The European Supervisory Authorities (ESAs) — comprising the European Securities and Markets Authority (ESMA), the European Banking Authority (EBA), and the European Insurance and Occupational Pensions Authority (EIOPA) — have issued a joint statement on 31 July 2026 urging a consistent and risk-based approach to information and communication technology (ICT) risks arising from frontier AI models. The statement, published under reference JC 2026 25, is addressed to financial institutions and supervisors across the EU, and seeks to align the application of existing ICT risk management frameworks with the rapid adoption of advanced AI systems in the financial sector.
The document, produced by the ESAs' Joint Committee, does not introduce new binding rules but rather provides supervisory guidance on how to treat frontier AI models under the current Digital Operational Resilience Act (DORA) framework. It emphasizes that ICT risks from frontier AI — such as model opacity, data dependency, and potential systemic concentration — should be managed proportionately, with a focus on the materiality of the risk rather than the novelty of the technology. The statement calls on financial entities to integrate frontier AI into their existing risk management processes, including business continuity, incident reporting, and third-party risk management, and urges supervisors to adopt a convergent approach to avoid fragmentation across member states.
This is the first joint ESA statement specifically addressing frontier AI in the financial sector, and it follows a series of EU-level initiatives on AI governance. In April 2026, the European Commission published its AI innovation package, which included a proposal to clarify liability rules for AI systems, and in May 2026, the European Parliament's Committee on Economic and Monetary Affairs (ECON) held a hearing on the financial stability implications of AI, where several MEPs pressed the Commission on the need for sector-specific guidance. The ESAs' statement builds on these efforts by providing a concrete supervisory perspective, though it stops short of proposing new legislation.
The statement reflects a careful balancing act between fostering innovation and ensuring financial stability. On one hand, it acknowledges the potential benefits of frontier AI, such as improved risk detection and operational efficiency, and cautions against overly prescriptive rules that could stifle adoption. On the other hand, it highlights the unique risks posed by these models, including the possibility of correlated failures if many institutions rely on the same AI providers, and the challenge of explaining AI-driven decisions to regulators and customers.
For financial institutions, the main impact is the expectation that they will need to demonstrate, in their supervisory reporting, how they assess and mitigate ICT risks from frontier AI. This could increase compliance costs, particularly for smaller firms that may lack the technical expertise to evaluate complex models. For AI technology providers, the statement signals that they may face more rigorous due diligence from financial clients, who will be required to understand the models they deploy. For national supervisors, the call for consistency may lead to more harmonized supervisory practices, but also to additional training and resource needs. For consumers and investors, the approach aims to reduce the risk of AI-driven operational failures that could disrupt financial services, though the absence of binding rules means the actual level of protection will depend on how supervisors implement the guidance.
The ESAs have indicated that they will monitor the application of the statement and may issue further guidance as frontier AI technologies evolve. The statement is part of a broader trend of EU regulators seeking to apply existing rules to new technologies rather than creating separate regimes, a stance that has been welcomed by industry groups but criticized by some consumer advocates who argue that more explicit safeguards are needed.