Source
European Banking Authority
July 31, 2026
The European Supervisory Authorities (EBA, EIOPA, and ESMA) have published a statement calling for a cross-sectoral, risk-based, and consistent supervisory approach to mitigate ICT risks arising from frontier AI models.
The statement considers existing regulatory requirements, the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, and recent publications by the European Systemic Risk Board (ESRB), ENISA, the Single Supervisory Mechanism (SSM), and other authorities.
Measures outlined aim to help financial entities strengthen operational resilience against cyber risks linked to frontier AI models, with a focus on prevention, detection, and management of these risks.
The authorities emphasize that financial entities should have robust governance and risk management frameworks to effectively manage and mitigate cyber risks associated with frontier AI models. The statement also updates on ongoing and planned DORA oversight activities for critical ICT third-party providers (CTPPs).
Both financial entities and competent authorities are encouraged to use this statement as a basis for supervisory dialogue, aligning with existing supervisory expectations. This approach aims to ensure the resilience of the EU financial system against risks driven by frontier AI technologies.