Generative Artificial Intelligence is rapidly entering the operational perimeter of central banks. From macroeconomic analysis to supervision, from managing unstructured data to preparing complex scenarios, applications are multiplying. But the enthusiasm for efficiency risks overshadowing a deeper issue: AI is not a “neutral” technology, but rather a factor of institutional discontinuity that raises unprecedented governance, control, and public responsibility challenges.
Unlike past innovations, generative AI combines computational power, widespread accessibility, and emerging capabilities that are hardly predictable. It is a general-purpose technology that evolves faster than the rules designed to regulate it. Hence what scholars call the “containment problem”: the growing difficulty of institutions in controlling tools capable of producing systemic effects on an economic and financial scale.
For central banks – guardians of monetary and financial stability – the stakes are particularly high. Algorithmic opacity can compromise the comprehensibility of analyses; widespread adoption of similar models in financial markets can amplify imitative behaviors; dependence on external providers can weaken sovereignty over data and critical infrastructures. In this context, algorithmic errors or biases do not remain confined but risk spreading rapidly.
The key point, however, is not technological but organizational. Data show that the vast majority of generative AI projects do not produce measurable impacts at the structural level. The reason is well known: organizations struggle to transform isolated experiments into integrated operational tools. AI often increases individual productivity, but this does not automatically translate into overall improvement if processes, responsibilities, and controls remain unchanged.
In central banks – where work is highly composite and combines technical analysis, expert judgment, and institutional responsibility – AI does not replace professions but reconfigures tasks. It automates some repetitive activities, supports analysis, frees up time for higher value-added decisions. But precisely for this reason, it requires new hybrid skills capable of integrating technology, risk, policy, and public mandate.
To govern this transformation, an increasingly central reference is the three lines of defense model. The first line – operational – is called upon to design and manage models with criteria of robustness, transparency, and security from the development phase. The second line – risk management, compliance, and data governance – defines standards, controls, and independent assessments. The third line – internal audit – assumes a strategic role in verifying the entire framework: from data quality to the explainability of algorithmic decisions, up to the adequacy of human supervision.
In particular, audit becomes the fundamental safeguard against the risk of “unconscious delegation” to machines. It must ensure that clear responsibilities exist over the model lifecycle, human intervention mechanisms, escalation protocols, and the ability to explain and justify AI-influenced decisions. In the absence of these safeguards, technology can undermine – rather than strengthen – institutional credibility.
The lesson that emerges is clear: AI must be treated as a strategic infrastructure, not as an isolated project. Value will depend less on the sophistication of models than on the organizational maturity of the institutions adopting them. Without multilevel governance, solid data sovereignty, and a culture of algorithmic responsibility, the risk is to remain trapped in “permanent experimentation” without real benefits.
For central banks, called to operate with medium-to-long-term horizons and under a strong public interest mandate, AI governance thus becomes a new frontier of stability. And the three lines of defense model, adapted to emerging technologies, is poised to be one of the most concrete tools to balance innovation and control, efficiency and responsibility.




