The Federal Reserve’s 2026 stress-test results delivered a reassuring message: America’s largest banks remain remarkably resilient. Under the Fed's "severely adverse" scenario, thirty-two major institutions collectively absorbed more than $700 billion in projected losses while maintaining capital levels above regulatory minimums. For regulators and bank executives advocating for lower capital requirements, the results appear to validate a simple conclusion: banks have more capital than they need. That conclusion is very premature.
The stress tests demonstrate that banks can withstand the crisis bank regulators chose to model. They do not demonstrate that banks are adequately prepared for the crises that may emerge over the next decade. As the Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation consider proposals introduced in March 2026 that would reduce capital requirements, policymakers should recognize an uncomfortable reality: the stress tests largely assess the risks of the last crisis, not necessarily the risks of the next one. The distinction matters.
What the Federal Reserve’s Stress Tests Actually Measure
Since the Global Financial Crisis of 2008, annual stress tests have become one of the most important tools for assessing the health of the banking system. The tests evaluate whether banks could survive a severe recession characterized by rising unemployment, falling asset prices, widening credit spreads, declining commercial real estate values, and significant loan losses.
These scenarios are intentionally severe. The 2026 exercise assumed a deep economic downturn, substantial declines in financial markets, and sharp deterioration across multiple credit sectors. Banks passed because they entered the test with substantial capital cushions and because the post-crisis regulatory framework has required them to build those cushions over many years.
But the annual Dodd-Frank Act Stress Test (DFAST) fundamentally asks a single question:
Can banks survive a very bad recession?
That is an important question. It is not the only question.
The stress tests do not primarily ask whether banks can survive a coordinated cyberattack. They do not ask whether artificial intelligence could accelerate fraud or trigger systemic operational failures. They do not ask whether a geopolitical conflict could freeze global supply chains or disrupt critical financial infrastructure. They do not ask whether a crisis in private credit could spill into the banking sector in unexpected ways. In short, they do not comprehensively assess many of the risks that increasingly dominate discussions among financial stability experts.
The Danger of Confusing Success with Excess
Supporters of lower capital requirements argue that the stress-test results demonstrate that banks are overcapitalized. If institutions can absorb hundreds of billions of dollars in losses and remain comfortably above minimum requirements, why not release some of that capital back into the economy?
The argument has intuitive appeal. Less required capital could support additional lending, investment, and economic growth.
But there is another interpretation.
Banks are passing the stress tests precisely because they have been required to maintain robust capital buffers. The success of the framework is not necessarily evidence that the framework is excessive. It is evidence that it works.
Imagine a city that has not experienced catastrophic flooding in decades because it invested heavily in levees and flood-control systems. The absence of flooding would not automatically justify dismantling those protections. Yet, that is effectively the logic that bank lobbyists apply to capital today.
The fact that banks survived the modeled scenario does not mean they possess excess capital relative to all potential future risks. It merely means they possess sufficient capital relative to the scenarios bank regulators selected.
The Risks the Stress Tests Do Not Capture
The most significant challenge facing the stress-testing regime is that many of today's emerging threats are difficult to model using traditional macroeconomic assumptions.
Consider cybersecurity.
Modern banks rely on interconnected networks, cloud-service providers, payment systems, and digital infrastructure that have become increasingly attractive targets for sophisticated adversaries. A successful attack on a major bank—or several financial institutions simultaneously—could disrupt payment systems, impair customer access to funds, and undermine confidence in the U.S. financial system.
Yet, these risks remain largely outside the core stress-testing framework.
The annual stress tests do not typically model a ransomware attack that disables critical banking operations. They do not simulate widespread cloud-provider outages. They do not assess the consequences of prolonged disruptions to payment infrastructure or coordinated attacks against multiple institutions.
Artificial intelligence introduces an additional layer of uncertainty.
Much of the current discussion surrounding AI focuses on productivity gains and operational efficiencies. Less attention has been paid to the ways AI could amplify financial-system vulnerabilities.
AI-enabled cyberattacks could become more sophisticated, scalable, and difficult to detect. Deepfake technologies could facilitate fraud against customers and financial institutions. Automated systems could accelerate misinformation campaigns that trigger digital bank runs. AI-driven trading systems could contribute to market instability during periods of stress. The same technology that improves efficiency may also increase the speed at which crises develop.
None of these scenarios are meaningfully incorporated into current stress-testing methodologies.
A bank may pass a severe recession test while remaining vulnerable to risks that do not resemble recessions at all.
Private Credit: The Growing Blind Spot
Another area of concern is private credit.
When the stress-testing framework was designed following the 2008 crisis, private credit occupied a relatively small corner of the financial landscape. Today, the industry has grown into a multi-trillion-dollar market and has become a critical source of financing for many borrowers.
The stress tests account for corporate loan losses, leveraged lending exposures, and broader credit-market deterioration. What they do not explicitly model is a standalone private-credit crisis.
What happens if major private-credit funds face severe liquidity pressures?
What happens if fund investors demand redemptions during a period of market stress?
What happens if banks are forced to absorb commitments, warehouse assets, or provide unexpected liquidity support to counterparties connected to the private-credit ecosystem?
These questions remain largely outside the formal framework.
As financial intermediation increasingly migrates beyond traditional banks and into nonbank institutions, the distinction becomes increasingly important. The next financial crisis may emerge not from bank balance sheets themselves but from the growing network of connections between banks and nonbanks.
Geopolitical Risks Are Different
The same limitations apply to geopolitical risk.
The Fed's scenarios incorporate the economic consequences of global stress—falling markets, widening spreads, weaker growth—but they do not model the specific events that could trigger those outcomes.
A conflict involving Taiwan, a major cyberwar between nation-states, disruptions to critical shipping routes, or sanctions-related financial fragmentation could generate second-order effects that are difficult to capture through traditional recession assumptions.
Financial crises rarely repeat themselves exactly. They evolve alongside technology, markets, and geopolitics.
The danger lies in assuming that future crises will resemble past ones closely enough for existing models to provide adequate protection.
Capital Is Insurance Against the Unknown
The debate over capital requirements ultimately comes down to one fundamental question: What is capital for?
If capital exists solely to absorb losses during a recession, then the argument for lower requirements becomes stronger. But capital exists to protect the banking system against uncertainty—including risks that regulators and market participants cannot fully anticipate. This is why maintaining substantial buffers remains compelling.
History offers a clear lesson. Few bank regulators anticipated the precise mechanisms of the 2008 financial crisis. Few predicted the sudden regional-bank failures of 2023. The most damaging financial disruptions often emerge from vulnerabilities that were underestimated, misunderstood, or entirely overlooked.
The next crisis may involve artificial intelligence, climate change, cyber warfare, private-credit contagion, geopolitical fragmentation, or a combination of factors that do not fit neatly into existing stress-testing models.
That possibility argues for significant caution.
A Passing Grade Is Not a Guarantee
The 2026 stress-test results should be welcomed. They confirm that America's largest banks are significantly stronger than they were before the Global Financial Crisis. They demonstrate that the banking system can withstand a severe recession and continue functioning.
But passing a test designed around yesterday's risks is not proof that bank are fully prepared for tomorrow's.
As bank regulators consider reducing capital requirements, they should remember what the stress tests actually show and what they do not. The results provide evidence of resilience under a specific set of assumptions. They do not provide evidence that the financial system has become less uncertain, less interconnected, or less vulnerable to emerging threats.
In an era defined by artificial intelligence, cyber risk, geopolitical instability, and the explosive growth of nonbank finance, the strongest argument for robust bank capital may be the simplest one:
The greatest dangers are often the ones that have not yet been modeled.
