ESMA
European Securities and Markets Authority
ESAs urge risk-based mitigation of ICT risks from frontier AI models
Published
Jul 31, 2026
Topics
Digital operational resilience, Cybersecurity, Artificial intelligence, DORA, ICT risk management, Third-party risk management, Operational resilience
Executive Summary
The European Supervisory Authorities issued a statement on 31 July 2026 encouraging EU financial entities to respond proactively to ICT and cyber risks amplified by frontier AI models. The statement does not create new regulatory requirements and its annex is explicitly illustrative, but it signals a coordinated supervisory focus under existing frameworks, particularly DORA’s ICT risk management, testing, incident and recovery, and ICT third-party risk management requirements, as well as the AI Act framework for general-purpose AI models with systemic risk. The ESAs highlight that AI-enabled threat actors may accelerate vulnerability discovery, exploit shared infrastructure and amplify single points of failure. Firms are encouraged to adjust ICT controls across prevention, detection and management, including asset inventories, secure-by-design practices, continuous monitoring, patching, resilience testing, backup and recovery capabilities, supply-chain controls, and management body accountability. Critical ICT third-party providers should also expect AI-related risks to be reflected in ESA oversight engagement and examination activity during 2027.
What Changed
Previous
Existing EU operational resilience rules applied technology-neutrally, without this ESA statement specifically framing frontier AI-enabled cyber threats as an urgent supervisory focus.
New
Financial entities are encouraged to act quickly and proportionately to enhance cybersecurity capabilities for AI-assisted threats, taking account of supervisory expectations and DORA proportionality.
Previous
DORA already required financial entities to maintain ICT risk management and operational resilience controls; the statement does not amend those legal requirements.
New
The ESAs expect firms to assess whether existing DORA-aligned controls remain adequate given shorter AI-enabled vulnerability discovery and exploitation cycles.
Previous
No new ESA checklist or template existed in this statement’s form for frontier AI-related ICT risk mitigation.
New
Entities may consider measures such as updated asset inventories, secure-by-design controls, access management, supply-chain monitoring, continuous vulnerability scanning, behavioural monitoring, resilience testing, and improved backup and recovery.
Previous
Management body accountability and risk appetite expectations already existed through operational resilience and governance frameworks.
New
Firms should review risk appetite metrics, tolerance thresholds and controls for risks arising from internal use of frontier AI models and indirect exposure to AI-enabled threats.
Previous
The statement does not identify a prior AI-specific CTPP oversight cycle in the same terms.
New
AI-related threats are expected to inform the 2027 Oversight Plan, oversight examinations and other oversight activities assessing CTPP preparedness and resilience.
Business Impact
Who is affected
Directly affected
EU financial entities subject to DORA, including banks, insurers, investment firms, trading venues, central securities depositories, central counterparties, payment and e-money institutions, crypto-asset service providers where in scope, and other regulated financial entities.
Indirectly affected
ICT third-party service providers, cloud providers, SOC providers, software and hardware suppliers, open-source dependency owners, AI tool providers, internal audit, external assurance providers and critical ICT third-party providers subject to ESA oversight.
Jurisdictions
European Union
Business processes
ICT risk management framework maintenance, Cyber threat and vulnerability management, Patch and configuration management, Security operations centre monitoring and escalation, Incident response and regulatory incident reporting preparation, Business continuity and disaster recovery planning, Operational resilience and threat-led testing, ICT third-party and supply-chain risk management, Management body risk reporting and risk appetite review
Estimated effort
Medium
Compliance risk
High
Affected Reports
| Field | Validation rule |
|---|
Recommended Actions
- 1Confirmed actionStep 1 of 7
because the ESA annex is illustrative and does not create additional requirements, map its prevention, detection and management examples to existing DORA controls rather than treating it as a new standalone rulebook.
- 2AI generatedStep 2 of 7
Refresh the ICT risk assessment to capture AI-assisted vulnerability discovery, exploitation of shared infrastructure, dependency concentration, single points of failure and indirect exposure through ICT third parties.
- 3AI generatedStep 3 of 7
Update board and senior management reporting so risk appetite metrics, tolerance thresholds, escalation triggers and investment decisions explicitly cover frontier AI-related cyber risk.
- 4AI generatedStep 4 of 7
Prioritise remediation of open ICT and security findings, especially issues already identified through supervisory activity, penetration testing, red teaming, audits or the 2024 cyber-resilience stress-test context referenced by the ESAs.
- 5AI generatedStep 5 of 7
Move high-risk systems toward more continuous detection and response by enhancing asset inventories, vulnerability scanning, behavioural monitoring, logging, patch automation and SOC escalation procedures.
- 6AI generatedStep 6 of 7
Revise incident response, business continuity, backup and disaster recovery scenarios to include AI-assisted multi-system attacks and simultaneous third-party or infrastructure failures.
- 7AI generatedStep 7 of 7
Engage critical and material ICT third-party providers on their AI-enabled cyber-risk controls, supply-chain monitoring, backup segregation, incident communication and resilience-testing evidence.
Timeline
other
Jun 25, 2026
The European Systemic Risk Board issued a warning on systemic cyber risks stemming from frontier artificial intelligence models, referenced by the ESA statement.
other
Jul 7, 2026
The European Commission published its Action Plan on Cybersecurity and Artificial Intelligence, referenced by the ESAs as context for the statement.
publication
Jul 31, 2026
The ESAs published statement JC 2026 25 on a consistent and risk-based approach for ICT risks from frontier AI models.
implementation
2027
The ESAs state that insights from targeted engagement with relevant critical ICT third-party providers have informed the annual risk assessment cycle and prioritisation of activities under the 2027 Oversight Plan; AI-related threats are expected to be reflected in oversight examinations and other oversight activities in 2027.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- StatementEuropean Supervisory Authorities / ESMAJul 31, 2026ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models ↗
https://www.esma.europa.eu/sites/default/files/2026-07/JC_2026_25_ESA_statement_on_frontier_AI_models.pdf
- RegulationOfficial Journal of the European Union / EUR-LexDec 14, 2022Regulation (EU) 2022/2554 on digital operational resilience for the financial sector ↗
https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- RegulationOfficial Journal of the European Union / EUR-LexJun 13, 2024Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence ↗
https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Regulatory Technical StandardOfficial Journal of the European Union / EUR-LexMar 13, 2024Commission Delegated Regulation (EU) 2024/1774 supplementing DORA with regulatory technical standards on ICT risk management tools, methods, processes and policies ↗
https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.