Microsoft, Google Cloud, AWS and Oracle are now supervised entities in the UK financial system. Here's what Critical Third Party designation actually costs, and why enterprise leaders should expect contract and multi-cloud fallout.
As of today, July 13, 2026, four of the world's largest technology companies are supervised entities inside the British financial system. Not banks. Not insurers. Cloud providers.
The UK government has formally designated Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL and Oracle Corporation UK Ltd as Critical Third Parties to the financial sector — the first companies ever named under a regime created by the Financial Services and Markets Act 2023. From today, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority will jointly supervise the resilience of the cloud services these firms provide to UK banks, insurers and market infrastructure. The designated companies must undergo resilience testing, conduct regular self-assessments and report major incidents to regulators.
The announcement, made July 10 and reported by Reuters, was framed by the government in plain terms: because banks and insurers increasingly rely on the same cloud suppliers, disruption at one provider could hit many firms simultaneously, affecting services customers depend on. Economic Secretary to the Treasury Rachel Blake put the stakes simply, saying that "maintaining trust in our financial system is essential to its success."
For enterprise technology leaders, the significant word in all of this is one regulators have been circling for months: systemic.
For two decades, cloud concentration was treated as a procurement issue. Each bank ran its own vendor risk assessment, negotiated its own service-level agreements, and made an individually rational choice — usually one of three or four hyperscalers, because that is where the capability is.
The regulatory shift now underway reframes those individually rational choices as a collectively dangerous pattern. An outage confined to one bank is an institutional failure, manageable through that bank's own continuity planning. An incident inside a shared platform — compute, identity, databases, monitoring, backup — could hit multiple banks, payment companies, insurers and trading venues at once. No single customer can measure that sector-wide risk, which is precisely the argument for regulators measuring it instead.
The UK is not alone, and the pattern across jurisdictions is what makes this a structural change rather than a local one. The European Union moved first: in November 2025, European regulators designated 19 technology and services firms as critical ICT third-party providers under the Digital Operational Resilience Act (DORA), a list that included the European arms of Google Cloud, AWS and Microsoft. The UK regime, effective today, complements DORA with a narrower initial list and joint supervision by three regulators. The Treasury has said further providers may be designated over time on a risk-based approach.
Reporting in sector newsletters, including AI Weekly's digest of the week's regulatory moves, adds two further data points to the pattern: the European Central Bank has reportedly set an October 31 deadline for significant European banks to demonstrate resilience against AI-powered attack scenarios, and U.S. Treasury analysts have reportedly concluded that the AI investment boom is now too entrenched to unwind without ripple effects across equities, private credit, data-center debt and utilities. Both items warrant independent confirmation — see the editorial flags — but they are directionally consistent with the confirmed UK and EU actions: financial supervisors, on both sides of the Atlantic, are treating concentrated technology infrastructure as a stability question.
For the four named providers, supervision is not symbolic. The regime gives UK regulators the power to gather information, assess resilience and set rules where the providers' services touch critical financial functions. That translates into concrete operating costs: dedicated regulatory-engagement teams, participation in sector-wide resilience testing, incident-reporting pipelines built to a supervisor's specification rather than a customer's, and the reputational exposure of being publicly examinable in a way suppliers never were.
A Google Cloud spokesperson responded to the designation constructively, telling Reuters that effective implementation could enhance long-term resilience and increase transparency between all parties — the response of a company that has concluded the regime is now a fact of the operating environment.
But the more consequential costs may land on the customers. Enterprise leaders running UK financial workloads should expect at least three second-order effects:
Scope-mapping obligations. Firms will need to know — with regulator-grade precision — which of their critical services run on designated providers, and which specific provider services fall within the supervised perimeter. For most banks, that inventory does not currently exist at the required fidelity.
Concentration accounting. Once regulators can see sector-wide dependency maps, they can act on them. Multi-cloud strategies that were previously cost-benefit decisions may become supervisory expectations for the most critical functions, with real architectural and financial consequences.
Contract renegotiation. Supervised providers will need to pass certain obligations — testing participation, incident-notification timelines, exit-planning cooperation — through to customer contracts. Procurement teams should expect the next renewal cycle to look different.
The critique of this regulatory turn writes itself: layering bank-style supervision onto technology suppliers risks slowing the very innovation financial firms are trying to adopt, and could entrench incumbents by raising compliance barriers that only the largest providers can absorb. That last point carries genuine irony — a regime designed to address concentration may advantage the four firms already concentrated at the top, because a fifth challenger now faces not just their scale but their regulatory apparatus.
The counterargument is that the systemic framing is simply accurate. When the plumbing of a G7 financial system runs through four companies, the choice is not between regulation and a free market; it is between regulation before a sector-wide outage and regulation after one. The UK has chosen before. The next several quarters — the first resilience tests, the first supervised incident, the first designation of a fifth provider — will show what the word "systemic" costs in practice, and who ends up paying it.

An invitation, extended to Powered readers.
Private test drives available for Powered readers through Bentley Motors.