Esta página ainda não está disponível em português e é apresentada em inglês. Páginas disponíveis em português
European supervisors set out expectations on ICT risk from frontier AI models
The EBA, EIOPA and ESMA have published a joint statement calling for a cross-sectoral, risk-based and consistent supervisory approach to the ICT risks arising from frontier AI models in the EU financial sector.
On 31 July 2026 the three European Supervisory Authorities, the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority, published a joint statement on the information and communication technology risks that arise from frontier artificial intelligence models. The statement calls for a cross-sectoral, risk-based and consistent supervisory approach to mitigating those risks.
Its subject is narrower than the phrase suggests. The statement is about cybersecurity: the threats that frontier models pose to financial entities in the Union, and the prevention, detection and management of those threats. It states that financial entities should have sound governance and risk management frameworks in place to support the effective management and mitigation of the cyber risks associated with such models.
The statement is anchored in the Digital Operational Resilience Act. It carries an update on ongoing and planned DORA oversight activities for critical ICT third-party providers, which is the mechanism by which the Union supervises the providers that many financial entities depend on, rather than supervising those entities alone. The authorities say they also took account of the European Commission’s action plan on cybersecurity and artificial intelligence and of publications by the European Systemic Risk Board.
Nothing in the statement creates a new obligation on its own. The authorities present it as a foundation for supervisory dialogue and encourage both financial entities and supervisory authorities to use it that way.
A supervisory dialogue is a conversation in which one side asks what was done and the other answers. Firms that keep dated, verifiable records of the decisions behind their technology arrangements have something to answer with when that conversation begins.
This summary is informational. It is not legal advice, and it does not establish an advisory relationship. Whether a change applies to a particular company, and what it requires of that company, is a question for its own counsel.