Federal Reserve Bank of New York

09/24/2026 | Press release | Distributed by Public on 09/24/2026 09:11

Nistor: Forging A Resilient Path

Speech

Forging A Resilient Path

September 24, 2026
Mihaela Nistor , Chief Risk Officer and Head of the Risk Group
Remarks at the Risk Live North America Conference, New York City As prepared for delivery

Good morning, everyone. It's great to be here again, and to navigate with you the changing landscape of our profession.

Operational risk used to be the function everyone forgot about until something broke. Necessary, but rarely central to strategic conversation.

That has changed, and it has changed because the nature of the risk itself has changed. And one of the biggest drivers of the change is artificial intelligence (AI).

Today I want to talk about AI from a slightly different angle. Not what AI can do, but what happens to the institution when AI does it.

Because the gap between technological acceleration and institutional adaptation is not simply a technology risk. It is an operational risk. And it belongs to us.

But before I begin, I should note that my remarks reflect my personal opinions and do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System.

Institutional Adaptation

Most conversations about AI and the workforce default to a simple binary: It will either create jobs, or it will destroy them. That framing is not particularly useful for the people in this room, because it skips past the part we actually manage.

I think about three aspects together: task exposure, deployment friction, and organizational redesign.

Task exposure tells us what can change. Deployment friction tells us how fast. Organizational redesign determines what happens next.

A task can be technically exposed to automation and still remain economically, legally, or operationally difficult to automate. Exposure is not displacement. Capability is not deployment. The distance between those two things is exactly where operational risk lives.

That distance is also where institutional fragility lives.

Large, systemically important institutions absorb technology slowly, often for very good reasons. Deployment is shaped not just by what the model can technically do, but by regulatory constraints, legal liability, legacy technology, data quality, workforce trust, cyber risk, low tolerance for operational failure, and leadership capability. We require governance, controls, explainability, and accountability.

Much of that friction is protective, so slowness itself is not the problem. The problem is that internally institutions do not move at one speed.

A business unit can automate junior analytical work before the organization redesigns the jobs that depend on that work. A function can deploy autonomous agents before governance fully understands the resulting concentration of decision-making. A process can become dependent on AI before resilience teams have designed a credible fallback.

Technology, controls, operating models, governance and workforce capabilities can all move at different speeds.

That asynchrony is where fragility can emerge.

Organizational Fragility

Let me give you one example.

Historically, institutions trained future experts through repetitive, lower-level work. Junior analysts built the reports. Junior underwriters reviewed the files. Junior control testers walked the process maps line by line. None of us particularly mourned the manual work. But the work had another purpose: It was the training mechanism for judgment.

You learned which numbers looked wrong. Which control worked differently in practice than it did on paper. Which dependency mattered. When something small was actually telling you something big. When to escalate. And eventually, when the policy was no longer enough.

AI is increasingly capable of absorbing a meaningful share of exactly this layer of work. In the short term that looks attractive. We automate routine tasks. We reduce cost. We increase output. And here is the paradox: We may gain measurable short-term efficiencies while quietly weakening the pipelines that produce our next generation of leaders with experienced judgment. That erosion will not show up in a loss event. It will not trip a control. It will show up five to seven years from now as thinner leadership benches, weaker institutional memory, and a workforce that has lost the habit of independent problem solving because the scaffolding was automated out from under it before it had finished doing its job.

Without intention, we can transfer risk forward in time.

That is the new organizational fragility we as risk managers must be attuned to. It is silent, it is slow, and it is exactly the kind of risk existing frameworks are not built to detect, because it does not fail today. It fails in the future, on someone else's watch.

Efficiency is Not Resilience

AI can make an institution more efficient while simultaneously creating new forms of fragility. We can remove layers of coordination. Increase spans of control. Reduce manual processes. Concentrate expertise. Depend more heavily on automated systems. Each decision may be perfectly rational on its own. Collectively, they can diminish the resilience of the institution.

We should also distinguish efficiency, robustness, and resilience.

Efficiency is doing normal work with fewer resources. Robustness is continuing to perform when something goes wrong. Resilience is the capacity to adapt when what goes wrong is something we did not anticipate. That last capability depends heavily on human judgement, and it takes years to build. We should be very careful about optimizing away the mechanisms that create it.

But there is a genuinely resilient path ahead.

A Deliberate Investment

There is a useful historical analogy here. When the spreadsheets entered accounting and finance, many expected them to eliminate work. Instead, the cost of analysis collapsed, and forecasting, budgeting, and financial planning expanded, because analytical capability that used to be expensive suddenly became cheap enough to use everywhere.

AI is not a spreadsheet, and history doesn't guarantee the same outcome. But the analogy contains an important lesson: Lower unit cost can expand demand. If we treat AI as a way to expand the volume and depth of judgment we can apply-for example, forecasting more scenarios, validating more models, monitoring more continuously-we may find that the demand for skilled risk judgment does not shrink, it grows. The organizations that will be resilient are the ones that invest deliberately in building AI fluency into their workforce now and preserving the developmental pathways that create judgment, rather than assuming those pathways will take care of themselves.

That is the difference between fragility and resiliency in one sentence: Fragility is what happens when adoption outruns institutional judgment, and resiliency is what happens when we build the workforce's judgment on purpose, in parallel with adoption, instead of hoping it survives by accident.

The Need to Stress Test

So, what does that mean for operational risk?

First, I think we should begin stress-testing not just the technology, but the institution around it. Ask ourselves the question: What human capability must we deliberately preserve even when technology makes that capability look economically inefficient under normal conditions?

Second, we have a set of medium-term structural risks that deserve a permanent place on our risk radar: human capital erosion that will result in the thinning of the leadership bench; AI embedded across third parties that will create dependencies that do not map into traditional vendor-risk frameworks; and a geographic and skills mismatch that will widen, as workers do not smoothly convert into the domains experiencing shortages.

Third, there is a category I would ask you to treat as strategic stress scenarios rather than forecasts, because the timing is genuinely uncertain, but the exposure is not. I call these acceleration pathways.

The first pathway is the convergence of AI with robotics, which could gradually erode the protection that physical, unstructured work has historically enjoyed. The second is the rise of autonomous agents coordinating workflows with less human intervention, which would materially change the ratio between human supervision and output, a ratio much of our governance and control structure currently assumes stays roughly constant. The third is infrastructure concentration: the possibility that compute, energy, and semiconductor capacity concentrate economic and geopolitical influence in a small number of hands, creating new asymmetries that look very different from traditional counterparty or concentration risk.

None of these are certain. We do not need to predict exactly how these technologies develop. All of them are the kind of uncertain but highly consequential scenarios that this room exists to stress test before the risk becomes real.

The Central Challenge

As you move into today's sessions, you will hear about how AI is actually being deployed and governed, how new technologies are being absorbed under real institutional constraints, and how our operating models might change over the next several years. I would ask you to carry one question through these conversations: What happens to the institution when the technology succeeds? Not only when it fails.

The central challenge in front of us is not whether AI is powerful. It clearly is. The central challenge is whether we, as institutions and as a profession, can adapt fast enough to absorb it without quietly hollowing out the judgment and human capability we will need on the other side. That is not a technology question. It is an operational risk question, and it is ours as risk leaders to own.

Thank you, and let's get started.

Federal Reserve Bank of New York published this content on September 24, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 24, 2026 at 15:11 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]