The 2008 VaR Model Replay#
History Doesn’t Repeat Itself, But It Often Rhymes.
The year is 2008. The global financial system is on the brink of collapse. The cause? A complex web of factors, to be sure, but at the heart of the crisis was a simple and seductive idea: that risk could be quantified, that it could be reduced to a single number, a “Value at Risk” or “VaR.”
The VaR model was a triumph of mathematical elegance and of regulatory convenience. It was a tool that promised to make the financial system safer, more efficient, and more profitable. And for a time, it seemed to work.
But the VaR model was built on a foundation of flawed assumptions. It was a model that was designed for a world of normal distributions, of gentle curves and predictable outcomes. It was a model that was blind to the reality of “fat tails” and “black swans,” of sudden and catastrophic events that defy all prediction.
When the crisis hit, the VaR model failed. And it failed spectacularly. The very tool that was supposed to manage risk had become the primary source of it.
The Mechanism of Systemic Synchronicity#
Today, we are making the same mistake again—but at a scale and velocity that makes 2008 look like a trial run.
The Financial Stability Board (FSB) and other global regulatory bodies have issued critical warnings regarding a phenomenon of “herding behaviour” and “market correlations” driven by the use of common data and common models. This risk mirrors the structural causes of the 2008 financial crisis but operates at a velocity and scale that renders traditional circuit breakers ineffective.
In 2008, banks running similar Value-at-Risk (VaR) models responded to rising volatility by deleveraging in the same direction at the same time—a procyclical feedback loop that researchers argue amplified the crisis, even if it did not single-handedly cause it.1 Today, the homogenization of AI foundation models creates the same dynamic—but the cascade can happen in milliseconds, not weeks.
What the numbers actually show:
- Adoption is real and rising. As of the 2024 Bank of England / FCA survey, 75% of UK financial firms already use AI, with a further 10% planning to within three years.2 But this is broad AI, not a monoculture yet—the same survey found foundation models make up only 17% of all AI use cases, and a third of AI use cases are third-party implementations.2
- Concentration is the vulnerability. Where generative foundation models are used, they cluster around a handful of providers—GPT, Claude and Gemini families—creating a narrowing base of shared model logic in risk and credit workflows. The FSB warns that this reliance on “common data and models” can produce correlated behaviour across firms.3
- Trading is following. AI adoption in trading is rising fast: US globally systemic banks (G-SIBs) have filed over 1,400 AI-related patent applications in a decade, and the technology increasingly converges on a small set of shared architectures and data sources.3
When models are trained on the same history, they can hallucinate the same future.
The diversity of the AI ecosystem is an illusion. Under the hood, the vast majority of these systems are powered by the same handful of foundation models from the same handful of companies. They are:
- Trained on the same datasets (Common Crawl, financial news corpuses, economic indicators)
- Built on the same architecture (Transformer variants)
- Optimized with the same techniques (RLHF, supervised fine-tuning)
- Aligned with the same regulatory frameworks (Basel III, Dodd-Frank)
The result: A new and more dangerous form of algorithmic monoculture. The models are more sophisticated, the data more granular, but the underlying logic is converging. When one model sees risk, they all see risk. When one tightens credit, they all tighten credit. Synchronously.
The FSB’s 2024 report on the financial-stability implications of AI names “market correlations” from common models and data as one of four core vulnerabilities—alongside third-party dependency, cyber risk, and model risk.4 Its October 2025 follow-up is more sobering still on the supervisory blind spot: it notes that only a few authorities yet ask firms to rank the systemic risk arising from “herding behaviour and the use of common data and models.”3 Model opacity means these correlations may not be identified until they manifest as a crisis.
