What Changed
EBA, EIOPA and ESMA — together referred to as the ESAs — have published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.

The statement underlines that financial entities should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models.
Highlights
- EBA, EIOPA and ESMA published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.
- The statement underlines that financial entities should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models.
- The ESAs outline measures to help financial entities strengthen their operational resilience against cyber risks linked to frontier AI models.
- The statement also provides an update on ongoing and planned DORA oversight activities for critical ICT third-party providers, known as CTPPs.
Who Is Affected
If you hold an account with a broker or other financial firm supervised in the EU, this statement is directed at that firm rather than at you directly, since the ESAs encourage financial entities and competent authorities to use the statement as a basis for supervisory dialogue.
The statement also feeds into ongoing and planned DORA oversight activities for critical ICT third-party providers, or CTPPs — the technology vendors that financial firms rely on for their operations.
What To Watch Next
The ESAs' emphasis falls on prevention, detection and management of these risks, which gives a sense of where supervisors will focus their attention as firms adapt.
To that end, the ESAs outline measures intended to help financial entities strengthen their operational resilience against cyber risks linked to frontier AI models.
The statement draws on existing regulatory requirements as well as the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, so newer investors and traders following this space can expect future supervisory guidance to build on both.