
Abstract Supervisory authorities are deploying large language models (LLMs) to assess disclosures, governance quality, and regulatory compliance. Most current applications extract verifiable facts from documents. The frontier, however, is evaluative: scoring qualitative dimensions—governance adequacy, risk culture, recovery plan credibility—for which no objective reference value exists. This article argues that evaluative LLM use is categorically different from any previously regulated form of supervisory modelling, for three structural reasons: the absence of ground truth against which outputs can be validated; the strategic ability of supervised institutions to game the evaluating instrument; and the systemic externalities created when many supervisors rely on the same few models. From these features it derives seven governance principles—three concerning the instrument itself, four concerning the institutional environment around it—and shows that no existing framework, including the EU Artificial Intelligence (AI) Act, the Digital Operational Resilience Act (DORA), and the European Banking Authority (EBA) Guidelines on PD and LGD estimation, satisfies them. It concludes with recommendations for supervisory authorities and standard-setting bodies.
The growing importance of European Union (EU) debt in recent years has led to significant institutional changes. Since 2020, the European Commission has taken on the role of managing the Union's debt, while the European Central Bank (ECB) has begun providing 'fiscal agent' services in support of this function. Specifically, the ECB holds the Commission's bank account for borrowing operations and acts as 'paying agent' for the securities issued, according to arrangements that may extend to future EU borrowing instruments. While article 21 of the Statute of the European System of Central Banks and of the European Central Bank allows central banks to act as 'fiscal agents' for public entities, this statutory task of the ECB has received little attention in legal scholarship. Traditionally, these functions have been performed by national central banks on behalf of their respective governments. The ECB's assumption of this role marks a departure from established practice within the Union and raises important legal and institutional questions. The article examines the nature and scope of the fiscal agent services, their implications for ECB independence and liability, and the nature of the ECB's relationship with the Commission and other institutions, such as the European Court of Auditors. In this way, the research contributes to the debate on the EU fiscal capacity and EU institutional balance.
Drawing on the London Stock Exchange's Alternative Investment Market (AIM) as a case study, this article analyses a hand-collected dataset of material rule revisions to the AIM listing rules from 1995-2025. Its principal finding is that the AIM listing rules evolve much more in earlier years (from 1995-2007) as compared to later years (2008-2025), with relatively long periods without any consequential rule changes. This pattern of rule evolution is consistent with theories of regulatory demand and regulatory learning, as well as the Exchange's goal of safeguarding reputation. It also emphasizes the importance of initial regulatory design. Some categories of rules are, proportionally, revised more than others, which is consistent with regulatory learning and gap-filling. Only limited evidence is found for regulatory shocks spurring rule evolution. AIM's forthcoming rulebook reform should be guided by a less risk-averse regulatory philosophy, cognisant of the importance of how these rules are interpreted and subsequently revised.
The current international regime for restructuring sovereign debt largely relies on consensual processes and contract law. This has enabled uncooperative distressed debt investors to realize high profits by insisting on full payment in situations where most creditors have already agreed to debt relief. To counter the disruptive effects of holdout creditors, Belgium, the United Kingdom, and France have enacted domestic laws limiting the enforceability of distressed sovereign debt. Recent proposals for similar legislation in New York and other jurisdictions seek to facilitate efficient and equitable sovereign debt restructurings more generally. While the policy debate is often reduced to a binary choice between 'statutory' and 'market based' approaches, a comparative analysis reveals a range of different solutions. This article surveys existing laws and proposals in the context of underlying legal concepts and policy concerns, identifying nine design choices that can inform the legislative process.
Tom Gosling's 2025 article, 'Universal Owners and Climate Change', asks an important question: Is it in universal owners' interest for warming to remain at or below 1.5 degrees C, and do universal owners have a plausible way of contributing to this outcome? The following response explores downside risk, tipping points and feedback loops, incrementalism, discount rates, climate models, and the efficacy and cost of available investor tools as they relate to universal owners, suggesting that they have an interest in keeping warming to 1.5 degrees C and that they have low-cost tools at their disposal to contribute to this goal.
