EU Regulators Urge Enhanced Governance for AI Risks
EBA, EIOPA, and ESMA advocate for consistent oversight to address ICT risks from frontier AI models in the EU financial industry.

The European Supervisory Authorities, including the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA), have put forth a joint statement urging a consistent supervisory approach to manage ICT risks associated with frontier AI models in the EU financial sector. This call highlights the need for robust governance and risk management frameworks.
Addressing ICT Risks in AI
The statement by the ESAs emphasizes mitigating ICT risks from frontier AI models through a cross-sectoral, risk-based approach. They reference the regulatory requirements already in place, alongside the European Commission's Action Plan on Cybersecurity and Artificial Intelligence. Recent publications from the European Systemic Risk Board (ESRB) and the European Union Agency for Cybersecurity (ENISA) further inform their guidance.
Strengthening Operational Resilience
Financial entities are encouraged to enhance their operational resilience by focusing on preventing, detecting, and managing risks linked to AI models. The statement offers guidance on how to build effective governance and oversight to tackle these vulnerabilities.
Governance Frameworks
The ESAs underscore the importance of financial entities establishing strong governance frameworks. These frameworks should support efficient management and mitigation of cyber risks, particularly those posed by advanced AI models. The emphasis is on ensuring that these institutions have the necessary structures in place to withstand AI-related risks.
DORA Oversight
Ongoing and planned Digital Operational Resilience Act (DORA) oversight activities for critical ICT third-party providers (CTPPs) are highlighted as a key area to address the evolving risks. The EU's focus is on supervising the ICT ecosystems that support the financial entities, ensuring that service providers also adhere to resilience standards.
A Framework for Dialogue
The ESAs encourage this guidance to serve as a foundation for dialogues between financial entities and competent authorities. By aligning with existing supervisory expectations, the aim is to bolster the EU financial system's resilience against AI-driven risks.
For more information, you can refer to ESMA's news section.
The full statement issued on 31st July 2026, offers detailed insights into this regulatory push, and stakeholders are urged to integrate these recommendations actively.
Tags
About the author

Eleanor Whitfield
Regulatory Affairs Correspondent
Eleanor Whitfield tracks gambling legislation, licensing decisions, and regulator enforcement across key markets — from the UKGC, MGA, and Germany's GGL to Spain's DGOJ and the state-by-state map in the Americas. The reporting answers three questions precisely: what changed, where, and who it affects, with jurisdictions, effective dates, and penalty figures named exactly as published. Compliance officers and operators read Eleanor Whitfield to know which rulebook moved before their next board meeting.
More from Eleanor Whitfield








