TL;DR
European financial regulators EBA, EIOPA, and ESMA have jointly issued a call for enhanced governance and consistent supervision to mitigate ICT risks arising from advanced AI models. The move aims to strengthen oversight across the EU financial sector amid growing AI adoption.
European financial regulators EBA, EIOPA, and ESMA have jointly called for enhanced governance frameworks and consistent supervisory practices to address the increasing ICT risks associated with frontier AI models in the EU financial sector. This coordinated effort aims to strengthen oversight as AI adoption accelerates, highlighting the importance of managing emerging technological risks in a rapidly evolving landscape.
The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA) released a joint statement emphasizing the need for improved governance structures and harmonized supervisory approaches to manage risks from advanced artificial intelligence models. The regulators specifically point to the potential cybersecurity, operational, and compliance risks posed by frontier AI systems used in financial services.
The statement urges financial institutions and supervisors to implement robust governance arrangements, including clear accountability, risk management protocols, and ongoing oversight of AI deployments. It also calls for supervisory consistency across member states to prevent regulatory gaps and ensure effective risk mitigation. These measures are presented as part of a broader effort to align AI risk management with existing financial regulation frameworks.
While the regulators did not specify immediate regulatory changes, they emphasized that supervisory bodies should integrate AI-specific risk assessments into their existing oversight processes. The joint call reflects a recognition of AI’s transformative potential and the need for proactive governance to prevent systemic risks, data breaches, and other operational failures tied to frontier AI systems.
Implications for Financial Stability and Regulatory Frameworks
This coordinated call underscores the increasing importance of governance in AI deployment within the EU financial sector. As AI models become more complex and integrated into core operations, the risk of operational failures, cyberattacks, and compliance breaches grows. Strengthening governance and ensuring consistent supervision is critical to maintaining financial stability and protecting consumers. The move also signals a shift toward more harmonized regulatory practices across the EU, aiming to prevent regulatory arbitrage and ensure a level playing field.

Designing Financial Data Architectures: Patterns and Principles for AI, Analytics, and Operational Efficiency
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Growing Adoption of AI in EU Financial Services and Regulatory Response
Over recent years, AI technologies, especially frontier models, have become integral to financial institutions’ risk assessment, trading, customer service, and fraud detection systems. This rapid adoption has raised concerns among regulators about potential ICT vulnerabilities, operational disruptions, and data security issues. Prior to this joint statement, individual regulators had issued guidelines on AI risk management, but a unified, cross-sector approach was lacking.
The European Commission has signaled its intention to develop comprehensive AI regulations, including specific provisions for financial services. The current joint call from EBA, EIOPA, and ESMA reflects a proactive stance to embed governance and supervision measures ahead of formal regulations, emphasizing the importance of consistent oversight to mitigate systemic risks.
Recent incidents involving AI-related operational failures and cyber threats have heightened the urgency for such coordinated regulatory guidance, especially as frontier AI models continue to evolve rapidly and expand their use cases in finance.
“Effective governance and consistent supervision are essential to managing the ICT risks posed by frontier AI models in financial markets.”
— Maarten Verwey, Chair of ESMA

AI In Cybersecurity: Simplifying Cyber Risk with Smart, Affordable Tools for Small Business Defense
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Details on Specific Regulatory Measures Still Unclear
While the joint statement emphasizes the need for improved governance and supervision, it does not specify concrete regulatory changes or timelines. It remains unclear whether new binding rules will be introduced or if existing frameworks will be adapted to better address AI risks. The extent to which individual member states will implement harmonized measures also remains to be seen.

AI Model Risk Blueprint: Model Validation Testing | Ethical Considerations in AI Models | Integrating AI with Business Risk Plans | Real-World AI Model Risk Strategies | AI Governance Tools & Resource
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps Include Stakeholder Engagement and Regulatory Development
Regulators are expected to engage with financial institutions, technology providers, and industry associations to develop detailed guidance and possible regulatory proposals. The European Commission is also expected to incorporate these recommendations into upcoming AI regulation initiatives. Monitoring of AI deployment and supervisory practices will likely intensify over the coming months, with updates on specific measures anticipated later this year.

AI-Powered Contract Management: AI-Powered Contract Management:AI contract management, legal automation, contract lifecycle management, AI legal tech, … compliance monitoring, smart contracts.
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What specific risks do frontier AI models pose to financial institutions?
Frontier AI models can introduce cybersecurity vulnerabilities, operational failures, data privacy issues, and compliance challenges, which may threaten financial stability and customer trust.
Will new regulations be introduced as a result of this call?
The regulators have not announced specific new regulations yet. They are emphasizing the need for improved governance and supervision, with details to be developed in the coming months.
How will this affect financial institutions operating in the EU?
Institutions will likely need to review and strengthen their AI governance frameworks, ensure supervisory compliance, and prepare for increased oversight related to AI risks.
Is this part of broader EU efforts on AI regulation?
Yes, it aligns with the European Commission’s broader AI strategy, which aims to establish comprehensive rules for AI deployment across sectors, including finance.
Source: primary