The Millisecond Cascade#
Here is the danger stated plainly. People compare this to 2008, and they are right to be uneasy. But 2008 was a slow-motion disaster. VaR-driven deleveraging took days or weeks to fully cascade. Homogenized AI systems can do the same thing in milliseconds. The precedent is not theoretical: on 6 May 2010, correlated algorithmic market-makers running similar signals simultaneously withdrew liquidity from US equity markets, and the Dow fell roughly 1,000 points in minutes before recovering—the “Flash Crash,” documented in the joint SEC/CFTC report.5 That was one asset class, one afternoon. Now imagine the same reflex spanning credit, logistics, and liquidity at once.
Consider a hypothetical stress event in May 2027. The specific timings and figures below are illustrative—a thought experiment, not measured data—but the mechanism is real:
Trigger: A geopolitical shock triggers volatility in energy markets. Perhaps a critical undersea cable is severed, or a major oil facility goes offline unexpectedly.
T+0ms: Market data hits the trading clusters. News APIs parse headlines. Sentiment analysis algorithms flag “high uncertainty.”
T+50ms: Homogenized AI trading agents across all major firms, analyzing the same news feeds with similar “sentiment analysis” weights, simultaneously decide to dump liquidity in emerging market debt. Thousands of sell orders hit the order book in the same 10-millisecond window.
T+100ms: Simultaneously, credit risk models at major banks, sensing the volatility via API feeds, automatically tighten lending criteria by 40-60 basis points across the board. Small businesses see credit lines frozen. Trade finance disappears. Letters of credit become unavailable.
T+200ms: Supply chain AIs, reacting to the credit tightening and energy price signals, cancel inventory orders globally to preserve cash. Just-in-time logistics networks begin unwinding. Container bookings are cancelled. Warehouse orders are put on hold.
T+300ms: Liquidity providers, seeing the coordinated selling, widen spreads dramatically. Market depth evaporates. Circuit breakers trigger in equity markets, but credit markets have no such protections.
T+500ms: The first human traders notice unusual market behavior. By the time they can comprehend what’s happening—let alone convene a risk committee or call a regulator—the cascade is complete.
The result is a “Flash Crash” not just of stock prices, but of the real economy—credit, logistics, and liquidity—before a human regulator can even convene an emergency meeting.
Traditional financial circuit breakers are designed for human-speed panics. US rules pause a single stock for 5 minutes (Limit Up-Limit Down) or halt the whole market for 15 minutes at Level 1 and Level 2, up to a shutdown for the rest of the trading day at Level 3—all built to give humans time to assess and decide.5 But these mechanisms are useless when the decision cycle operates at sub-second speeds and spans not just trading but credit allocation, supply chain logistics, and infrastructure management.
And the supervisors know they are behind. The FSB’s October 2025 report finds that only a handful of authorities yet monitor the systemic risk from “herding behaviour and the use of common data and models.”3 By the time such correlations manifest, it is too late. The models are black boxes. The correlations are emergent properties of shared training data and architecture. There is no “off switch” that can be pulled without shutting down the entire financial system.
Outcome Homogenization: When “Personalized” Means “Identical”#
The most insidious aspect of AI homogenization is not just systemic risk—it’s outcome homogenization at the individual level.
Research on algorithmic monoculture demonstrates that even when institutions use “custom” models, if those models share the same architecture (e.g., the Transformer) and pre-training data (Common Crawl, standard financial corpuses), they tend to fail on the same individuals—producing correlated outcomes for specific people or groups.6
The “Universal Rejection” Effect:
If Bank A’s AI denies a loan to a specific applicant based on obscure correlations in their data footprint—perhaps a pattern in their transaction history, their social media activity, or their geographic location—Bank B’s AI, trained on similar patterns, is disproportionately likely to do the same. A denial by one lender’s model is echoed by the others.
This creates a “universal rejection” effect where an individual or business is not just denied by one vendor, but risks being algorithmically exiled from the entire financial system at once—eroding the “second opinion” that a diverse market is supposed to provide.
There is no second opinion in a homogenized system.
