AI for All: Adopting the Framework – A Use Case Approach on Facial Recognition Technology (November 2022) https://www.niti.gov.in/sites/default/files/2022-11/Ai_for_All_2022_02112022_0.pdf accessed 18 March 2026
- ↑ Press Information Bureau, Government of India, India AI Governance Guidelines (November 2025) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf accessed 19 March 2026
- ↑ Office of the Principal Scientific Adviser to the Government of India, Strengthening AI Governance Through Techno-Legal Framework (White Paper, January 2026) https://psa.gov.in/CMS/web/sites/default/files/publication/AI-WP_TechnoLegal.pdf?utm accessed 12 April 2026.
- ↑ Financial Stability Board, Policy Measures to Address Systemically Important Financial Institutions (4 November 2011) https://www.fsb.org/uploads/Policy-Measures-to-Address-Systemically-Important-Financial-Institutions.pdf accessed 18 March 2026
- ↑ European Data Protection Supervisor, Guidance for Risk Management of Artificial Intelligence Systems https://www.edps.europa.eu/system/files/2025-11/2025-11-11_ai_risks_management_guidance_en.pdf (11 November 2025) accessed 9 April 2026.
- ↑ OECD, Recommendation of the Council on Artificial Intelligence (22 May 2019, as amended 3 May 2024) OECD/LEGAL/0449 https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449#mainText
- ↑ Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC (Digital Services Act) [2022] OJ L 277/1 https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng
- ↑ Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689/1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- ↑ Justice K.S.Puttaswamy (Retd) v Union of India (AIR 2018 SC(SUPP) 1841)
- ↑ Gummadi Usha Rani v Sure Mallikarjuna Rao 2026 SCC OnLine SC 341
- ↑ High Court of Kerala, Policy Regarding Use of Artificial Intelligence Tools in District Judiciary (Memorandum, 19 July 2025) https://images.assettype.com/theleaflet/2025-07-22/mt4bw6n7/Kerala_HC_AI_Guidelines.pdf accessed 21 March 2026
- ↑ Mata v Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023).
- ↑ State v Loomis, 881 N.W.2d 749 (Wis. 2016).
- ↑ Hacker P, Kasirzadeh A and Edwards L, AI, Digital Platforms, and the New Systemic Risk (2025) https://arxiv.org/pdf/2509.17878 accessed 18 March 2026
- ↑ Galaz V and others, Machine Intelligence, Systemic Risks, and Sustainability (Beijer Discussion Paper Series No 274, 2021) https://beijer.kva.se/wp-content/uploads/2021/06/Disc274_Galaz-et-al_2021.pdf accessed 21 March 2026
- ↑ Brouwer J, ‘Systemic AI risk is slipping off the international agenda. Should we care?’ (Oxford Insights, 3 April 2025)https://oxfordinsights.com/insights/systemic-ai-risk-is-slipping-off-the-international-agenda-should-we-care/ accessed 9 April 2026.
- ↑ Palumbo A, ‘Systemic Risk Management as an Emerging Regulatory Approach in EU Digital Legislation: Salient Features and Outstanding Challenges’ (2026) Technology and Regulation 1–17 https://techreg.org/article/view/23131/27073 accessed 11 April 2026.
- ↑ Ojha A, AI Governance in India: A Case Study (National e-Governance Division, February 2026) https://negd.gov.in/wp-content/uploads/2026/02/Astha-Ojha-AI-Governance-in-India-Final-4.pdf accessed 18 March 2026.