The European Supervisory Authorities (EBA, EIOPA and ESMA) have called for a cross-sectoral, risk-based and consistent supervisory approach to mitigate ICT risks stemming from frontier AI models in the EU financial sector. In a joint statement published on 31 July 2026, the three authorities outline measures to help financial entities strengthen their operational resilience against cyber risks linked to these advanced AI systems, with particular emphasis on prevention, detection and management. The statement urges financial entities to maintain robust governance and risk management frameworks to support effective mitigation of such risks, and encourages both entities and competent authorities to use the statement as a basis for supervisory dialogue.

The statement takes into account existing regulatory requirements, including the Digital Operational Resilience Act (DORA), as well as the European Commission's Action Plan on Cybersecurity and Artificial Intelligence. It also references recent publications by the European Systemic Risk Board (ESRB), the European Union Agency for Cybersecurity (ENISA), the Single Supervisory Mechanism (SSM) and other competent authorities, reflecting a broader institutional push to address AI-related vulnerabilities in the financial sector. The ESAs update on ongoing and planned DORA oversight activities for critical ICT third-party providers (CTPPs) to address this risk, signalling that supervision of these providers will be a key channel for managing frontier AI risks.

The joint statement marks a coordinated effort by the three sectoral regulators to align supervisory expectations across banking, insurance and securities markets. By advocating a consistent approach, the ESAs aim to prevent regulatory arbitrage and ensure a level playing field for financial entities of all sizes. The emphasis on governance and risk management implies that firms will need to integrate frontier AI risk assessments into their existing operational resilience frameworks, potentially requiring updates to internal policies, staff training and incident response procedures.

For financial institutions, the statement signals that supervisors will increasingly scrutinise how they deploy frontier AI models, particularly in areas such as fraud detection, credit scoring and algorithmic trading. This could lead to additional compliance costs, especially for smaller entities that may lack specialised AI expertise. However, the risk-based approach allows supervisors to tailor expectations to the scale and complexity of each firm's AI usage, avoiding a one-size-fits-all burden. For critical ICT third-party providers, the statement reinforces their role as a focal point of DORA oversight, meaning they may face more frequent and detailed assessments of their AI-related security measures.

The statement is non-binding, but it sets the stage for more concrete supervisory guidance. The ESAs are expected to follow up with more detailed technical standards or guidelines, building on the ongoing work under DORA and the Commission's AI action plan. The call for supervisory dialogue suggests that the authorities will engage with individual firms and national supervisors to refine expectations, potentially leading to more harmonised practices across the EU. The impact on consumers is indirect but positive: stronger operational resilience in the financial sector reduces the likelihood of service disruptions or data breaches that could affect retail customers. Overall, the statement reflects a proactive regulatory stance, balancing the benefits of frontier AI innovation with the need to safeguard financial stability and data protection.

← Atlas › News › Digital & Communication