ESAs Call for Stronger ICT Risk Governance for Frontier AI
Frontier AI ICT risk analysis in the financial sector – GOWISE Academy

ESAs Call for Stronger ICT Risk Governance for Frontier AI

The European Supervisory Authorities—EBA, EIOPA and ESMA—have issued a joint statement on the growing ICT and cyber risks associated with frontier AI models in the EU financial sector.

Frontier AI models can accelerate cyber threats by enabling malicious actors to:

🔹 Discover and exploit vulnerabilities more rapidly;
🔹 Target vulnerabilities in shared infrastructure; and
🔹 Exploit single points of failure across interconnected financial entities.

These capabilities could turn an incident affecting one entity or common service provider into a broader systemic disruption.

The ESAs call on financial entities to adapt their ICT risk management processes, procedures and controls around three strategies:

🔹 Prevention

Maintain complete and continuously updated ICT asset inventories, apply secure-by-design principles, reduce attack surfaces, strengthen access controls, automate patching for high-risk systems and monitor risks across the ICT supply chain.

🔹 Detection

Move from periodic checks towards continuous vulnerability scanning, comprehensive logging and behavioural monitoring. Security operations and red-teaming capabilities may also be strengthened using AI-supported solutions.

🔹 Management and operational resilience

Update incident response, business continuity, disaster recovery and backup arrangements to address AI-assisted attacks and potential multi-system failures. Operational resilience testing should progressively incorporate AI-enhanced threat scenarios.

The statement also emphasises the responsibility of management bodies. Financial entities should establish clear accountability, review their ICT risk appetite and tolerance thresholds, ensure adequate investment and move towards continuous, informed oversight of AI-related cyber risks.

The ESAs confirm that DORA and the AI Act already provide the regulatory foundation for addressing these risks. The statement does not establish additional requirements or a mandatory checklist; its measures are illustrative and should be applied proportionately according to each entity’s size, complexity and risk profile.

AI-related risks are also being incorporated into the DORA oversight of critical ICT third-party providers and are expected to form part of oversight activities during 2027.

Share: 

Save up to 20%

Learn More, Save More

Enroll in multiple courses and unlock exclusive bundle discounts

Related news:

Group Discount
Learn Together, Save Together

Team orders? Get 10% off automatically — bigger groups, contact us.

We value your privacy

We use cookies to personalize content, and analyze our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy