09/04/2026 | News release | Distributed by Public on 09/04/2026 07:22
Posted on September 4, 2026 by Editor
Europe's three financial supervisors have set out how the sector should handle the cyber risks that come with the most powerful AI systems. The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA), together the European Supervisory Authorities, have published a joint statement calling for a consistent, risk-based approach to the ICT risks arising from frontier AI models across banking, insurance and investment firms.
While such AI tools can help deliver substantial defensive improvements, they could also generate systemic risks by enabling attackers to find and exploit weaknesses faster than ever. The statement creates no new rules, but calls for a response drawing on existing regulation such as the Digital Operational Resilience Act (DORA) and the AI Act's regime for general-purpose models carrying systemic risk.
The prevention measures indicated lean heavily on inventories: keeping a comprehensive, continuously updated record of every IT asset, from infrastructure and applications to APIs and AI components, and mapping the dependencies between them to find potential points of failure. The wider aim is consistency, so that a frontier-model risk is supervised to the same expectations regardless of where in Europe it surfaces.
Read the statement here.