The European Supervisory Authorities (EBA, EIOPA, and ESMA) have issued a joint statement highlighting the cyber risks associated with frontier AI models. They urge financial entities to enhance governance frameworks and ensure consistent supervision to address these vulnerabilities.
The ESAs aren't introducing new regulations but are clarifying expectations under existing frameworks, particularly DORA. Supervisors will closely examine how financial entities manage AI-related ICT risks. This shift moves AI governance from theory to operational accountability for GRC leaders.
What Happened
The ESAs released a statement urging financial entities to bolster operational resilience against cyber risks from frontier AI models. The focus is on preventing, detecting, and managing these risks through strong governance and risk management.
The statement references existing regulatory requirements and recent publications from bodies like the European Systemic Risk Board and ENISA. It also updates DORA oversight activities for critical ICT third-party providers to include AI-related risks. This serves as a foundation for supervisory dialogue between authorities and financial entities.
Timeline
While no specific implementation deadline was given, the timing is significant. DORA's ICT risk management requirements become effective in January 2025. Financial entities must now meet explicit expectations regarding AI model risks as part of DORA's oversight framework.
The statement aligns with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, linking AI governance to broader operational resilience efforts. This is part of a coordinated regulatory push across EU financial supervision.
Which Controls Failed or Were Missing
The ESAs identified systemic gaps in how financial entities handle frontier AI models:
Inadequate governance over AI model deployment. Many organizations view AI models as mere technology implementations, ignoring the ICT risks they introduce. Deploying a frontier AI model, whether through a third-party provider or internally, creates dependencies that can fail or be compromised.
Insufficient cyber risk assessment for AI systems. Traditional ICT risk assessments often overlook AI-specific risks like training data poisoning, model extraction attacks, and adversarial inputs.
Weak third-party oversight for AI providers. If you're using frontier AI models from a critical ICT third-party provider, your vendor risk profile should address model-specific threats. The ESAs' statement indicates that DORA oversight will examine how well financial entities manage these dependencies.
Limited detection capabilities for AI-related incidents. Your team needs to detect model integrity compromises and manipulated outputs. Without monitoring controls tailored to AI behavior, you're operating without visibility.
What the Relevant Standard Requires
DORA's ICT risk management framework is key. Article 6 requires comprehensive ICT risk management covering identification, protection, detection, response, recovery, and learning. Article 8 addresses third-party dependencies.
For critical ICT third-party providers, DORA's oversight framework (Articles 31-44) includes investigations and inspections. The ESAs' statement clarifies that this oversight extends to AI-related ICT risks.
The statement also aligns with broader ICT governance expectations:
ISO/IEC 27001:2022 addresses information security risks but lacks AI-specific controls. Extend Annex A.5.1 (policies for information security) and A.8.1 (user endpoint devices) to cover AI model integrity and supply chain risks.
NIST AI Risk Management Framework offers a complementary approach. Its governance function calls for accountable AI systems with documented risk management processes. Map your DORA ICT risk register to NIST AI RMF categories to identify gaps.
NIS2 Directive requires entities to implement risk management measures for network and information systems. If your organization falls under NIS2, AI models processing critical data are in scope.
Lessons and Action Items for Your Team
Extend your ICT risk register to include AI model risks. Document each frontier AI model's provider, deployment model, data flows, potential failure modes, and detection mechanisms.
Update vendor risk profiles for AI providers. Ensure due diligence covers model training data sources, security measures, incident response procedures, and contractual commitments.
Build detection controls for AI integrity. Monitor for unexpected changes in model outputs, anomalous API usage, adversarial attacks, and performance degradation.
Prepare for supervisory dialogue. Document your assessment of AI-related ICT risks, implemented controls, and accepted residual risks. Supervisors will inquire.
Review your resilience testing program. DORA Article 24 requires advanced testing of ICT tools. Include scenarios where AI models fail or behave unpredictably. Address model-specific dependencies in recovery procedures.
Map AI governance to your existing framework. Integrate AI model risks into your ICT risk management framework, vendor risk program, and incident response procedures. Use existing governance structures to oversee AI deployments.
The ESAs' statement clarifies existing expectations under DORA and related frameworks. If you're treating frontier AI models as business tools without ICT risk oversight, you're not aligned with supervisory expectations. Ensure your current controls adequately address these risks or extend them as needed.





