top of page

Frontier AI and Cyber Risk: New ESA Expectations for Financial Entities

  • Elena Niki Karletidi
  • Aug 2
  • 5 min read

On 31 July 2026, the European Supervisory Authorities—the EBA, EIOPA and ESMA—issued a joint Statement on ICT risks from frontier AI models.


The statement highlights the growing cybersecurity and operational-resilience risks arising from increasingly capable AI models and calls on financial entities to strengthen their existing ICT risk-management arrangements without delay.


It does not establish new legal obligations or a separate implementation deadline. It does, however, provide a clear indication of how supervisory expectations are developing under the Digital Operational Resilience Act (DORA) and the EU AI Act.


What is frontier AI?

Frontier AI refers to highly advanced, general-purpose AI models operating at the leading edge of current technological capability. Such models can perform a wide range of sophisticated tasks, including analysing and generating software code, processing large volumes of information, identifying technical weaknesses, and supporting complex reasoning and planning.


“Frontier AI” is primarily a descriptive term rather than a separate legal classification under the EU AI Act. The closest formal concept under the AI Act is a general-purpose AI model with systemic risk, for which providers are subject to additional obligations relating to risk assessment, technical documentation, transparency and cybersecurity.


Frontier AI can significantly improve cyber defence by supporting vulnerability detection, threat analysis, security monitoring and incident response. However, the same capabilities may be used by malicious actors to identify and exploit vulnerabilities faster, conduct more sophisticated attacks and target multiple interconnected systems.


Why are the ESAs concerned?

The ESAs identify three features that may create wider risks for the financial sector.


Frontier AI models may enable malicious actors to:

  • discover and exploit vulnerabilities at considerably greater speed;

  • target weaknesses in shared infrastructure and ICT supply chains; and

  • identify and leverage dependencies or single points of failure across interconnected entities.

This creates the possibility that a cyberattack may not remain limited to one financial entity or system.


Where several firms depend on the same cloud provider, software component, network service, API or other critical technology, an AI-assisted attack may cause simultaneous or cascading disruption. If the disruption persists or affects multiple institutions, the consequences could extend to the broader financial system and the real economy.


The issue is therefore not simply whether a financial entity uses frontier AI internally. Firms may also be exposed indirectly through cybercriminals, ICT third-party providers, counterparties, shared infrastructure and technology supply chains.


Existing weaknesses may become more significant

The ESAs emphasise that the accelerating threat environment can increase the materiality of existing ICT control weaknesses.


Open findings relating to vulnerability management, access controls, legacy infrastructure, incident response, business continuity, third-party risk or security monitoring may become more serious when threat actors can identify and exploit weaknesses at machine speed.


Financial entities should therefore not approach frontier AI risk as a completely separate compliance exercise. They should assess whether existing weaknesses identified through audits, penetration tests, supervisory reviews, resilience testing and other assurance activities require faster remediation or stronger controls.


DORA and the AI Act provide the regulatory foundation

The statement does not create a new regulatory framework. Instead, the ESAs emphasise that DORA and the AI Act already provide the principal foundation for addressing these emerging risks.


DORA remains directly relevant through its requirements concerning:

  • ICT risk management;

  • identification and classification of ICT assets;

  • incident detection, management and reporting;

  • business continuity and disaster recovery;

  • digital operational-resilience testing;

  • ICT third-party risk management; and

  • management-body responsibility and oversight.


The AI Act complements this framework by regulating certain uses of AI systems and introducing specific requirements for providers of general-purpose AI models with systemic risk.


The ESAs expect financial entities to implement appropriate measures proportionately, considering their size, overall risk profile and the nature, scale, complexity and interconnectedness of their services and operations.


The three risk-mitigation priorities

The ESAs organise the recommended response around three areas: prevention, detection and management of cyber risk.


1. Prevention

Effective prevention begins with a comprehensive and continuously updated inventory of ICT assets. The inventory should cover infrastructure, applications, data repositories, APIs, AI and machine-learning components, software dependencies and relevant external services. These assets should be classified based on their criticality, exposure and dependencies.


Financial entities should consider:

  • embedding security and operational resilience into system design;

  • implementing effective network segmentation;

  • reducing unnecessary external exposures and decommissioning unsupported legacy systems;

  • strengthening access management, least-privilege controls and multi-factor authentication;

  • protecting proprietary source code and critical system configurations;

  • accelerating risk-based vulnerability remediation and patching;

  • introducing appropriate automated security controls into development and operational processes; and

  • applying cybersecurity standards across the full ICT supply chain.