Sustainable finance has become mainstream, with governments and stakeholders relying on financial players/channels to prod real economy firms into addressing environmental and social issues. An overlooked, yet significant problem with this idea is credit substitution-where firms replace their 'exiting' creditors or investors. This significantly weakens the effect of 'exit' and results in the migration of problems or risks associated with lending and investment to new entrants. This article examines credit substitution in theory and practice, focusing on its implications for sustainable finance. It argues that the current regulatory framework and broader ecosystem for financial institutions worldwide create conditions highly conducive to credit substitution. Key factors include substantial cross-jurisdictional differences in approaches towards sustainable finance among major financial centres and cross-sectoral differences within jurisdictions-particularly in the EU-where sustainable finance regulations vary between bank-based and market-based financing. These conditions undermine the effectiveness of sustainable finance policies. If the aim is to address environmental and social impacts in the real economy, such policies are diluted; alternatively, if focused on managing financial risks associated with lending to and investing in firms causing these impacts, the result is only migration, rather than mitigation, of risks. The article concludes with policy implications.
The EU's supervision of financial markets remains fragmented and misaligned with the depth of market integration achieved through initiatives such as the Capital Markets Union (CMU) and the Savings and Investment Union (SIU). Political resistance to centralizing supervision, particularly under the European Securities and Markets Authority (ESMA), has stalled reform, leaving a hybrid system of national oversight, mutual recognition, and limited supranational authority. This patchwork hampers consistency, weakens enforcement, and exposes the EU to inefficiencies and regulatory arbitrage-especially in fast-evolving cross-border segments like fintech, environmental, social and governance (ESG), and crypto-assets.This article proposes a supervisory efficiency test as a practical tool to assess whether supervisory arrangements correspond to the level of market integration for specific financial products, services, or actors. Rather than relying on political agreement over institutional reform, the test offers an evidence-based, task-specific approach to evaluate whether supervision is best handled nationally, through coordination, or centrally.If embedded systematically into the EU's regulatory process, the test could support a more coherent, proportionate, and adaptive supervisory architecture that evolves in step with Europe's financial markets.
With the overhaul of the regulatory framework in light of the financial crisis of 2007-2009 the concept of regulatory capital was significantly altered. Qualitative capital requirements, specifically those applicable to common equity tier 1 (CET1), were harmonized in a directly applicable European Regulation (the Capital Requirements Regulation (CRR)) to ensure that a common understanding of regulatory capital would exist between the EU Member States. Yet no direct effect that impacts the private law position of the CET1 holder was (seemingly) awarded to the qualitative requirements, creating certain inherent fragilities in the capital structure which mainly relies on adequate ex ante supervisory control. This article revisits the discussion as to whether the qualitative capital requirements in the CRR do have direct effect based on an analysis of the corpus of case-law that has been created since the introduction of the new regulatory framework. This article finds that although no absolute direct effect can be ascertained, there might be room for the application of a direct effect where financial stability is at stake and the CET1 instruments have entered their regulatory phase. Aspects that play a pivotal role in this potential direct effect are the limitation of fundamental rights, judicial review, and rationale of CET1 capital.
This article provides a comprehensive dataset on the terms and conditions (T&Cs) set by leading providers of crypto custody and wallet services. The sample studied reveals a dichotomy within the crypto custody industry: some custodians seek to protect their clients' rights and interests while others provide T&Cs at odds with any meaningful client protection. In such an environment, financial regulation can serve three purposes. It can promote a level playing field for crypto custodians, ensure an adequate level of client protection regardless of client due diligence, and reduce the likelihood of costly disputes, thereby lowering both information asymmetry and transaction costs. This article provides an overview of how crypto-assets are held in custody before outlining the research sample. The article then presents findings on custody practices, including safekeeping, key storage, outsourcing, asset segregation, insolvency protection, client entitlements, reuse, liability cap, and choice of law, courts, and arbitration. Finally, the argument and conclusion are set out.
Retail payment fraud has become a structural challenge that no longer falls solely within the remit of payment service providers. As transactions flow through increasingly fragmented digital ecosystems, the mismatch between where fraud occurs and where liability resides is becoming unsustainable. This article examines how modern fraud exploits institutional asymmetries and identifies the need for a realignment of preventive duties and financial responsibility. Drawing on international experiences-from Singapore's cascading liability model to the UK's reimbursement regime-it argues that effective fraud prevention requires proportional accountability across the full value chain. The analysis then turns to the evolving European regulatory framework, highlighting its ambition but also its structural and legal constraints. The article concludes with policy recommendations aimed at fostering meaningful cross-sectoral cooperation, clarifying data-sharing rules, and institutionalizing shared accountability mechanisms. In doing so, it contends that fraud prevention and accountability are not separate goals, but rather two sides of the same coin.
