On 7 July 2026, the European Systemic Risk Board (ESRB) issued a warning (dated 25 June 2026) on systemic cyber risks stemming from frontier artificial intelligence models (FAIMs).
Warning
The warning notes that current evidence indicates that FAIMs are capable of discovering vulnerabilities, generating working exploits and autonomously executing full-scale cyberattacks at a speed, scale and level of accuracy far exceeding previous AI models. This constitutes a paradigm shift in the cybersecurity domain and an inflection point in terms of AI capability. As such the ESRB considers these developments to be a source of systemic risks to the EU financial system.
The ESRB states that it is essential to ensure that systemically important payment and settlement systems and financial market infrastructures remain protected against vulnerabilities emerging from FAIM use and development. Public and private operators should thoroughly review and update their cybersecurity frameworks to take into account such vulnerabilities. Authorities in charge of supervision or oversight should adopt measures to ensure that systems are adequately protected.
The ESRB General Board has also approved the publication of a note entitled “Addressing Frontier AI Models with cyber capabilities from a financial stability perspective”. This note provides further analysis of the risks identified.
ESAs
ECB letter to banks
The European Central Bank (ECB) has written to the CEOs of significant institutions setting out supervisory expectations for addressing the evolving AI-related cyber threat landscape.
The ECB is calling on significant institutions to assess the impact of the evolving threat landscape without delay, and to develop a comprehensive action plan outlining concrete measures to strengthen relevant controls, allocating the necessary resources, assigning clear roles and responsibilities, and defining timelines for implementation. The action plan should build upon the significant institution’s existing cyber-risk strategy and address both immediate priorities and longer-term strategic aspects. The action plan should be submitted to the respective Joint Supervisory Team (JST) by 31 October 2026. The JST will further engage with the significant institution to discuss the action plan and will monitor its progress.
The ECB will also conduct a horizontal analysis of the submitted action plans to identify trends, challenges and areas for improvement, and will share its conclusions with significant institutions to support them in strengthening their ICT resilience.
In addition, the ECB is extending the deadline for the annual collection of the IT Risk Questionnaire from September 2026 to February 2027.
