Joint endorsement by the three ESAs. On the same day, the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA)—collectively the ESAs—issued a joint statement endorsing the ESRB's warning . They urged every financial entity within the scope of the Digital Operational Resilience Act (DORA)—including banks, insurers, asset managers, and investment firms—to adapt its cybersecurity and ICT-risk arrangements to address frontier AI threats
.
ESA statement on consistent supervision (31 July 2026). Three weeks later, the ESAs published a formal joint statement (JC 2026 25) calling for a cross-sectoral, risk-based, and consistent supervisory approach . Key demands included enhanced governance and board-level accountability for AI-enabled cyber risks, continuous risk assessments and updated ICT risk management frameworks, rapid incident response capabilities calibrated to AI-compressed attack timelines, and a level playing field across all financial sectors
.
ECB direct letter to significant institution CEOs. On 7 July 2026, Claudia Buch, Chair of the ECB's Supervisory Board, sent letters to the CEOs of all Significant Institutions (SIs) supervised under the Single Supervisory Mechanism (SSM) . The letters required immediate and proactive measures against AI-enabled cybersecurity threats and demanded concrete action plans from each institution
. According to reports, roughly 110 lenders were asked to submit comprehensive plans by the end of October 2026
.
UK financial authorities moved in a similar timeframe with a series of escalating interventions.
Joint statement: Bank of England, FCA, and HM Treasury (15 May 2026). The Bank of England, the Financial Conduct Authority (FCA), and HM Treasury issued a joint statement calling on all regulated financial firms and financial market infrastructures to urgently strengthen cyber defences against frontier AI models . The statement set out five domains of expected action: governance and strategy, vulnerability management, third-party risk management, protection, and response and recovery
. It reinforced that existing operational resilience rules and the Senior Managers and Certification Regime already require firms to plan for and mitigate these risks
.
Bank of England / FPC names AI a systemic stability risk (7 July 2026). On the same day the ESRB published its warning, the Bank of England's Financial Policy Committee (FPC), in its half-yearly Financial Stability Report, named AI a distinct systemic risk on two fronts: leverage and concentration in AI-linked markets, and frontier-AI-amplified cyber threats . Deputy Governor Sarah Breeden signalled that bespoke policy measures may follow for autonomous AI agents
. Reuters reported the BoE specifically highlighted AI's role in increasing banks' vulnerability to cyberattacks
.
FCA Mills Review (6 July 2026). The FCA published a major review of AI in financial services, concluding that AI will amplify fraud and cyber risks—making fraud more convincing, scalable, and harder to detect—and calling for updated regulatory frameworks .
Regulators did not act in an information vacuum. Several major 2026 surveys document the scale and speed of the threat, and the industry's own sense of being under-prepared.
Data from outside Europe reinforces the picture. The Reserve Bank of India's June 2026 Financial Stability Report found AI-enabled cyber threats are the top perceived cybersecurity risk facing India's financial sector . The DSCI reported that exploit windows have collapsed from approximately 745 days to about 44 days, while attack costs have fallen by over 70%
.
Across official regulatory statements, industry bodies, and expert commentary, a consistent set of recommended responses has emerged.
Governance and accountability. Embed frontier AI cyber risk into board-level risk appetite and ICT governance frameworks, treating it as a systemic rather than purely operational concern . Assign clear accountability at senior management level for AI-related cyber risk
.
Technical and operational measures. Invest in real-time network visibility and AI-driven defensive tools; firms with visibility gaps are far more likely to suffer AI-powered breaches . Apply cyber hygiene fundamentals consistently—rapid patching, access management, network segmentation, and zero-trust architecture—as recommended by the UK's National Cyber Security Centre (NCSC)
. Implement blast-radius controls to limit the spread of breaches
. Conduct regular red-teaming and adversarial testing specifically targeting frontier AI attack scenarios
.
Supervisory and cross-border coordination. Pursue a "whole-of-nation" approach bringing together financial regulators, cybersecurity agencies, and AI developers, as advocated by the IMF and ESRB . Strengthen international coordination through bodies like the G7 Cyber Expert Group and the Financial Stability Board; the G7 has already published strategies including stronger governance and cross-sector engagement
. Scale up public-sector AI and cyber expertise to keep pace with private-sector capabilities
.
Strategic direction. Move from rule-setting to hands-on supervision of AI cyber risks, as UK and EU regulators are already doing . Treat the compressed exploit window as the new normal and adjust incident response service-level agreements accordingly
. Consider whether existing notification thresholds and capital requirements under DORA and Solvency II adequately capture frontier AI risk
.
The consensus is clear: frontier AI cyber risk is no longer a future scenario. It is an active systemic threat, and the appropriate response combines strong governance, fundamental cyber hygiene, investment in defensive AI, and deep cross-border supervisory coordination.