Every passage attributed to the statement below was read in the published document itself, retrieved from the issuing authorities' own domain on 2 September 2026, and the reference and date are given in the sources block. Where the document cites another body, this desk has followed the citation to that body's own pages and says what it found, including where two dates are in play for the same instrument. Nothing here is legal advice, and the statement should be read in full before anything is built on it.
- A joint statement of the European Supervisory Authorities, issued through their Joint Committee under the title Toward a consistent and risk-based approach for ICT risks from frontier AI models, is now published and addressed to financial entities and their supervisors.
- It runs on the resilience rail, not the AI Act rail. The framework it asks entities to adjust is the DORA framework: ICT risk management, testing, incident and recovery management, and ICT third-party risk management.
- Three strategies are set out: prevention, detection and management. The first concrete artefact named is a comprehensive and continuously updated inventory of all IT assets, including AI and machine learning components.
- The governance ask is specific. Management body accountability should move from periodic oversight to continuous, informed engagement, and the risk appetite framework should account for indirect exposure to frontier models, not only for internal use of them.
- It reaches vendors too. The authorities acting as Lead Overseers record targeted engagement with critical ICT third-party service providers, insights feeding the 2027 Oversight Plan, and AI risks being embedded into the Oversight Examination Methodology.
What arrived, and why it did not look like AI regulation
A compliance function tracking AI in Europe through 2026 has been tracking one thing: the application dates of the AI Act, and what the Omnibus did to them. That is the right primary focus. It has also produced a blind spot, because the supervisory apparatus of European finance does not wait for a single statute to tell it what to worry about, and it has now said something about frontier AI on machinery that was already in force.
The document is a joint statement of the European Supervisory Authorities, which is to say the banking, insurance and occupational pensions, and securities and markets authorities acting through their Joint Committee. Its title is Toward a consistent and risk-based approach for ICT risks from frontier AI models, and the noun that carries the argument is in the middle of it: ICT risks. Not compliance risks, not conduct risks, not model risk in the actuarial sense. Information and communications technology risk, which in European financial regulation has a home, a regulation and a supervisory routine already.
The statement is explicit that it is not adding anything. Its stated goal is to provide context to the current situation considering the existing legislation and supervisory expectations, through possible mitigating actions that financial entities may implement to address these risks. A reader looking for a new duty will not find one. A reader looking for what supervisors will ask about in the next cycle has found it.
The rail it chose
Section 5 of the statement is the load-bearing paragraph for anybody trying to work out which body of law this belongs to, and it is worth reading closely rather than summarising.
It says that the current EU regulatory framework, especially the Digital Operational Resilience Act and the AI Act, provides a solid foundation to tackle risks stemming from the release of highly capable AI models. It then says that the requirements set out in DORA remain highly relevant, and it lists them: the implementation of the ICT risk management framework, testing, incident and recovery management, and ICT third-party risk management. Its treatment of the AI Act is a single sentence, and it points at the regime for general-purpose AI models with systemic risk, where providers of those models are subject to additional obligations including transparency, the provision of relevant technical documentation and cybersecurity aspects.
Notice what that division does. The AI Act obligations named are obligations on the model providers. The obligations the addressees of this statement actually hold, and which the statement asks them to adjust, are DORA obligations. The AI Act appears as part of the landscape; DORA appears as the thing to go and work on. Our reading of how AI systems sit inside the DORA perimeter for financial entities is at agentinsured.eu, on DORA and AI systems in financial services, and the certification-side treatment of the same perimeter is at agentcertified.eu, on DORA and AI agent certification.
The statement also names the reason the existing framework is being pointed at rather than replaced. It observes that the regulatory framework remains technology-neutral, and that what has changed is the length of the vulnerability discovery and exploitation cycle. Shorter cycles, therefore act fast and proactively, therefore make the arrangements to enhance cybersecurity capabilities and adapt them to the new context. That is a regulator declining to write a new rulebook and instead saying that the existing one has to be executed faster. It is an unglamorous move and, on the evidence of how long AI-specific legislation takes to arrive anywhere, a realistic one.
What the authorities say the capability actually is
The opening paragraph makes three claims about what frontier models change, and all three are worth holding precisely, because they are the claims that make this an aggregation question rather than an incident question.