Despite the significance of repurchase agreements (repos) in market-based finance, European repo markets remain underexplored. Drawing on monetary hierarchy literature, we make three conceptual arguments. First, we argue that repos' balance sheet mechanics differ depending on the counterparties' relative hierarchical position. Vertical repos across hierarchical levels imply money creation; horizontal repos lend on pre-existing money. Second, we conceptualize the 'inherently ambiguous' whereabouts of the security used as repo collateral: it becomes the lender's off-balance-sheet asset, paired with a liability to return it, while the Basel III regulations treat it as 'encumbered' on the borrower's balance sheet. Third, we propose an on-balance-sheet notation of collateral frameworks that illustrates their function as a central bank policy tool which influences central counterparties' general collateral baskets. Empirically, we study vertical repos of the Eurosystem and horizontal repos in European interbank markets with regard to their institutional evolution and principal role in the Eurocrisis. We show that in case of Eurosystem repos, the 'inherent ambiguity' helps conceal the security and enable sovereign debt funding compliant with the 'monetary financing prohibition'. In case of interbank repos, the 'inherent ambiguity' facilitates the security's effective bilocation as it gets simultaneously treated as the borrower's encumbered asset and as disposable for the lender's re-use.
As the European Union advances financial integration, eliminating regulatory and institutional barriers to interstate banking consolidation must become a priority. This is particularly relevant for large, systemically important financial institutions within the euro area, whose performance has ripple effects worldwide. Interstate consolidation offers numerous advantages: greater financial stability through diversification, improved market efficiency, and enhanced global competitiveness of European financial markets. It also supports internal EU goals, such as completing the Banking Union and advancing the Capital Markets Union, as emphasized by reports by Mario Draghi and Enrico Letta. However, regulatory fragmentation, political resistance, and prudential barriers remain significant obstacles. Achieving greater interstate consolidation requires a multi-faceted legislative strategy. Key actions include facilitating the formation and growth of cross-border financial groups by simplifying transaction mechanisms, ensuring an unfettered market for corporate control, and addressing prudential barriers; enhancing group-wide capital and liquidity management through revisions to the Capital Requirements Regulation to allow capital and liquidity waivers for EU subsidiaries; and establishing legal certainty in resolution frameworks by specifying enforceable conditions for intra-group asset transfers and loss-sharing arrangements during resolution. Without these reforms, EU financial fragmentation will persist, weakening Europe’s international competitiveness and leaving its markets vulnerable in an increasingly competitive global environment.
In recent years, the European Union (EU) has adopted a broad range of sustainable finance-related legislation, including the Corporate Sustainability Due Diligence Directive (CSDDD), the Sustainable Finance Disclosures Regulation (SFDR), and the Corporate Sustainability Reporting Directive (CSRD). This legislation abounds with direct and indirect references to human rights and business and human rights (BHR) frameworks like the UN Guiding Principles on Business and Human Rights (UNGPs). They provide for BHR disclosure obligations and conduct obligations for investors and their portfolio entities. However, these references have largely been overlooked by both the BHR and financial law communities, leading to important gaps in how investors understand their BHR obligations and the efforts required to implement them. This article makes two contributions to understanding the integration of human rights in EU sustainable finance. First, it conducts a review of the extensive human right provisions in EU sustainable finance-related legislation, including the CSDDD, SFDR, Taxonomy Regulation, and CSRD. It also examines their mobilization of established administrative and sanction mechanisms to monitor and enforce compliance. Second, it highlights important challenges arising from this integration, particularly concerning coherence and terminology. Coherence challenges stem from conflicting interpretations between EU sustainable finance-related legislation, and between EU legislation and international human rights and BHR frameworks. Terminological challenges arise from different understandings of key concepts, such as ‘risk’, between the BHR and financial law communities. This article examines possible responses to these challenges.
Combating illicit financial activity in permissionless blockchain-based financial systems—referred to as ‘decentralized finance’ or ‘DeFi’—has challenged regulators and policymakers. Traditional financial integrity laws and regulations—dealing with anti-money laundering (AML), countering the financing of terrorism (CFT), and sanctions—attach to intermediaries, including, with respect to AML/CFT obligations, those intermediaries the Bank Secrecy Act defines as ‘financial institutions’. This article proposes a framework to effectively detect, deter, and prevent illicit financial activity in DeFi, while preserving the technology as permissionless, neutral infrastructure. The three-part proposal sets forth a definition of ‘independent control’ in order to identify smart contract-based financial protocols that do not constitute DeFi; seeks to classify genuine DeFi protocols as ‘critical infrastructure’, subject to oversight and security coordination by the Treasury Department’s Office of Cybersecurity and Critical Infrastructure Protection; and suggests that new laws could require certain businesses necessary to the transmittal of communications about DeFi transactions to take on additional illicit finance risk-management practices without being subject to the Bank Secrecy Act.
