EBA - European Banking Authority

07/31/2026 | Press release | Distributed by Public on 07/31/2026 06:37

EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector

  • Press Release
  • 31 July 2026

The European Supervisory Authorities (EBA, EIOPA and ESMA - the ESAs) today published a statement (link) calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.

The statement takes into account existing regulatory requirements, the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, as well as recent publications by the European Systemic Risk Board (ESRB), the European Union Agency for Cybersecurity (ENISA), the Single Supervisory Mechanism (SSM) and other competent authorities.

The ESAs outline measures to help financial entities strengthen their operational resilience against cyber risks linked to frontier AI models. Particular emphasis is placed on the prevention, detection and management of these risks.

The statement underlines that financial entities should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models. It also updates on ongoing and planned DORA oversight activities for critical ICT third-party providers (CTPPs) to address this risk.

The ESAs encourage both financial entities and competent authorities to use the statement as a basis for supervisory dialogue, taking into account existing supervisory expectations. Such an approach would help ensuring that the EU financial system remains resilient against the risks driven by frontier AI technologies.

Documents

ESA Statement on frontier AI models

(408.2 KB - PDF)

Related content

Topic

Digital finance

Topic

Operational resilience

Press contacts

Franca Rosa Congiu

EBA - European Banking Authority published this content on July 31, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on July 31, 2026 at 12:37 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]