⚠ A Single Platform Is a Single Point of FailureModerate threat

BlackRock (BLK) — threat to the moat

A concentration BlackRock creates for everyone else, and the reason regulators are writing rules about critical technology providers.

Aladdin's value comes from being the one system. That property, viewed from outside any individual client, is a systemic concern: a large share of the world's institutional assets are risk-managed, positioned and reported on one platform, using one set of models.

Technology services revenue, a share of total revenue (%)8.3%20237.9%20248.2%20258.0%Q2 2026BlackRock Form 10-K FY2025 and BlackRock Form 10-Q, Q2 2026
Aladdin is about 8% of revenue, and the risk it carries is out of proportion to that share.

Two distinct problems follow. The first is operational — an extended outage would leave a substantial part of the industry unable to see its own positions. The second is subtler and more interesting: if many institutions use the same risk models, they may reach similar conclusions at similar moments, and the diversity of view that makes markets work is reduced. This has been raised by regulators and academics for years, without resolution, largely because it is hard to measure.

Regulation is arriving regardless. BlackRock's own filings describe the European Union's Digital Operational Resilience Act, applicable from 2025, as introducing direct regulation of providers and users of technology and data services to financial firms, with new governance, incident reporting, resilience testing and information-sharing requirements1. That is a compliance cost today and a category of oversight that did not previously exist.

The escalation risk is designation: a determination by a regulator somewhere that a critical technology provider to the financial system should be supervised as such, with capital, operational and governance requirements attached. BlackRock has spent a decade successfully arguing that an asset manager is not systemically important because it does not own the assets. The technology business is a harder version of that argument, because the concentration is genuine and BlackRock is unambiguously the provider.

Watch the rulemaking on critical third-party providers in the EU and UK. That is where this either stays a compliance line item or becomes something structural.

References
  1. ReportedBlackRock's own filings describe the European Union's Digital Operational Resilience Act, applicable from 2025, as introducing direct regulation of providers and users of technology and data services to financial firms, with...
    BlackRock, Inc. Form 10-K, FY2025, regulation and risk factors — "BlackRock competes with investment management firms, mutual fund complexes, insurance companies, banks, brokerage firms, financial technology providers and other financial institutions"; key competitive factors "include investment performance track records, the efficient delivery of beta for index products, investment style and discipline"; in 2025 the SEC clarified guidance on when a 5% shareholder's engagement "could lead to the shareholder being considered to hold shares with the 'purpose or effect of changing or influencing control of the issuer'", noting engagement that "exerts pressure on management to implement specific measures or changes to a policy" may be considered influencing control; on proxy voting reform, "in 2025, the SEC indicated that they are considering regulatory changes related to proxy voting" and "such reforms could increase regulatory scrutiny and uncertainty for BlackRock and affect its business or operating activities"; the EU Digital Operational Resilience Act, applicable in 2025, "focuses on direct regulation of providers and users of technology and data services" and "introduced additional governance, risk management, incident reporting, resilience testing and information sharing requirements" — FY2025 · publ. February 2026 · source ↗
Sources
Generated September 23, 2026