Europe’s three supervisory authorities—European Banking Authority (EBA)  European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authorities (ESMA)—have jointly called on financial firms to sharpen ICT risk management as frontier AI models introduce faster-moving cyber threats than legacy systems were built to handle.

In a statement published last week, the ESAs said the existing regulatory toolkit—chiefly the Digital Operational Resilience Act (DORA) and the AI Act—remains fit for purpose, but firms can’t afford to lean on it passively. The core problem is speed: frontier models are compressing the gap between a vulnerability being discovered and exploited, and legacy dependencies across firms’ IT estates aren’t built to keep pace.

The framework stays technology-neutral, the regulators said, but that shrinking window is what’s driving the call to action: move fast, get proactive, upgrade cybersecurity capabilities to match the new threat landscape.

Why frontier models raise the stakes

New models mean new dependencies threaded through IT estate and AI-assisted threat actors probing and breaching perimeters faster than traditional ones. This creates a vulnerability lifecycle accelerating past what periodic security reviews can catch.

The authorities thus urge firms follow three lines of defence:

Prevent: Full, current inventories of every IT asset—infrastructure, applications, data, APIs, AI/ML components—classified by criticality and exposure. Secure-by-design architecture and proactive patching over reactive fixes. Map dependencies to know where to act first.

Detect: Periodic monitoring gives way to continuous. Prevention won’t always hold against AI-assisted breaches, so firms need AI-enhanced SOC and red-teaming to match the speed and complexity of the threat.

Manage: Testing, disaster recovery, backup and governance built to withstand AI-driven risk—including multi-system failures. Expect knock-on updates to business continuity plans and IT architecture.

The ESAs frame this as proportionate, not universal: firms scale their response to size, risk profile and operational complexity, not a single mandate. They said they’ll keep working with national authorities to keep supervision “proportionate, risk-based and forward-looking” as frontier AI capabilities evolve, in line with DORA’s broader resilience objectives.