The statement says advanced capabilities significantly accelerate cyber risks, and that AI-enabled cyber tools could generate systemic risks through the ability to rapidly discover and exploit vulnerabilities, to target vulnerabilities in shared infrastructure, and to turn to advantage what it calls single points of failure across entities. It is balanced about direction: it says the same models can help deliver substantial defensive improvements, while noting that defenders have to implement their responses following quality assured protocols, which attackers do not.
Read those three items again with an insurance eye rather than a compliance eye. Speed collapses the window between discovery and exploitation. Shared infrastructure means many organisations hold the same weakness. Single points of failure across entities means one failure reaching many balance sheets. Those are the three properties that turn a set of independent risks into a correlated one, and correlation is the property that decides whether a risk can be carried at all. A European supervisor has described the correlation structure of AI-enabled cyber risk in a published document, which is a more useful artefact for that conversation than any market commentary. The coverage-side reading of that point is at agentinsured.eu, on systemic model failure and aggregation.
Prevention, detection, management
The operative section asks entities, taking into account the expectations of their own supervisory authorities, to adjust ICT risk management processes, procedures and controls according to three strategies. An annex gives examples against each. The summary below follows the statement's own ordering and language.
Prevention. The first named requirement is an inventory. The statement says prevention relies on comprehensive and continuously updated inventories of all IT assets, including infrastructure, applications, data repositories, APIs, and AI or machine learning components, because that is what enables assets to be classified by criticality and exposure. It then asks for secure-by-design principles so that systems are architected with built-in safeguards rather than relying solely on reactive controls, for strong monitoring and proactive patching to reduce the window of exposure, and for assessment of the risk arising from dependencies among IT assets. The annex extends the same logic outward, asking entities to assess, monitor and enforce cybersecurity standards across the whole supply chain, including not only service providers and partners but also software and hardware providers and open-source communities.
Detection. Here the ask is a change of tempo rather than a change of tool. Detection scales up existing vulnerability discovery processes in timeliness and complexity to match the threat, on the premise that the perimeter might still be breached. Monitoring processes transition from periodic to continuous, to reduce detection and response times and to improve visibility of unusual or malicious behaviour. The annex adds that periodic security checks such as annual penetration tests or compliance audits may be insufficient, because gaps between scheduled checks are exploitable by an adversary that adapts in real time.
Management. This covers operational resilience testing, enhanced disaster recovery, data backup capability and increased cyber maturity, and it asks that risk management frameworks, testing methodologies and governance structures adapt to AI-assisted threats and potential multi-system failures. Two specifics in the annex deserve attention. Backups should not be exposed to the same risks as primary systems, which is an old lesson restated for a faster adversary. And resilience testing should evolve to simulate AI-enhanced threat scenarios, because attacks that trigger cascading failures across interconnected systems are not what traditional resilience tests anticipate.
None of these ideas is novel in isolation, and the statement does not pretend otherwise. What is new is the ranking. An inventory that includes AI and machine learning components as first-class assets, maintained continuously rather than annually, is the first thing named in the first strategy, and it is the artefact almost nobody has. The certification-side treatment of that specific artefact is at agentcertified.eu, on the inventory as the first evidence artefact.
The governance ask, and the phrase that reaches everybody
Two sentences in the statement will do more work in practice than the whole annex, because they are addressed to the level of an organisation that decides what gets funded.
The first asks competent authorities to ensure that a financial entity's management body is fully committed to mitigating these risks, with clear governance and accountability frameworks in place, timely response plans adequately prepared, and sufficient internal investments dedicated to strengthening cyber resilience. The annex sharpens it: management body accountability should evolve from periodic oversight to continuous, informed engagement, integrating cybersecurity into strategic decisions and ensuring sufficient resources are allocated. The reasoning given is that AI-driven attacks target not only technical systems but also governance weaknesses, decision-making gaps and risk oversight failures.
The second is the sentence that reaches organisations which had concluded that none of this concerns them. The statement asks that the risk appetite framework be reviewed to update or incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them.
