| Link(s): | ESA Statement on frontier AI models – European Insurance and Occupational Pensions Authority ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models |
Context
The European Supervisory Authorities (ESAs), including EIOPA, have released a statement noting that the advanced capabilities of recent frontier AI models significantly accelerate cyber risks, underscoring the urgent need for robust cybersecurity measures and rapid incident response capabilities.
In a similar message to the statement published by the FCA in May 2026, the ESAs warn that AI-enabled cyber tools could generate systemic risks due to their ability to rapidly discover and exploit vulnerabilities, target vulnerabilities in shared infrastructure, and leverage single points of failure across entities.
Key points to note and next actions
- To strengthen risk mitigation, promote a coordinated supervisory approach and to ensure a level playing field across the EU, the ESAs are encouraging financial entities to adjust Information and Communication Technology (ICT) risk management processes, procedures and controls according to the following three risk mitigation strategies: i) prevention; ii) detection; iii) management.
- To assist firms, the statement includes an annex providing examples of risk mitigation strategies and actions firms may wish to consider, in order to improve resilience in the face of potential AI-driven threats. The examples are listed under the titles of ‘Prevention’, ‘Detection’, and ‘Risk management and operational resilience’.
