-
ESAs statement on mitigating ICT risks from frontier AI models
31 July 2026The European Supervisory Authorities (ESAs, comprising the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority) have published a joint statement toward a consistent and risk-based approach for information and communication technology (ICT) risks from frontier AI models. The statement builds on the European Commission's action plan on cybersecurity and AI, the ESRB's warning on systemic cyber risks from frontier AI models, and the ECB's letter to significant institutions on AI-related cybersecurity threats.
While noting that existing frameworks, including the Digital Operational Resilience Act and the EU AI Act, provide a strong foundation for managing these risks, the ESAs emphasise that the speed at which vulnerabilities can be identified and exploited requires financial institutions to take a proactive approach. The ESAs encourage firms to strengthen their ICT risk management processes through three key risk mitigation strategies: prevention; detection, moving to continuous vulnerability monitoring; and management.
Examples of risk mitigation strategies and actions are set out in the accompanying annex. The ESAs state that in all cases and without delay, financial entities should establish governance structures that support effective management of frontier AI-related risk, with clear accountability frameworks, timely response plans and sufficient internal investment dedicated to strengthening cyber resilience. Separately, the ESAs as lead overseers have initiated targeted engagement with relevant critical third-party providers to understand how they identify and manage these risks.
Blog
