EU supervisors urge firms to act now on frontier-AI cyber risk
A joint EBA, EIOPA and ESMA statement asks financial firms to strengthen prevention, detection and incident management under DORA, while 2027 oversight turns to critical ICT providers.

The EU's three financial supervisory authorities have urged financial firms to tighten cyber resilience now as frontier AI accelerates the speed and scale of attacks. The joint EBA, EIOPA and ESMA statement, published on 31 July, says highly capable models can find and exploit vulnerabilities faster, target shared infrastructure and take advantage of single points of failure across institutions.
The immediate message is not that a new frontier-AI rule has arrived. It is that unresolved ICT weaknesses carry more risk in a faster threat environment, and supervisors expect firms to use the controls they already have more effectively.
What changes now
The ESAs point to the Digital Operational Resilience Act and the AI Act as the existing regulatory foundation. DORA's requirements for ICT risk management, testing, incident and recovery management and third-party risk remain central. The AI Act separately sets obligations for providers of general-purpose AI models with systemic risk.
For financial entities, the statement calls for fast, proactive and proportionate action. It does not divide responsibility into a provider-vendor-deployer chain, and it does not announce a new classification or implementation timetable. Its focus is the resilience of financial entities and the supervisory response to a changing cyber threat.
Three control tracks
The statement organises the work around **prevention, detection and management**.
- **Prevention:** keep complete, current inventories of infrastructure, applications, data repositories, APIs and AI components; apply secure-design principles; protect source code; reduce unnecessary exposure; improve patching and access management; and enforce cybersecurity standards across the supply chain.
- **Detection:** move vulnerability scanning, logging and behavioural monitoring toward continuous or near-real-time operation where proportionate. The ESAs also point to more frequent tests and compliance checks, supported by security-operations and red-team capability.
- **Management:** update incident reporting, business-continuity and recovery arrangements for AI-assisted attacks and multi-system failures. Test backups, map dependencies, run resilience scenarios, improve escalation and make management accountability continuous rather than periodic.
This is not a checklist to adopt blindly. The ESAs say measures should reflect the firm's size, risk profile, interconnectedness and the nature, scale and complexity of its operations.
The management-body test
Competent authorities are asked to examine whether management bodies are committed to mitigating the risk, whether accountability and response plans are clear, and whether firms are investing enough in cyber resilience. Risk-appetite frameworks should also account for both internal use of frontier models and indirect exposure to them.
The statement says financial entities should establish governance and closely monitor the risk **without delay**. A defensible first review is therefore to ask:
1. Are known ICT findings being closed at a pace that reflects faster vulnerability exploitation?
2. Can monitoring identify unusual behaviour continuously, rather than only at the next scheduled scan?
3. Do incident, continuity and recovery tests cover simultaneous failures across connected systems?
4. Are dependencies on cloud, software, APIs and other ICT providers mapped to critical services and single points of failure?
5. Do risk appetite, escalation and board reporting reflect direct and indirect frontier-AI exposure?
Those questions translate the statement into current control work without presenting its examples as new legal duties.
The 2027 oversight signal
The ESAs have already begun targeted engagement with critical ICT third-party providers. They say the findings are informing the annual risk assessment and the priorities in the **2027 Oversight Plan**. AI-related risks are also being added to the DORA oversight examination methodology and are expected to feature in 2027 examinations and other oversight activity.
That future timetable does not postpone the work for financial entities. It signals where supervisors are building their own evidence base while firms are expected to improve governance and controls now.
What the statement does not do
The Annex is expressly illustrative: it creates no additional requirements and is not a comprehensive checklist. The statement also sets no new reporting form, effective date or standalone compliance deadline. Firms should distinguish those boundaries from its clear supervisory direction to act quickly under existing requirements.
**Official sources:** ESMA announcement and joint ESA statement JC 2026 25.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- European UnionEU AI Act Omnibus enters into force, adding nudification banTargeted AI Act amendments entered into force on 27 July 2026, adding a nudification ban and cybersecurity simplifications weeks before August high-risk obligations apply.
- ArgentinaArgentina’s CNV redirects pending trust and fund applicationsArgentina’s CNV resolutions remove two offering routes and set different transition rules for pending financial-trust and closed-end-fund applications.
- West AfricaUMOA commission fines three banks and liquidates LOCAFRIQUEThe UMOA Banking Commission published four decisions on 6 August, imposing penalties on three banks and ordering LOCAFRIQUE’s liquidation.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.