Live Updates

EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector

AI Analysis

On 2026-07-31, the European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement calling for a cross-sectoral, risk-based and consistent supervisory approach to address ICT and cyber risks arising from frontier AI models in the EU financial sector. The statement does not introduce new binding rules but signals how supervisors expect existing frameworks, particularly under DORA and related ICT risk regulations, to be applied to frontier AI use cases.

Key dates

2026-07-31
Joint ESA statement on ICT risks from frontier AI models in the EU financial sector published

Suggested considerations

  • Compliance teams may wish to map existing and planned uses of frontier AI models (including large language models and other advanced generative or predictive systems) to current ICT risk and cyber resilience frameworks under Regulation (EU) 2022/2554 (DORA) to demonstrate that these models are covered by documented risk assessments, controls and monitoring.
  • Firms should consider reviewing governance arrangements for frontier AI, including board and senior management oversight, clear accountability, and integration of AI-related ICT risks into the firm’s risk appetite, risk taxonomy and operational risk frameworks, with specific escalation and reporting lines.
  • Risk and technology functions may wish to update ICT and cyber risk management policies to explicitly address frontier AI threats (e.g. prompt injection, model poisoning, data leakage, adversarial attacks) and to align detection, logging and incident response capabilities with the ESAs’ emphasis on prevention, detection and management of AI-related cyber risks.
  • Operational resilience teams should consider conducting scenario analysis and testing around frontier AI incidents (such as compromised AI-enabled customer interaction tools or automated decision engines) to evidence the ability to maintain critical services in line with DORA requirements on ICT-related incident management and business continuity.
  • Compliance and procurement teams may wish to review contracts and due diligence for critical ICT third‑party providers that supply or host frontier AI models, assessing how provider controls, service levels and incident processes meet DORA expectations and the ESAs’ focus on frontier AI risks.
  • Supervisory engagement teams should consider preparing to discuss the firm’s frontier AI strategy, risk management and governance with competent authorities, using the ESA statement as a reference point for how existing supervisory expectations on ICT risk and cyber resilience are applied to AI use cases.
  • Internal audit and second‑line control functions may wish to plan thematic reviews of frontier AI deployments to assess coverage of AI-specific ICT risks within existing control frameworks, including documentation quality, model oversight, and alignment with DORA and sectoral guidance.
  • Firms should consider monitoring forthcoming ESA and national competent authority publications on frontier AI and DORA oversight activities, as the statement signals that supervisory practices and expectations in this area are evolving and may be further operationalised.

What changed

The publication introduces a consolidated supervisory expectation that frontier AI models be treated explicitly as a source of ICT and cyber risk within existing EU operational resilience and ICT risk management frameworks, rather than as a separate technology domain. It emphasises the need for robust governance, risk management, and controls around the prevention, detection and management of cyber risks stemming from frontier AI, including model governance, validation, monitoring and incident handling. The statement also highlights ongoing and planned oversight activities under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), particularly regarding critical ICT third‑party providers, indicating that the ESAs will focus on frontier AI-related ris

Compliance impact

The impact is primarily supervisory and interpretative rather than creating new binding obligations, but it raises expectations that frontier AI deployments will be demonstrably integrated into existing ICT risk, cyber security and DORA compliance frameworks. Firms that cannot evidence robust governance and risk management for frontier AI may face heightened supervisory scrutiny and potential find

Who is affected

  • EU‑authorised credit institutions subject to DORA and sectoral prudential legislation
  • EU investment firms authorised under MiFID II and in scope of DORA
  • EU insurance and reinsurance undertakings supervised under Solvency II and covered by DORA
  • Institutions for occupational retirement provision (IORPs) supervised by EIOPA where DORA applies via national implementation
  • Critical ICT third‑party providers designated under Regulation (EU) 2022/2554 (DORA)
  • EU‑authorised payment institutions and electronic money institutions in scope of DORA
  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • MiFID II
  • Solvency II
  • PSD2
  • EU AI Act
  • European Commission Action Plan on Cybersecurity and Artificial Intelligence

AI-generated analysis. May contain errors or omissions — verify with the original EBA source before acting. Full disclaimer.

What the EBA said

The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.

Published by EBA . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankAsset ManagerInsurancePayment Provider
View Original on EBA Back to Feed

Share this update