ESMA
European Securities and Markets Authority
ESAs endorse ESRB warning on systemic cyber risks from frontier AI models
Published
Jul 7, 2026
Topics
Cyber risk, Frontier AI, DORA, Operational resilience, ICT third-party risk, Supervisory expectations
Executive Summary
The European Supervisory Authorities have welcomed and supported the European Systemic Risk Board’s warning that frontier AI models are changing the cyber-threat environment for the EU financial sector. The statement does not create a new rule, reporting template or implementation deadline. It is, however, a clear supervisory signal that financial entities should reassess whether their cybersecurity, vulnerability management, incident response and third-party oversight capabilities remain adequate as AI-enabled tools increase the speed, scale and sophistication of attacks. The ESAs link the issue to the existing Digital Operational Resilience Act framework, which already requires financial entities to manage ICT risk, and note that the AI Act also forms part of the broader EU framework. The ESAs also state that they are engaging with national supervisors and Critical ICT Third-Party Providers, and that future supervisory expectations will be communicated consistently. Firms should treat this as an immediate risk-management and supervisory-readiness issue rather than a formal rule change.
What Changed
Previous
AI-related cyber risk was managed within existing ICT and operational resilience frameworks without this specific ESA endorsement of the ESRB systemic warning.
New
Financial entities are urged to make appropriate arrangements to adapt cybersecurity capabilities to AI-enabled cyber threats.
Previous
Financial entities were expected to maintain ICT risk management and cybersecurity arrangements under DORA and related supervisory expectations.
New
Firms should reassess whether detection, vulnerability management, patching, incident response and threat-intelligence processes remain effective against frontier AI-enabled attacks.
Previous
No specific ESA statement in the supplied source directed supervisors to incorporate frontier AI cyber risks into supervisory work.
New
National supervisors are expected to consider these developments, with the ESAs aiming to promote a consistent, risk-based and forward-looking supervisory approach.
Previous
DORA established an oversight framework for Critical ICT Third-Party Providers.
New
ESA oversight engagement is being applied to the specific risk context created by highly cyber-capable frontier AI models.
Previous
Financial entities were subject to existing DORA ICT risk and incident reporting arrangements.
New
Existing reporting arrangements remain in place, but firms should ensure AI-enabled attack scenarios are reflected in incident triage, escalation and control evidence.
Business Impact
Who is affected
Directly affected
EU financial entities subject to DORA, including banks, investment firms, trading venues, central counterparties, central securities depositories, insurers, reinsurers, pension institutions, payment institutions, electronic money institutions, crypto-asset service providers and other in-scope financial entities.
Indirectly affected
Critical ICT Third-Party Providers, other ICT suppliers, AI providers, software providers, security firms, open-source maintainers and national competent authorities.
Jurisdictions
European Union, European Economic Area, where DORA and related supervisory frameworks apply through local implementation or incorporation
Business processes
ICT risk management and operational resilience governance, Cyber threat intelligence and vulnerability management, Security monitoring, detection and incident response, Major ICT-related incident classification and escalation, ICT third-party risk management and provider oversight, Board and senior management cyber-risk reporting, Supervisory engagement and examination readiness
Estimated effort
Medium
Compliance risk
High
Affected Reports
| Field | Validation rule |
|---|
Recommended Actions
- 1AI generatedStep 1 of 7
refresh the cyber threat assessment to include frontier AI-enabled vulnerability discovery, exploit generation, phishing, malware development and attack automation scenarios.
- 2AI generatedStep 2 of 7
test whether vulnerability management, patch prioritisation and compensating controls can respond to materially shorter exploit windows.
- 3AI generatedStep 3 of 7
update incident response and DORA major ICT incident triage playbooks so AI-enabled attack indicators are considered during classification, escalation and evidence capture.
- 4AI generatedStep 4 of 7
review key ICT third-party and Critical ICT Third-Party Provider oversight files, including requests for information on how providers are adapting controls to frontier AI-enabled threats.
- 5AI generatedStep 5 of 7
brief the management body and relevant risk committees on the ESA and ESRB supervisory signal, residual risk and planned remediation actions.
- 6AI generatedStep 6 of 7
prepare for supervisory questions by mapping existing DORA ICT risk controls to frontier AI cyber-risk scenarios and documenting gaps, ownership and remediation dates.
- 7AI generatedStep 7 of 7
monitor ESAs and national competent authorities for the promised clarification of supervisory expectations and update internal control standards when issued.
Timeline
effective date
Jan 17, 2025
DORA applies, establishing the harmonised EU framework for financial-sector ICT risk management, incident reporting, operational resilience testing and ICT third-party risk management.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- Official news statementEuropean Securities and Markets AuthorityDate not specifiedThe ESAs support ESRB warning on systemic cyber risks from frontier AI models ↗
https://www.esma.europa.eu/press-news/esma-news/esas-support-esrb-warning-systemic-cyber-risks-frontier-ai-models
- Primary legal textOfficial Journal of the European Union / EUR-LexDec 14, 2022Regulation (EU) 2022/2554 on digital operational resilience for the financial sector ↗
https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Primary legal textOfficial Journal of the European Union / EUR-LexJun 13, 2024Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence ↗
https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.