Supply-chain assessments should extend beyond direct service providers. Relevant dependencies may include cloud providers, software and hardware suppliers, third-party APIs, outsourced security operations and open-source components.


2. Detection

Traditional security monitoring often relies on known attack signatures, predefined patterns or periodic vulnerability scanning. These approaches may be less effective against AI-assisted attacks that can adapt rapidly and generate unusual behaviour.


The ESAs therefore encourage financial entities to consider:

  • continuous or more frequent vulnerability scanning;

  • comprehensive logging and behavioural monitoring;

  • improved anomaly and lateral-movement detection;

  • faster analysis and escalation of unusual activity;

  • increased frequency of security testing and compliance checks;

  • enhanced security operations centre capabilities; and

  • appropriate use of AI-supported monitoring and red-teaming tools.


Monitoring should remain risk-based. The objective is not simply to generate more alerts, but to improve the entity’s ability to identify and respond to genuine threats before they develop into significant incidents.


3. Cyber-risk management and operational resilience

Incident-response and business-continuity arrangements are frequently designed around individual system failures or predictable attack sequences.

Frontier AI may facilitate attacks affecting several systems simultaneously or exploiting dependencies in ways that traditional scenarios do not anticipate. Financial entities should therefore consider whether their existing response and recovery arrangements remain adequate.


Relevant actions include:

  • updating incident-response and business-continuity scenarios to address AI-assisted attacks;

  • testing the organisation’s ability to respond to simultaneous or cascading system failures;

  • strengthening disaster-recovery and data-backup arrangements;

  • ensuring backup environments are not exposed to the same vulnerabilities as primary systems;

  • incorporating AI-enhanced cyber threats into operational-resilience testing;

  • identifying and monitoring critical software, infrastructure and operational dependencies; and

  • introducing faster risk-monitoring and escalation arrangements.


The ESAs clarify that the measures included in their statement are illustrative and do not constitute a comprehensive checklist. Each financial entity must determine the appropriate controls based on its own risk profile and operating environment.


Management-body responsibility

The statement places significant emphasis on management-body accountability.

Management bodies should ensure that:

  • frontier AI-related risks are incorporated into the entity’s ICT risk-management framework;

  • responsibilities and reporting lines are clearly defined;

  • timely response and recovery plans are maintained;

  • sufficient financial, technical and human resources are allocated;

  • significant weaknesses are remediated without unnecessary delay; and

  • management information supports continuous and informed oversight.


The Risk Appetite Framework should also be reviewed to determine whether relevant metrics, tolerance thresholds and control measures adequately reflect the evolving risk profile.


This assessment should cover risks arising both from the entity’s own use of advanced AI and from indirect exposure through malicious actors, ICT providers and other external dependencies.


ICT third-party providers will also face increased attention

The ESAs, acting as Lead Overseers under DORA, have already begun targeted engagement with relevant critical ICT third-party providers.

AI-related risks are being incorporated into the DORA Oversight Examination Methodology and are expected to influence the 2027 oversight programme and related examinations.


Financial entities should therefore consider how their critical ICT providers identify, assess and manage AI-enabled cyber threats. Contractual rights, assurance information, testing participation, incident cooperation and supply-chain visibility may become increasingly important.


What should financial entities do now?

Although the statement introduces no new deadline, its instruction to act without delay signals an immediate supervisory expectation.


Financial entities should consider conducting a focused assessment covering:

  1. their direct and indirect exposure to frontier AI risks;

  2. the completeness of ICT asset and dependency inventories;

  3. outstanding ICT and cybersecurity weaknesses;

  4. vulnerability identification, remediation and patching timescales;

  5. continuous monitoring and detection capabilities;

  6. AI-assisted and multi-system incident scenarios;

  7. business continuity, disaster recovery and backup resilience;

  8. ICT third-party and supply-chain exposure;

  9. management-body oversight and escalation arrangements; and

  10. the continued suitability of the Risk Appetite Framework.


The objective should be to integrate frontier AI risks into the existing DORA framework rather than create a disconnected governance structure.



 
 

The material reflected in our website, including Blog material, is for informational purposes only and does not constitute legal advice, consulting, or any other professional advice. Please seek independent professional guidance for your specific needs.

All rights reserved. No part of this work may be reproduced, stored in a retrieval system of any nature, or transmitted, in any form or by any means including photocopying and recording, without the prior written permission of the ENAH Services Ltd. The reproduction or transmission of all or part of the work, whether by photocopying or storing in any medium by electronic means or otherwise without the written permission of the owner is strictly prohibited and the commission of any unauthorised act in relation to the work will result in civil and/or criminal actions. 

bottom of page