Guidelines  ·  2026-08-04

EBA, EIOPA and ESMA (the ESAs) issue joint statement on ICT risks from frontier AI models for EU financial sector

GuidelinesHigh impactEuropean Union
On 31 July 2026, the three European Supervisory Authorities (EBA, EIOPA, ESMA — 'the ESAs') jointly published 'ESA Statement Toward a consistent and risk-based approach for ICT risks from frontier AI models' (JC 2026 25). The statement calls for a cross-sectoral, risk-based, and consistent supervisory approach to AI-accelerated cyber risk across banking, insurance, and securities, building on DORA's ICT risk-management framework and the AI Act's GPAI-systemic-risk provisions. It sets out three risk-mitigation strategies — prevention (asset inventories including AI/ML components, secure-by-design, patching), detection (scaled vulnerability discovery), and management — and updates on planned DORA oversight activity for critical ICT third-party providers (CTPPs). It explicitly builds on the ESRB's 25 June 2026 warning (ESRB/2026/3) and ENISA's frontier-AI cybersecurity view published the same month.
This is the first joint statement from all three EU financial supervisory authorities specifically addressing frontier-AI-driven ICT/cyber risk, escalating AI security from a general-purpose cybersecurity concern to an explicit cross-sectoral supervisory expectation for EU banks, insurers, and investment firms. Although styled as a 'statement' rather than binding technical standards or guidelines, it signals imminent supervisory dialogue and examination focus, and feeds directly into DORA's ICT third-party oversight regime.
EU-regulated financial entities should benchmark ICT risk-management frameworks, AI/ML asset inventories, and incident-response/recovery plans against the ESAs' prevention/detection/management framing ahead of supervisory dialogue; CTPPs should track related DORA oversight activity updates.
ESMA — ESA Statement on frontier AI models (PDF, JC 2026 25)EBA press release — EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI modelsInsight EU Monitoring — EU financial supervisors demand unified safeguards against frontier AI cyber risks
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →