When the safest borrower becomes the most exposed: a lesson in reading feedback, not levels
The BIS has just measured private credit’s exposure to software firms — the sector AI is disrupting. The interesting part isn’t the number. It’s what the episode teaches about how early-warning indicators actually fail.
In one line. For fifteen years, software was the ideal borrower. AI is turning the ideal borrower into the most exposed one. The BIS documents it; lenders haven't priced it. But the durable lesson here isn't about software — it's about the difference between an indicator that measures a level and one that measures a feedback loop, and why that distinction decides whether you get 2018 wrong.
The setup, in plain terms
Suppose you lend for a living. You want the perfect borrower: predictable revenue, high margins, no factories, customers who rarely leave.
For fifteen years that borrower existed, and it was called software. Subscriptions renew themselves. High gross margins. Almost no capital expenditure. A cash flow machine.
Private credit — funds lending directly to mid-sized companies, bypassing banks — concentrated there. And because most of that market is opaque, nobody could measure how much. Which is what makes the new BIS Bulletin No 128 (Avalos, Cornelli and Eren, 14 July 2026) worth reading: it found a window.
That window is the BDC — business development company. It's a US vehicle that, by statute, must report its loans one by one, quarterly, to the SEC. There are around 170 of them, holding some $550 billion in assets, originating roughly one fifth of all US direct lending. They are the visible slice of an otherwise unobservable market. Whatever is true of them is plausibly true of the rest.
What the BIS found
One. BDCs have lent about $115 billion to software firms — roughly a fifth of all their lending and over 80% of their technology portfolios. Around three quarters of that sits in productivity, application and workflow tools: precisely where AI substitutes most directly.
Two. Lenders are not charging for the risk. Spreads on software borrowers are indistinguishable from other sectors — and they have fallen, fastest on newly issued loans and on loans from non-traded BDCs, the least scrutinised segment. The BIS puts it plainly: lenders are being paid less to carry a risk that has grown.
Three. The exposure is doubly concentrated. 60% of software lending now goes to firms borrowing from seven or more BDCs at once — under 10% in 2015. Meanwhile the five largest BDCs hold about 37% of that credit, the ten largest more than half. A shock would surface across many balance sheets simultaneously, with losses landing on few.
And the honest counterpoint, which the BIS states first: less than 1% of these loans are past due, a smaller share than the rest of their portfolios. Loans are mostly senior and secured. Leverage is capped by statute. Nothing is broken.
Note the asymmetry, though. Public equity markets have been discounting AI disruption since December 2022 — software valuations went from a premium over the broader tech sector to a discount. Credit hasn't moved at all.
Why private credit is a harder object to observe
Before the methodological part, one structural point, because it explains why a bulletin like this exists at all.
A bank is observed continuously: a supervisor sees its book, capital ratios are public, stress tests are run on it. Private credit is not one thing but a family of vehicles under different legal regimes, most of them outside registration requirements, with thin disclosure and hard-to-trace links to banks and other intermediaries.
Three consequences follow, and they compound:
Valuation is largely mark-to-model. These loans do not trade. Their reported value is the manager's own assessment — which is not fraud, but it does mean the number that reassures you was produced by the party it reassures.
There is no system-wide view. No one can aggregate exposures across the sector the way a supervisor aggregates bank exposures. The BIS works around this by reasoning from BDCs outward, and says so explicitly.
Funding structure varies enormously. Listed BDCs are equity-funded with no redemption right — genuinely stable. Non-traded vehicles offer periodic, capped redemptions, and caps are a promise about normal weather.
That is why the correct reading of Bulletin 128 is not "BDCs are dangerous". It is the opposite: BDCs are the better-lit room, and this is what the better-lit room looks like.
What the BIS was able to measure, in one table. Source: BIS Bulletin No 128 · FGA Research illustration.
The BIS measures each link separately. The question an early-warning indicator has to answer is whether they have started to push on one another. Source: BIS Bulletin No 128 · FGA Research illustration.
The part worth teaching: levels versus feedback
Here is where the episode becomes generally useful, well beyond private credit.
Most early-warning indicators measure a level. Credit spreads. Leverage ratios. Valuation multiples. Default rates. Each answers: how stretched is this one thing? And each shares the same failure mode — a single dimension can stretch a long way without a cycle turning, and it usually does.
