2026-08-05
Added
The Malta Financial Services Authority (MFSA) clarifies that this circular does not introduce new supervisory expectations for Frontier Artificial Intelligence Models (FAIMs), but rather reinforces the continued relevance of existing regulatory requirements and governance principles for all Licence Holders. The Authority highlights that FAIMs may accelerate cyber threats by compressing the time between vulnerability discovery and exploitation, thereby placing pressure on established vulnerability-management and cyber-defence cycles. Licence Holders are encouraged to assess whether their existing ICT risk management, operational resilience, and third-party dependency arrangements remain effective against these evolving threats, particularly regarding asset visibility, patch management, and concentration risk. For entities within its scope, the circular emphasizes that Regulation (EU) 2022/2554 (DORA) remains the regulatory anchor for digital operational resilience, requiring management bodies to ensure ICT risk measures are commensurate with their risk profile and operating environment.