← Back to updates
ESMA

ESMA

European Securities and Markets Authority

Medium Impact

ESAs endorse ESRB warning on systemic cyber risks from frontier AI models

Published

Jul 7, 2026

Topics

Cyber risk, Frontier AI, DORA, Operational resilience, ICT third-party risk, Supervisory expectations

Executive Summary

The European Supervisory Authorities have welcomed and supported the European Systemic Risk Board’s warning that frontier AI models are changing the cyber-threat environment for the EU financial sector. The statement does not create a new rule, reporting template or implementation deadline. It is, however, a clear supervisory signal that financial entities should reassess whether their cybersecurity, vulnerability management, incident response and third-party oversight capabilities remain adequate as AI-enabled tools increase the speed, scale and sophistication of attacks. The ESAs link the issue to the existing Digital Operational Resilience Act framework, which already requires financial entities to manage ICT risk, and note that the AI Act also forms part of the broader EU framework. The ESAs also state that they are engaging with national supervisors and Critical ICT Third-Party Providers, and that future supervisory expectations will be communicated consistently. Firms should treat this as an immediate risk-management and supervisory-readiness issue rather than a formal rule change.

What Changed

newESA endorsement of ESRB systemic risk warning

Previous

AI-related cyber risk was managed within existing ICT and operational resilience frameworks without this specific ESA endorsement of the ESRB systemic warning.

New

Financial entities are urged to make appropriate arrangements to adapt cybersecurity capabilities to AI-enabled cyber threats.

modifiedCybersecurity capability expectations

Previous

Financial entities were expected to maintain ICT risk management and cybersecurity arrangements under DORA and related supervisory expectations.

New

Firms should reassess whether detection, vulnerability management, patching, incident response and threat-intelligence processes remain effective against frontier AI-enabled attacks.

newSupervisory attention by competent authorities

Previous

No specific ESA statement in the supplied source directed supervisors to incorporate frontier AI cyber risks into supervisory work.

New

National supervisors are expected to consider these developments, with the ESAs aiming to promote a consistent, risk-based and forward-looking supervisory approach.

modifiedCritical ICT third-party provider oversight

Previous

DORA established an oversight framework for Critical ICT Third-Party Providers.

New

ESA oversight engagement is being applied to the specific risk context created by highly cyber-capable frontier AI models.

newNo immediate reporting template change

Previous

Financial entities were subject to existing DORA ICT risk and incident reporting arrangements.

New

Existing reporting arrangements remain in place, but firms should ensure AI-enabled attack scenarios are reflected in incident triage, escalation and control evidence.

Business Impact

Who is affected

Directly affected

EU financial entities subject to DORA, including banks, investment firms, trading venues, central counterparties, central securities depositories, insurers, reinsurers, pension institutions, payment institutions, electronic money institutions, crypto-asset service providers and other in-scope financial entities.

Indirectly affected

Critical ICT Third-Party Providers, other ICT suppliers, AI providers, software providers, security firms, open-source maintainers and national competent authorities.

Jurisdictions

European Union, European Economic Area, where DORA and related supervisory frameworks apply through local implementation or incorporation

Business processes

ICT risk management and operational resilience governance, Cyber threat intelligence and vulnerability management, Security monitoring, detection and incident response, Major ICT-related incident classification and escalation, ICT third-party risk management and provider oversight, Board and senior management cyber-risk reporting, Supervisory engagement and examination readiness

Estimated effort

Medium

Compliance risk

High

Affected Reports

DORA ICT risk management framework and control evidenceMajor ICT-related incident assessment, escalation and notification playbooksCyber threat intelligence and vulnerability management dashboardsICT third-party provider risk assessments and due-diligence questionnairesBoard or risk committee operational resilience reporting packs
FieldValidation rule

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    AI generatedStep 1 of 7

    refresh the cyber threat assessment to include frontier AI-enabled vulnerability discovery, exploit generation, phishing, malware development and attack automation scenarios.

  2. 2
    AI generatedStep 2 of 7

    test whether vulnerability management, patch prioritisation and compensating controls can respond to materially shorter exploit windows.

  3. 3
    AI generatedStep 3 of 7

    update incident response and DORA major ICT incident triage playbooks so AI-enabled attack indicators are considered during classification, escalation and evidence capture.

  4. 4
    AI generatedStep 4 of 7

    review key ICT third-party and Critical ICT Third-Party Provider oversight files, including requests for information on how providers are adapting controls to frontier AI-enabled threats.

  5. 5
    AI generatedStep 5 of 7

    brief the management body and relevant risk committees on the ESA and ESRB supervisory signal, residual risk and planned remediation actions.

  6. 6
    AI generatedStep 6 of 7

    prepare for supervisory questions by mapping existing DORA ICT risk controls to frontier AI cyber-risk scenarios and documenting gaps, ownership and remediation dates.

  7. 7
    AI generatedStep 7 of 7

    monitor ESAs and national competent authorities for the promised clarification of supervisory expectations and update internal control standards when issued.

Timeline

effective date

Jan 17, 2025

DORA applies, establishing the harmonised EU framework for financial-sector ICT risk management, incident reporting, operational resilience testing and ICT third-party risk management.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform