Frontier AI models accelerate systemic cyber risks in EU finance
EBA Press

Frontier AI models accelerate systemic cyber risks in EU finance

The European Supervisory Authorities have urged financial entities to strengthen risk management against cyber threats from frontier AI models. A joint statement issued on July 31 outlines three core strategies—prevention, detection, and management—under the DORA and AI Act frameworks.

Three pillars to counter machine-speed threats

The European Supervisory Authorities (EBA, EIOPA, and ESMA) warned that advanced frontier AI models accelerate cyber risks by enabling rapid vulnerability exploitation and targeting shared infrastructure.

To counter machine-speed threats, financial entities must adapt risk management across three pillars: prevention, detection, and risk management.

Prevention relies on complete IT asset inventories, secure-by-design architecture, and automated patching.

Detection requires transitioning from periodic to continuous vulnerability scanning while deploying AI-driven security operations.

Management demands updating business continuity plans to handle multi-system failures and embedding AI-related risks directly into executive governance frameworks.

Regulatory alignment and oversight plans

The joint statement builds on existing EU frameworks, notably the Digital Operational Resilience Act (DORA) and the AI Act, which establish baseline requirements for third-party risk management and general-purpose AI models.

Beyond setting expectations for financial entities, supervisory authorities are incorporating frontier AI risks into their own oversight mechanisms.

As Lead Overseers under DORA, the ESAs have begun integrating AI threat scenarios into their examination methodology and plan to assess critical third-party providers starting in 2027.

Necessary guidance, but enforcement is key

The guidelines offer a necessary roadmap for addressing automated cyber threats.

Yet non-binding expectations leave too much room for patchy implementation across member states.

True resilience depends on whether regulators actually penalize slow-moving legacy institutions.