This paper presents a stylized framework to assess conceptually how the financial risks of climate change could interact with a regulatory capital regime. We summarize core features of a capital regime such as expected and unexpected losses, regulatory ratios and risk-weighted assets, and minimum requirements and buffers, and then consider where climate-related risk drivers may be relevant. We show that when considering policy implications, it is critically important to be precise about how climate change may impact the loss-generating process for banks and to be clear about the specific policy objective. While climate change could potentially impact the regulatory capital regime in several ways, an internally coherent approach requires a strong link between specific assumptions and beliefs about how these financial risks may manifest as bank losses and what objectives regulators are pursuing. We conclude by identifying several potential research opportunities to better understand these complex issues and inform policy development.
Universal ownership theory proposes that widely diversified investors have a financial self-interest at the portfolio level in reducing market-wide risks relating to environmental or social (ES) issues. This article sets out a double test for determining when universal owner theory justifies investor action and applies these tests to the case of climate change. When applied to the commonly adopted goal of limiting global warming to 1.5 degrees C, universal owner theory runs into problems on both tests. First, it is uncertain whether this goal is financially optimal at the portfolio level. Second, even if it were optimal, investors have limited efficacy to achieve this outcome. This article considers goals that climate-concerned investors might set and the actions they could take that would be consistent with the tests. The actions best supported by evidence involve four areas of focus. First, engagement with investee companies based on realistic goals. Second, positive engagement on policy. Third, modest and bounded impact investments that can credibly be considered as reducing climate risk. Fourth, working to ensure that transition and physical risks are fully incorporated into investment models. Through targeting a more modest set of ambitions, climate-concerned investors can be more impactful while avoiding conflicts with fiduciary duties to clients.
Generative artificial intelligence (gen AI) introduces novel opportunities to strengthen central banks' cyber security but also presents new risks. This article uses data from a unique survey among cyber security experts at major central banks to shed light on these issues. Responses reveal that most central banks have already adopted or plan to adopt gen AI tools in the context of cyber security, as perceived benefits outweigh risks. Experts foresee that AI tools will improve cyber threat detection and reduce response time to cyber attacks. Yet gen AI also increases the risks of social engineering attacks and unauthorized data disclosure. To mitigate these risks and harness the benefits of gen AI, central banks anticipate a need for substantial investments in human capital, especially in staff with expertise in both cyber security and AI programming. Finally, while respondents expect gen AI to automate various tasks, they also expect it to support human experts in other roles, such as oversight of AI models.
The introduction of the Securities Financing Transactions Regulation into EU law provides a unique opportunity to obtain an in-depth understanding of repo markets. Based on the transaction-level data reported under the regulation, this article contributes to the literature with key facts about the euro area repo market. We start by providing the regulatory background, as well as highlighting some of its advantages for financial stability analysis. We then go on to present three sets of findings that are highly relevant to financial stability and focus on the dimensions of the different market segments, counterparties, and collateral, including haircut practices. Finally, we outline how the data reported under the regulation can support the policy work of central banks and supervisory authorities and contribute to the existing literature on repo markets. We demonstrate that these data can be used to make several important contributions to enhancing our understanding of the repo market from a financial stability perspective, ultimately assisting international efforts to increase repo market resilience.
ABSTRACT Authorized Push Payment (APP) fraud occurs where bank customers are tricked into transferring money from their account. As this article shows, this type of fraud is a growing threat, catalysed by the rise of remote banking. However, long-standing legal and regulatory rules leave most victims without a route to redress, as recently confirmed by the UK Supreme Court’s 2023 decision in Philipp v Barclays. Through this lens, the article examines a new and ‘world first’ UK regulatory response, which includes a mandatory reimbursement scheme for APP fraud victims in certain circumstances. The article finds that the UK’s new loss allocation scheme is valuable, but also that its specific coverage is problematic given the broad nature of this threat. Overall, the article argues that the priority for UK regulators should be to develop a more ‘joined-up’ response to APP fraud, and it offers generally applicable insights into effective regulatory responses to this evolving threat.