European Supervisors Demand Improved Governance Amid AI Risks
EBA, EIOPA, and ESMA urge enhanced oversight to mitigate ICT risks from AI models in the EU financial sector.

The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) have issued a joint statement calling for a consistent risk-based supervisory approach to mitigate ICT risks arising from advanced artificial intelligence (AI) models in the European Union financial sector.
Regulatory Requirements and Suggested Actions
This statement is based on existing regulatory requirements, the European Commission's Cybersecurity Action Plan, and publications from entities such as the European Systemic Risk Board (ESRB) and the European Union Agency for Cybersecurity (ENISA). European supervisors want financial entities to strengthen their operational resilience against cybersecurity risks associated with advanced AI models. Emphasis is placed on prevention, detection, and effective management of these risks.
Governance and Risk Management
It is essential that financial entities have robust governance and risk management frameworks to effectively manage the cybersecurity risks linked to advanced AI models. This recommendation also includes updates on ongoing and planned supervisory activities under the Digital Operational Resilience Act (DORA) for Critical Third Party Providers of ICT (CTPP).
Supervisory Dialogue and System Resilience
The ESAs encourage financial entities and competent authorities to utilize the statement as a basis for effective supervisory dialogue. This approach would help ensure that the EU financial system remains resilient against risks driven by emerging AI technologies.
For additional inquiries: Tayfun Yilmaz, Communications Officer, [email protected].
Tags
About the author

Miguel Sandoval
Regulatory Affairs Correspondent
Miguel Sandoval tracks gambling legislation, licensing, and regulator enforcement — from Spain's DGOJ and the Latin American authorities to the UKGC, the MGA, and the state-by-state map in North America. The reports answer three questions precisely — what changed, where, and who it affects — with jurisdictions, dates, and penalties cited exactly as published. Operators and compliance officers read Miguel Sandoval to know which rulebook moved before their next meeting.
More from Miguel Sandoval








