This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 1 minute read

EU supervisors suggest how financial firms should prevent, detect and manage AI-cyber disruption

Last month the European Central Bank told the banks it oversees to submit their plans for addressing AI-enabled cybersecurity threats by the end of October. Since then the European Supervisory Authorities have used a joint statement setting out how firms should adapt their DORA controls for AI-driven threats.

Responding to the new threat landscape

Like the ECB, the ESAs describe the changing threat landscape arising from frontier AI models. From Claude Mythos through to Hugging Face and a recent incident report from the UK AI Security Institute, the list of examples of how AI is enhancing cyberattacks is getting longer.

According to the ESAs, all firms should “without delay” establish governance structures to monitor and manage the risk of AI-assisted cyber incidents. Firms should also update their risk appetite frameworks.

The ESAs note the importance of the Digital Operational Resilience Act. Among other things, DORA requires EU financial entities to implement an ICT risk management framework, test for vulnerabilities and report major ICT-related incidents.

Illustrative actions

The ESAs encourage financial entities to adjust their ICT risk management controls according to the following strategies: prevention, detection and management. The statement does not create new obligations but does suggest potential actions for firms including:

  • Updating inventories of all IT assets to classify them by criticality and exposure

  • Taking a proactive approach to patching to reduce the window of exposure

  • Scaling up discovery of vulnerabilities to match AI-assisted threats

  • Using AI as part of continuous monitoring processes to reduce detection times

  • Testing incident reporting and business continuity processes for AI-assisted threats and multi-system failures

  • Enforcing cybersecurity standards across the supply chain

Critical providers

The ESAs also describe how they have started to engage with critical third-party providers under DORA on this topic. Initially this has been to understand how vendors identify and mitigate risks. Looking ahead the ESAs will use this information to determine their future oversight activities.

Looking ahead

This is the latest in a growing list of interventions by financial supervisors about AI-enhanced cyber threats. In its July 2026 letter the ECB told banks to address open supervisory findings relating to cyber resilience without delay. Firms across the financial services sector should take similar steps, as well as updating their internal risk frameworks and controls, including processes and policies, to respond to the evolving threat landscape in a way which is proportionate to their business. Firms should also get ready to respond to their regulators to explain what they are doing to maintain their operational resilience.

Tags

dora, operational resilience, ai, cyber, eu, fintech, payments, banking