Indirect exposure is the operative phrase, and it is unusually well chosen. An entity that has adopted no frontier model, banned the tools internally and taken no AI vendor is nevertheless exposed, because the capability sits with whoever is attacking it and inside the technology supply chain it already depends on. Deciding not to adopt is not a way of declining the exposure, it is only a way of declining the benefit. Any board paper that answers a question about AI risk by describing the organisation's AI adoption has answered a different question from the one the supervisor is asking.
The annex that says it is not a checklist
The annex opens with a disclaimer worth quoting because of the tension it creates. It says that financial entities may consider these strategies and actions taking into account their size, complexity, interconnectedness and risk exposure, that it does not establish additional requirements, nor should be regarded as a comprehensive checklist, and that it is to be read as illustrative examples, also in dialogue with ICT third-party service providers.
Every word of that is accurate and none of it will stop the annex being used as a checklist, because it is the most specific published list of what supervisors have said they are thinking about. This is a recurring shape in supervisory soft law and it is worth naming rather than complaining about. The correct response is not to treat the annex as a control framework and tick it, and it is also not to disregard it because it disclaims itself. It is to be able to say, for each item, either that you do it, or that you have considered it and concluded it is not proportionate for you, and why. Proportionality is not an excuse in this document, it is a requirement: the statement says twice that a one-size-fits-all approach would not be proportionate or efficient, and that entities should take account of their size, risk profile, interconnectedness, scale and complexity, citing DORA Article 4 for the principle.
A reasoned negative decision is a governance artefact. An absent decision is a finding. That distinction is the same one that runs through the whole documentation logic of the AI Act, which we set out at Article 9 and the risk management system and, for what has to be written down and retained, at Article 12 on logging and record keeping.
The part that reaches your vendors
The final substantive paragraph is the one an AI vendor or cloud provider should read first, because it describes something that has already happened rather than something proposed.
The authorities record that, acting as Lead Overseers, they have initiated targeted engagement with relevant critical ICT third-party service providers to understand how those providers identify and manage the new challenges they face, covering identification and assessment of the risks, the mitigation measures implemented, and adaptation to the opportunities associated with the new capabilities. They state that the insights gained have informed the annual risk assessment cycle and the prioritisation of activities under the 2027 Oversight Plan, that AI-related risks are being embedded into the Oversight Examination Methodology with that work continuing through 2027, and that these threats are expected to be reflected in the scope of oversight examinations and other oversight activities in 2027.
For a financial entity, that changes the character of a vendor conversation. Questions about a provider's own AI exposure are no longer an unusual request from a nervous customer; they are aligned with what the provider is being asked by its overseer. For a provider, it means the answers should exist in a form that survives being repeated. And for both, it is a reminder that the value chain question in AI is rarely about the model and usually about who is answerable for what, which we treat under the Act at Article 25 and value chain responsibilities.
What this does not do
Four boundaries, stated plainly, because a statement like this attracts over-reading in both directions.
It creates no AI Act obligation and changes no AI Act date. Standalone Annex III high-risk obligations still apply from 2 December 2027 and Annex I from 2 August 2028 under the AI Omnibus, and the deployer duties in Article 26 are untouched by anything here. The complete reading of those duties is at the Article 26 complete guide.
It is not about AI agents doing your work. This is the most common misreading available. The statement is about frontier models as a capability in the hands of attackers and inside shared infrastructure. It is not about a customer service agent giving wrong advice, or an underwriting model producing a biased decision. Those are real exposures and they sit elsewhere, in professional liability, in the Act's high-risk regime, and in product liability. Keeping the two apart is the whole point of the buyer-facing companion to this piece at insureyouragent.com, on which AI risk your insurance is actually about.
It does not apply to organisations outside the financial perimeter. The addressees are financial entities and their competent authorities. A logistics company or a software vendor is not being spoken to. It would be a mistake to conclude that the analysis is therefore irrelevant to them, since the description of the threat is not sector-specific and the supervisory tempo in finance has a long history of setting expectations that later travel, but the obligation is not theirs.
It is not a prediction. The statement describes a risk that has been assessed as serious by more than one European body and sets out mitigations. It does not forecast an event, and this desk does not either.