The alternative is to measure feedback: not how stretched any one dimension is, but whether the dimensions have started to amplify each other. Whether a shock to corporate revenues tightens financial conditions, and that tightening damages the real economy, and that damage feeds back into corporate revenues. A vicious circle.
The distinction is not academic. It is the difference between two kinds of error:
False alarms (type I). A level-based indicator fires whenever its dimension stretches. It calls crises that never come. Every level indicator has a long list.
Missed turns (type II). An indicator too reluctant to fire arrives after the damage.
A feedback-based indicator makes a specific trade: it accepts being later on the level in exchange for being right about the regime. It refuses to fire on one stretched dimension. It waits for the loop.
Our own FGA Warning Signal is built on exactly that principle — it fires when three dimensions (macro, corporate/micro and financial markets) enter a vicious circle. And the record shows both sides of the trade:
It hit −2.9 in 2008 and −2.8 in 2020, its historical lows. The loop closed.
It did not fire in 1998 or in Q4 2018 — episodes where one dimension tightened sharply, markets fell hard, and the feedback never materialised.
Why the Warning did not fire in 1998 or Q4 2018. Source: FGA Research · historical results, illustrative.
A pure credit indicator would have fired in Q4 2018. That is the whole argument, in one counterexample. The methodology is documented in the working paper — The Robustness of a Four-Layer Macro-Cycle Classification System (WP-2026-01, DOI 10.5281/zenodo.20709770) — with the full record: six of six episodes ahead of the break, exact binomial p ≈ 0.016.
Applying it here
So what does Bulletin 128 actually give us? Not a reading. An anatomy — the three links of a loop that has not yet started turning:
Corporate/micro: AI compresses software revenues.
Financial: that risk isn't in the price of credit, the loss buffer has thinned, and lenders are concentrated.
Macro: if the loop closed, credit would withdraw from the US mid-market — not just from technology.
And then the first link would worsen again. That is a vicious circle.
It isn't turning today. The first link hasn't fired — real delinquency remains under 1% — and the other two aren't amplifying each other. Our cycle layer reads green and rising. The document changes what we watch. It changes no colour.
Four-layer reading as of 27 July 2026. The BIS report adds context to Layer 1; it does not move it. Source: FGA Research.
A second lesson: the metrics that reassure you are the ones looking backwards
The BIS is careful about something that deserves emphasis, because it generalises to almost any credit analysis.
Delinquency, impairment and write-down data are backward-looking by construction. A revenue shock takes time to become a missed payment. And there is an instrument — payment-in-kind, where the borrower settles interest by issuing more debt instead of paying cash — that postpones the moment strain becomes visible at all.
So a portfolio can be deteriorating and reporting well simultaneously. Today's calm numbers may simply be old numbers.
This is why the BIS chose BDCs. Not because BDCs are the problem — their statutory leverage caps and secured lending make them the better-protected part — but because they are the only part you can see. The analytical move is to reason from the observable to the unobservable, and state clearly that you are doing so. That is worth imitating.
What to watch — and why sequence beats snapshot
Three concrete markers, in order of importance:
Real delinquency, not accounting delinquency. Watch whether that "under 1%" starts to rise, and specifically whether it rises faster in software than in the rest of the portfolio. That would be the first link firing.
Whether spreads wake up. Watch for credit beginning to charge software borrowers more than everyone else. Today it doesn't discriminate. The day it does, the market will have priced the risk — late, but priced.
Non-traded funds. About a quarter of this credit sits in semi-liquid vehicles with quarterly redemption caps around 5% of assets. In early 2026, a large one breached its cap for the first time. A repeat would be funding fragility surfacing in fair weather.
And this is the methodological point to end on. A vicious circle is not a state you can read from a single document — it is a process, and processes are only visible in sequence. One report gives you the photograph. Tracking the layers week after week gives you the film. For a feedback-based indicator, the film is the only thing that matters: the question is never "how bad is this number today" but "have these three started pushing on each other yet".
That is why the layer tracking is where this piece actually gets resolved — not here, but over the coming weeks.
A practical checklist: how to read an institutional warning
If there is one transferable thing in this piece, it is this. Reports from the BIS, the IMF, the ECB or the Fed are written to be careful, which means the strength of the claim is often buried in qualifiers. Four questions extract it quickly.
