The ESAs support ESRB warning on systemic cyber risks from frontier AI models

The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support today’s warning from European Systemic Risk Board (ESRB) on the systemic cyber risks posed by frontier AI models.

Recent advances have significantly enhanced the ability of frontier AI models to identify and exploit high-severity vulnerabilities in IT systems within very short timeframes. While the EU’s regulatory framework – including DORA and the AI Act – provides a solid foundation for managing cyber and AI-related risks, the speed and scale of these tools raise concerns that AI-enabled cyber-attacks could undermine the operational resilience of financial entities.

Since the release of the first frontier AI models, the ESAs have raised awareness about the ICT risks posed by the widespread adoption of these models and engaged with EU competent authorities to ensure that financial entities take appropriate mitigation measures. In their first annual report on major ICT-related incidents under DORA, the ESAs encouraged financial entities to strengthen cybersecurity measures to maintain their resilience amid the rapid evolution of highly capable AI-driven tools.

Against this backdrop, the ESAs concur with the ESRB warning and urge financial entities to make appropriate arrangements to adapt their cybersecurity capabilities. They also invite competent authorities to reflect these developments in their supervisory activities. Finally, the ESAs note the ESRB’s call on the European Union to scale up its capacity, expertise and strategic autonomy in this critical area, which requires that all parties are involved, including AI providers, software providers, security firms, open-source maintainers, financial institutions, and authorities at both national and Union level.

The ESAs are working closely with the EU supervisory community to ensure that financial entities across the EU proactively identify and mitigate these risks in line with the requirements of the Digital Operational Resilience Act (DORA), which establishes a harmonised framework for mitigating ICT risks in the financial sector.

In their capacity as Overseers of Critical ICT Third-Party Providers, the ESAs are also engaging with these providers on the measures they are taking to adapt to the situation, in order to manage risks and ensure the continuity of services provided to the EU financial sector.

​The EBA consults on rules to further improve depositor protection under the revised Deposit Guarantee Schemes Directive

EBA logo

EBA E-mail alert 23 July, 2026

News & Press

​The EBA consults on rules to further improve depositor protection under the revised Deposit Guarantee Schemes Directive

News

​The European Banking Authority (EBA) today launched four public consultations on proposed rules to further strengthen depositor protection, preserve financial stability, and further harmonise depositor protection standards across the EU under the revised Deposit Guarantee Schemes Directive (DGSD3). The EBA seeks stakeholders’ feedback on Implementing Technical Standards (ITS) on depositor information, ITS on information exchange between credit institutions, Deposit Guarantee Schemes (DGSs) and other relevant authorities, Regulatory Technical Standards (RTS) on the treatment of client funds protection standards across the EU, and Guidelines (GL) on how DGSs should invest funds collected from the industry. The four consultations run until 23 October 2026.

EBA launches Discussion Paper on Pillar 3 Data Hub for small banks

EBA launches Discussion Paper on Pillar 3 Data Hub for small banks

EBA launches Discussion Paper on Pillar 3 Data Hub for small banks

 

News

​The European Banking Authority (EBA) today published a Discussion Paper which proposes a simplified process for small and non-complex institutions (SNCIs) when implementing the Pillar 3 Data Hub (P3DH). The objective is to gather stakeholder feedback on a streamlined approach under which the EBA would collect and perform the calculation and publication of Pillar 3 disclosures for SNCIs, thereby reducing the burden for the latter.

EBA launches Discussion Paper on Pillar 3 Data Hub for small banks

​The EBA launches early consultation on simplified EU-wide stress test, with climate risk integration

The EBA launches early consultatio on simplified EU-wide stress test, with climate risk integration

Press Release

The European Banking Authority (EBA) published today the draft methodology, templates, and template guidance for the 2027 EU-wide stress test. The 2027 exercise introduces significant simplifications to improve efficiency and risk sensitivity, while preserving the robustness and comparability of results. Key changes include a substantial reduction in data requirements, the alignment of information with harmonised supervisory reporting, and the integration of climate risks into the EU-wide stress test. A total of 63 banks from the EU and Norway, including 47 from the euro area, will participate, covering 75% of the EU banking sector. The industry consultation is being launched at an earlier stage than for previous EBA stress tests, to facilitate banks’ preparedness.

You can edit or cancel your subscription at any time. Manage your subscription or unsubscribe.
Please do not reply to this message. If you have questions, please visit our contact page.
Please refer to EBA’s Legal notice regarding the handling of your personal data.
EBA launches Discussion Paper on Pillar 3 Data Hub for small banks

EBA E-mail alert 17 July, 2026

​The EBA consults on amendments to data collection for the 2027 market risk benchmarking exercise

News

​The European Banking Authority (EBA) today launched a consultation on amendments to the Implementing Technical Standards (ITS) governing the benchmarking of internal models and the standardised approach for market risk for the 2027 exercise. The proposed amendments aim to ensure that the benchmarking framework remains aligned with the evolving regulatory framework, while providing institutions and supervisors with adequate time to prepare for the implementation of the upcoming market risk requirements. This consultation runs until 3 September 2026.