The European Supervisory Authorities (ESAs) have set out three risk mitigation strategies – prevention, detection and management – to help financial entities minimise ICT risks stemming from frontier artificial intelligence (AI) models.
The ESAs include the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA).
In their statement, they call for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models, focused around three key areas.
Prevention relies on “comprehensive and continuously updated inventories of all IT assets”, as this enables financial entities to classify assets based on criticality and exposure.
The second, detection, scales up existing vulnerability discovery processes, in terms of timeliness and complexity, to match the existing threats. However, the ESAs warned that despite preventative measures, the “perimeter might still be breached by AI-assisted threat actors”.
“Therefore, detective measures are essential to identify, analyse, and respond to intrusions before they escalate into significant incidents. Monitoring processes transition from periodic to continuous, to reduce detection and response times, and enhance visibility into unusual or malicious behaviour,” they stated.
Thirdly, the ESAs said financial entities should focus on the management of cyber risk to improve operational resilience. This should be done through operational resilience testing, enhanced disaster recovery, data backup capabilities and increased cyber maturity.
“Risk management frameworks, testing methodologies, and governance structures need to adapt to address AI-assisted threats and potential multi-system failures. In parallel, management bodies must ensure that accountability keeps pace with emerging risks, while cybersecurity awareness must evolve toward a more proactive and adaptive mindset,” the ESAs said.
The ESAs encouraged both financial entities and competent authorities to use the statement as a basis for supervisory dialogue, taking into account existing supervisory expectations.
They said that doing so would help ensure that the EU financial system remains resilient against the risks driven by frontier AI technologies.










Recent Stories