top of page

ESAs Set Supervisory Expectations on Frontier AI Cyber Risk

  • Writer: OpusDatum
    OpusDatum
  • Jul 31
  • 3 min read
European Banking Authority logo with large blue eba text and the full name beside it on a white background

The European Supervisory Authorities — the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA), collectively the ESAs — published a joint statement on 31 July 2026 calling for a cross-sectoral, risk-based and consistent supervisory approach to the information and communication technology (ICT) risks arising from frontier artificial intelligence (AI) models. The statement takes account of existing regulatory requirements, the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, and recent publications by the European Systemic Risk Board (ESRB), the European Union Agency for Cybersecurity (ENISA), the Single Supervisory Mechanism (SSM) and other competent authorities. It sets out measures to strengthen operational resilience against frontier AI-linked cyber risk, organised around three mitigation strategies: prevention, detection and management. It also provides an update on ongoing and planned Digital Operational Resilience Act (DORA) oversight activity for critical ICT third-party providers (CTPPs).


The analytical basis is set out in the ESRB's June warning, which the ESAs endorsed on 7 July. The ESRB found that frontier models can discover vulnerabilities, generate working exploits and autonomously execute full-scale cyberattacks at a speed, scale and accuracy far exceeding earlier AI systems, characterising this as a paradigm shift in cybersecurity and a source of systemic risk to the EU financial system. The ESAs are explicit that the mitigation strategies are not to be applied uniformly: entities are expected to calibrate to their size and overall risk profile, and to the nature, interconnectedness, scale and complexity of their services, activities and operations. The statement imposes no new legal obligations on third-party providers of ICT services, including frontier AI model providers themselves.


For UK-regulated firms, the statement is confirmatory rather than novel. The Bank of England, the Financial Conduct Authority (FCA) and HM Treasury issued a joint statement on 15 May 2026 reaching materially the same conclusion — that frontier AI cyber capability now exceeds what a skilled practitioner can achieve in speed and scale, and that adversaries can exploit vulnerabilities across multiple firms simultaneously at a rate conventional controls cannot match — anchored in existing obligations including FCA Principle 3, Prudential Regulation Authority (PRA) Fundamental Rule 7 and the operational resilience rules in force since March 2022. The operative provisions for FCA solo-regulated firms sit in SYSC 15A; for PRA-authorised firms, the Rulebook and supervisory statement SS1/21 apply, with model risk expectations under SS1/23 also engaged. Neither the UK nor the EU authorities have created new rule text. Both have signalled that supervisory dialogue will now test how existing frameworks are being applied to this threat vector.


The practical consequence for financial crime functions is that the integrity of detection infrastructure is now a live supervisory question rather than an IT concern held at arm's length. Transaction monitoring, sanctions and payment screening, and customer due diligence platforms sit within the same technology estate and, in many institutions, are delivered by the same concentrated group of third-party vendors that DORA's CTPP oversight and the UK's critical third parties regime were designed to address. Compromise, manipulation or degradation of those systems is a financial crime control failure as much as an operational resilience event, and the record of testing, tuning governance and vendor assurance will be read that way. Firms should also expect the identity and authentication layer to attract scrutiny, given the direct line between AI-enabled credential compromise or synthetic impersonation and downstream unauthorised payment and fraud exposure.


UK groups with EU-authorised entities face the sharper operational question. DORA oversight of CTPPs proceeds on its own timetable, and evidence of frontier AI risk assessment will be requested at entity level. Divergence in the supporting documentation between UK and EU arms of the same group is difficult to defend when the underlying vendor stack is shared. UK firms should track output from the Cross Market Operational Resilience Group (CMORG) and the National Cyber Security Centre (NCSC), and revisit the cyber resilience effective practices published by the Bank, PRA and FCA in October 2025.


bottom of page