1. Is this a measurement or a projection? Bulletin 128 is overwhelmingly measurement — loan-level data through Q4 2025, 18,097 borrowers, a panel of 152,116 spread observations. That deserves far more weight than a forecast. The distinction matters because the two have very different track records: we looked at exactly that in our study of how often the official reports get it right.
2. What is the institution's loss function? The BIS is a financial-stability body: it is structurally more willing to warn early and be wrong than to stay silent and be late. The IMF, forecasting growth for member states, leans the other way. Neither is a flaw — but you should not read a BIS warning with the same prior as an IMF projection.
3. Does the document claim a mechanism, or only a correlation? This one claims a mechanism, and names each link. That is what makes it usable: a mechanism tells you what to watch next. A correlation only tells you what already happened.
4. What would have to be true for this to matter? The single most useful question, and the one most reports leave to the reader. Here the answer is concrete: real delinquency rising faster in software than elsewhere, spreads starting to discriminate, redemption caps under pressure. Write it down before the next headline arrives.
Notice that none of the four asks whether the warning is "right". That is the wrong question at this stage. The right question is what state of the world the warning is describing, and how you would know if it changed.
In this series
This piece is the third chapter of a thread we have been following since June:
AI bubble? What the BIS warns — and how to read it by layers (30 June) — the BIS Annual Report and Bulletin 120: how the build-out of AI is financed, from cash flows to debt. Today's piece is the mirror image: what happens to credit lent to the firms AI may displace.
War or technology: the summer's BIS–IMF diptych (14 July, in Spanish) — the same engine the BIS treats as a risk is what sustains the cycle for the IMF. Both readings coexist; the framework orders them.
How accurate are the official reports? (16 July) — the measured track record of the WEO and the BIS as instruments: what you can ask of each and what you cannot. Useful reading right before a warning like this one.
Why we read this particular story the way we do
A closing note on standing, because this piece sits at the intersection of two things we have spent a long time on.
On AI, we are not commentators — we are practitioners, and early ones. Francisco Salvador founded one of the first research firms to apply artificial intelligence to market sentiment analysis in 2001: two decades before the current cycle, when doing this meant building the tooling yourself. That history is why we read the AI-disruption claim in Bulletin 128 as an operating question — which software categories actually get substituted, and how fast — rather than as a headline. The BIS points at productivity, application and workflow tools. Anyone who has built in that space knows why those go first.
On the cycle, we publish the record. The four-layer framework is documented in a working paper with a DOI — The Robustness of a Four-Layer Macro-Cycle Classification System (WP-2026-01) — and the results are stated in full: six of six episodes ahead of the break (exact binomial p ≈ 0.016), defensive before 2000, 2008, 2020 and 2022, with no false exit in 1998 or Q4 2018. Applied in production since 2007–2008, without re-optimising on the episodes being judged. Drawdown −29% against the market's −52%, 7.5× against 5.5× (2008–2026, illustrative). And a pre-registered public forward test on OSF: every regime change is timestamped live, before the outcome is known.
We say this for one reason only: a claim about feedback loops is worth exactly as much as the record of the person making it. Ours is open, dated and checkable — including the misses.
And you — when you read an institutional warning like this one, what tells you it's a change of regime rather than a strong headline? I read every comment.
Editorial and educational content, not investment advice. No buy or sell signals, no price targets. Past results — real or simulated — do not guarantee future results; investing involves risk, including total loss of capital.
Information, not advice. Independence. Capital. Conviction.
Independence. Capital. Conviction. · FGA Research & Advisory · Est. 2006 · 33 years of study
Sources
BIS Bulletin No 128, "AI disruption in private credit: exposure to software firms in BDCs", F. Avalos, G. Cornelli and E. Eren, 14 July 2026 — bis.org/publ/bisbull128.pdf
BIS Bulletin No 120, "Financing the AI boom: from cash flows to debt", January 2026 — bis.org/publ/bisbull120.pdf
BIS Quarterly Review, March 2026, "Private credit's software lending meets AI disruption"
F. Salvador, "The Robustness of a Four-Layer Macro-Cycle Classification System", WP-2026-01 — DOI 10.5281/zenodo.20709770