The wider set this belongs to, and a note on two dates
The statement does not stand alone, and following its own citations is instructive. It positions itself as consistent with initiatives from the European Systemic Risk Board, from the European Union Agency for Cybersecurity and from competent authorities, and with the objectives of the Action Plan on Cybersecurity and Artificial Intelligence brought forward at Commission level. It notes that the agency for cybersecurity has issued an initial set of recommendations to develop operational capabilities, a document titled ENISA's View on Cybersecurity in the Frontier AI Era, whose publication page carries the date 7 July 2026. It records that the central bank has emphasised to the chief executives of significant institutions the importance of addressing open supervisory findings on ICT and security risks without delay, referring to earlier on-site inspections, targeted reviews and a cyber-resilience stress test.
A note on the Commission action plan. Its publication date is not stated in this article. The date is not in dispute and this desk has read the Commission page, but the fact is not yet inside our own registry of verified third-party claims, and the standing rule on this publication is that an unregistered date attributed to a named body is dropped rather than softened. The action plan is real, it is cited in the sources block by its own title and page, and any reader needing the date should take it from that page rather than from us.
On the systemic risk board's warning there are two dates in play and this desk states both rather than choosing. The joint statement's own footnote cites a warning on systemic cyber risks stemming from frontier artificial intelligence models carrying the reference ESRB/2026/3 and the date 25 June 2026. The board's own press release list, read on 2 September 2026, carries the announcement under the date 7 July 2026, with the title Frontier AI models could strain cyber resilience in the financial system, ESRB warns. Those are not necessarily in conflict, since an instrument adopted at a board meeting is commonly published later, but this desk has not read a page that says so, so it reports the two dates with their sources attached and settles neither. The release also records that systemic cyber risk was rated severe in June 2026, having been rated elevated three months earlier.
What to do with this
For a financial entity, four things, in order of how quickly they can be done.
Find out whether the inventory exists. Not the application inventory. An inventory that lists AI and machine learning components as assets, with owners, criticality and exposure classifications, updated continuously. If it does not exist, that is the first item, and it is also the artefact every adjacent regime asks for, so it is not work spent once.
Put indirect exposure into the risk appetite framework in words. The distinction between internal use and indirect exposure is the statement's own, it is unusual, and a framework that only addresses adoption will read as having missed the point.
Convert the annex into a decision record. For each item, do it, or record that it was considered and why it is not proportionate. That record is the difference between a proportionality argument and a gap.
Ask your critical providers what they told their overseer. They have been asked. The answers exist. Asking for them is now an ordinary request rather than an awkward one.
For everyone else, the useful move is narrower. Notice that Europe's first co-ordinated supervisory statement on frontier AI arrived through operational resilience law rather than through AI law, and check whether your own AI risk work is filed exclusively under the AI Act. The structural version of that argument, written for operators outside the European perimeter, is at agentliability.co, on the rail AI risk actually arrives on.
Questions
What is the ESA Statement on frontier AI models?
A joint statement of the European Supervisory Authorities, published through their Joint Committee under the title Toward a consistent and risk-based approach for ICT risks from frontier AI models. It is addressed to financial entities and to the competent authorities that supervise them. It is not legislation and it does not create new obligations. Its own words are that the goal is to provide context to the current situation considering the existing legislation and supervisory expectations, through possible mitigating actions that financial entities may implement to address these risks.
Is the ESA statement an AI Act instrument?
No, and that is the most important thing about it. It names both the Digital Operational Resilience Act and the AI Act as providing a solid foundation, but the machinery it asks entities to adjust is DORA machinery: the ICT risk management framework, testing, incident and recovery management, and ICT third-party risk management. Its reference to the AI Act is to the regime for general-purpose AI models with systemic risk, which sits on providers of those models rather than on the entities being addressed. The supervisory conversation about AI risk in European finance is therefore happening on the resilience rail, and it is happening now rather than on the deferred high-risk timetable.
What are the three risk mitigation strategies in the statement?
Prevention, detection and management. Prevention rests on comprehensive and continuously updated inventories of all IT assets, including infrastructure, applications, data repositories, APIs and AI or machine learning components, so that assets can be classified by criticality and exposure, together with secure-by-design architecture, monitoring, proactive patching and assessment of dependencies between assets. Detection is the move from periodic to continuous monitoring, so that intrusions are identified before they escalate. Management covers resilience testing, disaster recovery, backup capability and the adaptation of risk frameworks, testing methodologies and governance structures to AI-assisted threats and potential multi-system failures.
