Substrate Advisory
Reports

Infrastructure Outside the Perimeter

A four-part series on the technology regulated firms depend on but do not control: AI, cloud, public blockchain infrastructure and post-quantum cryptography. Excerpts below; full text is available as PDF.

```

The Model You Cannot AuditPart 1 of 4 · AI Dependency and the Regulated Firm · July 2026

A third of AI use cases in UK financial services now run on third-party providers, concentrated among a handful of closed frontier models no supervisor can inspect. The June 2026 suspension of two frontier models, reversed nineteen days later through direct vendor-government negotiation, turned model availability into a documented operational risk. Sets out what a board should already have in place: a tested fallback, an owned evaluation suite and an availability floor for workloads that cannot stop.

Download PDF →

The Provider You Cannot ExitPart 2 of 4 · Cloud Concentration and the Regulated Firm · July 2026

Three US hyperscalers hold 63 per cent of a cloud infrastructure market growing at 35 per cent a year, with no European alternative at scale. The EU and UK have now brought the providers themselves under direct supervisory oversight, and the October 2025 US-EAST-1 outage showed what the dependency looks like when it fails. Covers register-of-information granularity, tested exit plans and how to assess sovereign cloud offerings on the dimension that actually matters.

Download PDF →

The Settlement Layer Nobody LicensesPart 3 of 4 · Public Blockchain Infrastructure and the Regulated Firm · July 2026

When a regulated firm settles a tokenised asset on a public chain, the validators, RPC providers, oracles and bridges beneath the transaction sit entirely outside the supervisory perimeter, and the loss record at that layer already runs into billions. The DLT Pilot Regime and the Digital Securities Sandbox reward firms that treat this as an architected risk rather than an inherited one, and both currently have finite admission windows.

Download PDF →

The Clock You Do Not SetPart 4 of 4 · Post-Quantum Cryptography and the Regulated Firm · July 2026

The replacement standards for RSA and elliptic-curve cryptography are public and free to implement, but the transition dates are American, and Executive Order 14412 has now made them binding on the US federal estate. Confidential data captured today is exposed the day a capable quantum computer exists, regardless of when the firm migrates. Sets out the inventory-first approach and why the HSM refresh cycle already under way is the decision point.

Download PDF →
```