In theory, there could be a “Rashomon set” of equally accurate models that arrive at different conclusions—model diversity without sacrificing performance.7 But in practice, efficiency pressures and regulatory compliance demands drive all vendors toward the same optimal (and biased) weights.
Concrete example:
A small farmer in Iowa applies for an equipment loan. Bank A’s model flags them as “high risk” because:
- Their geographic region has high climate volatility (drought risk)
- Their business model doesn’t include expensive carbon tracking software
- Their ESG score is “undefined” (too small to be rated by third-party services)
The farmer tries Bank B, Bank C, and a fintech lender. All deny the application with minimal explanation. Why? Because all four institutions use foundation models trained on the same ESG compliance corpuses, the same climate risk datasets, and the same historical default data.
The farmer is not high risk. The farmer is algorithmically unbankable.
This is not hypothetical discrimination—it is emergent discrimination, arising from the complex interaction of training data, model architecture, and regulatory frameworks. And because it is emergent rather than explicit, it is nearly impossible to challenge or remedy under current legal frameworks.
Civil rights law, including “disparate impact” doctrine, requires proving that a specific policy or rule caused discrimination. But when the discrimination emerges from a billion-parameter neural network’s feature interactions, there is no “policy” to challenge—a gap legal scholars have flagged as big data’s disparate impact.8 The model simply learned that certain patterns correlate with risk—patterns that happen to perfectly align with protected class membership or geographic/economic marginalization.
The victim of this process has no recourse. They are trapped in a Kafkaesque loop where:
- The decision-maker is a non-human entity that cannot explain its reasoning
- The bank claims it is simply following “data-driven risk management protocols”
- The model vendor disavows responsibility for specific outcomes
- The regulator lacks the technical tooling to audit a billion-parameter neural network in real-time
- The homogenization means there is no alternative vendor to turn to
This creates a class of “algorithmically unbankable” entities—individuals, small businesses, entire communities—permanently excluded from the formal economy not by explicit policy, but by the invisible hand of correlated machine learning.
Sources#
Institute for New Economic Thinking at the Oxford Martin School, “Did Value at Risk cause the crisis it was meant to avert?” — https://www.inet.ox.ac.uk/news/value-at-risk ↩︎
Bank of England / Financial Conduct Authority, Artificial Intelligence in UK Financial Services 2024 (21 Nov 2024) — 75% of firms already use AI; foundation models = 17% of AI use cases; one-third of use cases are third-party. https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024 ↩︎ ↩︎
Financial Stability Board, Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector (10 Oct 2025) — “herding behaviour and the use of common data and models”; US G-SIBs filed over 1,400 AI-related patent applications in ten years. https://www.fsb.org/uploads/P101025.pdf ↩︎ ↩︎ ↩︎ ↩︎
Financial Stability Board, The Financial Stability Implications of Artificial Intelligence (14 Nov 2024) — names four vulnerabilities including “market correlations.” https://www.fsb.org/uploads/R14112024.pdf ↩︎
U.S. Securities and Exchange Commission & Commodity Futures Trading Commission, Findings Regarding the Market Events of May 6, 2010 (30 Sept 2010) — the Flash Crash report; also documents US circuit-breaker/LULD mechanics. https://www.cftc.gov/sites/default/files/idc/groups/public/@economicanalysis/documents/file/oce_flashcrash0314.pdf ↩︎ ↩︎
Rishi Bommasani et al., “Picking on the Same Person: Does Algorithmic Monoculture lead to Outcome Homogenization?” NeurIPS 2022. https://arxiv.org/abs/2211.13972 ↩︎
Lesia Semenova, Cynthia Rudin & Ronald Parr, “On the Existence of Simpler Machine Learning Models” (the Rashomon set / model multiplicity), 2022. https://arxiv.org/abs/1908.01755 ↩︎
Solon Barocas & Andrew D. Selbst, “Big Data’s Disparate Impact,” 104 California Law Review 671 (2016). https://www.californialawreview.org/print/big-datas-disparate-impact ↩︎