What does the statement mean by indirect exposure to frontier AI?
It is the phrase that reaches organisations which believe this does not concern them. The statement asks that the risk appetite framework be reviewed to update or incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them. An entity that deploys no frontier model is still exposed, because the capability sits with whoever is attacking it and inside the supply chain it depends on. Deciding not to adopt is not a way of declining the exposure.
Does the ESA statement create new legal obligations?
No. The statement is framed as context and encouragement rather than requirement, and its annex says in terms that it does not establish additional requirements, nor should be regarded as a comprehensive checklist, and is to be read as illustrative examples. What it does create is an articulated supervisory expectation, and entities are invited to use it as a basis for dialogue with their supervisors. In practice a published expectation that a supervisor has co-signed tends to arrive in a supervisory meeting as a question, which is a different thing from a rule and not a lesser one.
Does this affect AI vendors as well as financial entities?
Yes, through the oversight route. The statement records that the authorities acting as Lead Overseers have initiated targeted engagement with relevant critical ICT third-party service providers, covering how those providers identify and assess the risks, what mitigations they have implemented and how they are adapting. It states that the insights gained have informed the annual risk assessment cycle and the prioritisation of activities under the 2027 Oversight Plan, that AI-related risks are being embedded into the Oversight Examination Methodology, and that these threats are expected to be reflected in the scope of oversight examinations in 2027. A designated provider is already being asked these questions directly.
Sources
- Joint Committee of the European Supervisory Authorities, ESA Statement titled Toward a consistent and risk-based approach for ICT risks from frontier AI models, carrying the date 31 July 2026 on its own cover, together with a Joint Committee document reference which is not reproduced here. All passages attributed to the statement in this article, including the three capability claims, the DORA and AI Act framing in its section 5, the three mitigation strategies, the management body and risk appetite paragraphs, the Lead Overseer paragraph and the annex disclaimer, were read in the published document retrieved from esma.europa.eu on 2 September 2026. The publication entry, with the same reference and date, was also read at eiopa.europa.eu on 2 September 2026.
- Accompanying press release, titled EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector, read at eba.europa.eu on 2 September 2026, including the invitation to use the statement as a basis for supervisory dialogue.
- Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence, read at digital-strategy.ec.europa.eu on 2 September 2026. The publication date shown on that page is deliberately not restated in this article, for the reason given in section 9. The page read carries no reference to the financial sector or to supervisory authorities, and none is attributed to it here.
- European Union Agency for Cybersecurity, ENISA's View on Cybersecurity in the Frontier AI Era, publication page dated 7 July 2026, read at enisa.europa.eu on 2 September 2026. Only the landing page was read; the full report was not, and nothing from its contents is stated here beyond its own note that the recommendations are not an all-inclusive checklist.
- European Systemic Risk Board. Two dates are recorded in this article and neither is preferred over the other. The joint statement's footnote cites a warning on systemic cyber risks stemming from frontier artificial intelligence models under the reference ESRB/2026/3 with the date 25 June 2026. The board's 2026 press release list carries the announcement Frontier AI models could strain cyber resilience in the financial system, ESRB warns under the date 7 July 2026, read at esrb.europa.eu on 2 September 2026. The description of frontier AI models as advanced models capable of materially affecting offensive or defensive cyber operations, and the record of the risk rating moving from elevated to severe, come from that release. No page reconciling the two dates was read, so this desk states both.
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector is referred to here only as DORA and only through the statement's own citations of it, including its citation of Article 4 for the proportionality principle. The regulation text was not read at source for this article and no provision of it is quoted.
- Regulation (EU) 2024/1689 (EU AI Act) and Regulation (EU) 2026/1744 (the AI Omnibus, in force 27 July 2026). Annex III standalone high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. digital-strategy.ec.europa.eu.
- The observation in section 9 that three of the cited documents carry the same date, and the correlation reading in section 3, are this desk's own analysis. Neither is attributed to any authority, and no authority has described the statement as an aggregation analysis.
- No relationship exists between Future Proof Intelligence and any authority, agency or organisation named in this article. Each is named because it published the document attributed to it, on its own domain.