# ESA Statement on ICT risks from frontier AI models (JC 2026 25): ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models

Source: https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement
Last updated: Aug 26, 2026

On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery and exploitation and could create systemic cyber risk. It tells financial entities to adjust ICT risk-management processes under DORA around three strategies — prevention, detection and management — proportionately to their size and risk profile (DORA Art. 4), and says management bodies must own the risk and revisit risk-appetite metrics. The ESAs as Lead Overseers are embedding frontier-AI risk into DORA oversight of critical ICT third-party providers for the 2027 Oversight Plan.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) |
| Type | Guidance |
| Status | In force |
| Published | Jul 31, 2026 |
| Effective | Jul 31, 2026 |
| Applies to | All financial entities subject to DORA — banks, payment institutions, insurers, investment firms — and their competent authorities; critical ICT third-party providers under DORA oversight |
| Official text | https://www.eba.europa.eu/publications-and-media/press-releases/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision-mitigate-ict-risks-frontier |

## Key points

- Published July 31, 2026 as Joint Committee document JC 2026 25; follows the ESRB warning of June 25, 2026 (ESRB/2026/3), ENISA recommendations and the Commission's July 7, 2026 Action Plan on Cybersecurity and AI.
- Positions DORA and the AI Act (GPAI models with systemic risk) as the existing legal foundation; introduces no new requirements but asks entities to act fast and proactively.
- Prevention: continuously updated inventories of IT assets including AI/ML components, secure-by-design, proactive patching, dependency risk assessment.
- Detection: scale vulnerability discovery, move from periodic to continuous monitoring, enhance SOC and red-teaming with AI tools.
- Management: resilience testing, disaster recovery and backup, adapting risk frameworks and governance to AI-assisted threats and multi-system failures.
- Management bodies must ensure governance and accountability, response plans and investment; risk-appetite frameworks should add metrics and tolerance thresholds for frontier-AI risk.
- Supervisors to use the statement in supervisory dialogue; the ECB has pressed significant institutions' CEOs to close open ICT findings without delay.
- Lead Overseers engaged critical ICT third-party providers and are embedding AI risk into the Oversight Examination Methodology and 2027 oversight activities.

## What changed for banks

This is the first EU-level supervisory statement treating frontier AI as a cyber-threat multiplier rather than a model-governance issue. It converts DORA's technology-neutral ICT risk rules into concrete expectations — asset inventories including AI components, continuous monitoring, AI-enhanced red teaming, refreshed risk appetite — that supervisors will now test in dialogue and examinations, and it extends the same lens to cloud and AI vendors under DORA oversight.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)

## FAQ

### Does the ESA frontier AI statement create new DORA obligations?

No. JC 2026 25 states that DORA and the AI Act already provide the legal foundation and that its annex does not establish additional requirements. It sets out expected mitigation strategies — prevention, detection, management — that supervisors will use in dialogue with financial entities.

### What should a bank's board do about frontier AI cyber risk?

Per the July 31, 2026 ESA statement, management bodies should establish governance and accountability for frontier-AI-driven cyber risk, prepare timely response plans, dedicate investment to cyber resilience, and review the risk appetite framework to add metrics and tolerance thresholds for both internal use of such models and indirect exposure to them.

### Are cloud and AI vendors covered by the frontier AI statement?

Yes. The ESAs as DORA Lead Overseers have engaged critical ICT third-party providers on frontier-AI risks and are embedding these risks into the Oversight Examination Methodology and the 2027 Oversight Plan.

## Related documents

- [EBA factsheet: AI Act implications for the EU banking and payments sector](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-act-factsheet-2025) — AI Act: implications for the EU banking and payments sector (Nov 21, 2025)
- [EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384)](https://www.bankingnewsai.com/ai-regulation/documents/eba-2025-d-5384-ai-act-mapping-letter) — Outcome of EBA's AI Act mapping exercise — letter to DG FISMA and DG CNECT (Nov 21, 2025)
- [EBA Work Programme 2026](https://www.bankingnewsai.com/ai-regulation/documents/eba-work-programme-2026) — EBA Work Programme 2026 — AI Act implementation and digital-finance priorities (Oct 1, 2025)
- [EBA report: Rising application of AI in EU banking and payments (Sep 2025)](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-adoption-report-2025) — Rising application of AI in EU banking and payments sector (Sep 25, 2025)
- [EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28)](https://www.bankingnewsai.com/ai-regulation/documents/eba-rep-2023-28-ml-irb-follow-up) — Machine Learning for IRB Models — Follow-up report from the consultation on the Discussion paper on machine learning for IRB models (Aug 4, 2023)
- [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) — EBA/GL/2022/15 Guidelines on the use of Remote Customer Onboarding Solutions under Article 13(1) of Directive (EU) 2015/849 (Nov 22, 2022)
- [EBA discussion paper on machine learning for IRB models](https://www.bankingnewsai.com/ai-regulation/documents/eba-ml-irb-discussion-paper-2021) — Discussion Paper on machine learning for IRB models (Nov 11, 2021)
- [EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2020-06-loan-origination-monitoring) — Guidelines on loan origination and monitoring (May 29, 2020)

Last reviewed Aug 26, 2026. Cite the official text (https://www.eba.europa.eu/publications-and-media/press-releases/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision-mitigate-ict-risks-frontier) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
