The European Supervisory Authorities—EBA, EIOPA and ESMA—have issued a joint statement on the growing ICT and cyber risks associated with frontier AI models in the EU financial sector.
Frontier AI models can accelerate cyber threats by enabling malicious actors to:
🔹 Discover and exploit vulnerabilities more rapidly;
🔹 Target vulnerabilities in shared infrastructure; and
🔹 Exploit single points of failure across interconnected financial entities.
These capabilities could turn an incident affecting one entity or common service provider into a broader systemic disruption.
The ESAs call on financial entities to adapt their ICT risk management processes, procedures and controls around three strategies:
🔹 Prevention
Maintain complete and continuously updated ICT asset inventories, apply secure-by-design principles, reduce attack surfaces, strengthen access controls, automate patching for high-risk systems and monitor risks across the ICT supply chain.
🔹 Detection
Move from periodic checks towards continuous vulnerability scanning, comprehensive logging and behavioural monitoring. Security operations and red-teaming capabilities may also be strengthened using AI-supported solutions.
🔹 Management and operational resilience
Update incident response, business continuity, disaster recovery and backup arrangements to address AI-assisted attacks and potential multi-system failures. Operational resilience testing should progressively incorporate AI-enhanced threat scenarios.
The statement also emphasises the responsibility of management bodies. Financial entities should establish clear accountability, review their ICT risk appetite and tolerance thresholds, ensure adequate investment and move towards continuous, informed oversight of AI-related cyber risks.
The ESAs confirm that DORA and the AI Act already provide the regulatory foundation for addressing these risks. The statement does not establish additional requirements or a mandatory checklist; its measures are illustrative and should be applied proportionately according to each entity’s size, complexity and risk profile.
AI-related risks are also being incorporated into the DORA oversight of critical ICT third-party providers and are expected to form part of oversight activities during 2027.