What happened
On 31 July 2026, the three European Supervisory Authorities (EBA, EIOPA, ESMA — 'the ESAs') jointly published 'ESA Statement Toward a consistent and risk-based approach for ICT risks from frontier AI models' (JC 2026 25). The statement calls for a cross-sectoral, risk-based, and consistent supervisory approach to AI-accelerated cyber risk across banking, insurance, and securities, building on DORA's ICT risk-management framework and the AI Act's GPAI-systemic-risk provisions. It sets out three risk-mitigation strategies — prevention (asset inventories including AI/ML components, secure-by-design, patching), detection (scaled vulnerability discovery), and management — and updates on planned DORA oversight activity for critical ICT third-party providers (CTPPs). It explicitly builds on the ESRB's 25 June 2026 warning (ESRB/2026/3) and ENISA's frontier-AI cybersecurity view published the same month.
Why it matters
This is the first joint statement from all three EU financial supervisory authorities specifically addressing frontier-AI-driven ICT/cyber risk, escalating AI security from a general-purpose cybersecurity concern to an explicit cross-sectoral supervisory expectation for EU banks, insurers, and investment firms. Although styled as a 'statement' rather than binding technical standards or guidelines, it signals imminent supervisory dialogue and examination focus, and feeds directly into DORA's ICT third-party oversight regime.
Action needed
EU-regulated financial entities should benchmark ICT risk-management frameworks, AI/ML asset inventories, and incident-response/recovery plans against the ESAs' prevention/detection/management framing ahead of supervisory dialogue; CTPPs should track related DORA oversight activity updates.