AI Regulation Tracker · EBA · Guidance

What does ESA Statement on ICT risks from frontier AI models (JC 2026 25) say about AI in banking?

Published Jul 31, 2026 · Last reviewed Aug 26, 2026

On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery and exploitation and could create systemic cyber risk. It tells financial entities to adjust ICT risk-management processes under DORA around three strategies — prevention, detection and management — proportionately to their size and risk profile (DORA Art. 4), and says management bodies must own the risk and revisit risk-appetite metrics. The ESAs as Lead Overseers are embedding frontier-AI risk into DORA oversight of critical ICT third-party providers for the 2027 Oversight Plan.

DocumentESA Statement on ICT risks from frontier AI models (JC 2026 25)ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models
Issued byEuropean Banking Authority
TypeGuidance
StatusIn force
PublishedJul 31, 2026
EffectiveJul 31, 2026
Applies toAll financial entities subject to DORA — banks, payment institutions, insurers, investment firms — and their competent authorities; critical ICT third-party providers under DORA oversight
Official sourceeba.europa.eu
Use casesCybersecurity · Third-party & vendor AI · AI governance (general) · Generative & agentic AI

What are the key points of ESA Statement on ICT risks from frontier AI models (JC 2026 25)?

  • Published July 31, 2026 as Joint Committee document JC 2026 25; follows the ESRB warning of June 25, 2026 (ESRB/2026/3), ENISA recommendations and the Commission's July 7, 2026 Action Plan on Cybersecurity and AI.
  • Positions DORA and the AI Act (GPAI models with systemic risk) as the existing legal foundation; introduces no new requirements but asks entities to act fast and proactively.
  • Prevention: continuously updated inventories of IT assets including AI/ML components, secure-by-design, proactive patching, dependency risk assessment.
  • Detection: scale vulnerability discovery, move from periodic to continuous monitoring, enhance SOC and red-teaming with AI tools.
  • Management: resilience testing, disaster recovery and backup, adapting risk frameworks and governance to AI-assisted threats and multi-system failures.
  • Management bodies must ensure governance and accountability, response plans and investment; risk-appetite frameworks should add metrics and tolerance thresholds for frontier-AI risk.
  • Supervisors to use the statement in supervisory dialogue; the ECB has pressed significant institutions' CEOs to close open ICT findings without delay.
  • Lead Overseers engaged critical ICT third-party providers and are embedding AI risk into the Oversight Examination Methodology and 2027 oversight activities.

What did ESA Statement on ICT risks from frontier AI models (JC 2026 25) change for banks?

This is the first EU-level supervisory statement treating frontier AI as a cyber-threat multiplier rather than a model-governance issue. It converts DORA's technology-neutral ICT risk rules into concrete expectations — asset inventories including AI components, continuous monitoring, AI-enhanced red teaming, refreshed risk appetite — that supervisors will now test in dialogue and examinations, and it extends the same lens to cloud and AI vendors under DORA oversight.

Does the ESA frontier AI statement create new DORA obligations?

No. JC 2026 25 states that DORA and the AI Act already provide the legal foundation and that its annex does not establish additional requirements. It sets out expected mitigation strategies — prevention, detection, management — that supervisors will use in dialogue with financial entities.

What should a bank's board do about frontier AI cyber risk?

Per the July 31, 2026 ESA statement, management bodies should establish governance and accountability for frontier-AI-driven cyber risk, prepare timely response plans, dedicate investment to cyber resilience, and review the risk appetite framework to add metrics and tolerance thresholds for both internal use of such models and indirect exposure to them.

Are cloud and AI vendors covered by the frontier AI statement?

Yes. The ESAs as DORA Lead Overseers have engaged critical ICT third-party providers on frontier-AI risks and are embedding these risks into the Oversight Examination Methodology and the 2027 Oversight Plan.

DateDocumentStatus
Nov 21, 2025EBA factsheet: AI Act implications for the EU banking and payments sectorAI Act: implications for the EU banking and payments sectorFinal
Nov 21, 2025EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384)Outcome of EBA's AI Act mapping exercise — letter to DG FISMA and DG CNECTFinal
Oct 1, 2025EBA Work Programme 2026EBA Work Programme 2026 — AI Act implementation and digital-finance prioritiesIn force
Sep 25, 2025EBA report: Rising application of AI in EU banking and payments (Sep 2025)Rising application of AI in EU banking and payments sectorFinal
Aug 4, 2023EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28)Machine Learning for IRB Models — Follow-up report from the consultation on the Discussion paper on machine learning for IRB modelsFinal
Nov 11, 2021EBA discussion paper on machine learning for IRB modelsDiscussion Paper on machine learning for IRB modelsSuperseded

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →