2026-08-05
Added · Updated
The Malta Financial Services Authority (MFSA) clarifies that this circular does not introduce new supervisory expectations for Frontier Artificial Intelligence Models (FAIMs), but rather reinforces the continued relevance of existing regulatory requirements and governance principles for all Licence Holders. The Authority highlights that FAIMs may accelerate cyber threats by compressing the time between vulnerability discovery and exploitation, thereby placing pressure on established vulnerability-management and cyber-defence cycles. Licence Holders are encouraged to assess whether their existing ICT risk management, operational resilience, and third-party dependency arrangements remain effective against these evolving threats, particularly regarding asset visibility, patch management, and concentration risk. For entities within its scope, the circular emphasizes that Regulation (EU) 2022/2554 (DORA) remains the regulatory anchor for digital operational resilience, requiring management bodies to ensure ICT risk measures are commensurate with their risk profile and operating environment.
MFSA published 1 document in the last 30 days — get each new one by email the day it lands.
Circular
Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Frontier Artificial Intelligence Models and the Evolving CyberThreat Landscape This Circular applies to all Licence Holders. References to Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (“DORA”) apply only to those Licence Holders falling within its scope. Background and Recent Developments The Malta Financial Services Authority (the “MFSA” or the “Authority”) draws Licence Holders’ attention to recent European publications concerning the evolving cyber risks associated with Frontier Artificial Intelligence Models (“FAIMs”). These include the Warning and accompanying report issued by the European Systemic Risk Board (“ESRB”), the communication issued by European Central Bank (“ECB”) and the Joint Statement published by the European Supervisory Authorities (“ESAs”). FAIMs are advanced artificial intelligence (“AI”) models with capabilities that may materially affect offensive and defensive cyber operations. The European publications indicate that such models may enable cyber activity to be conducted with greater speed and sophistication, including through the accelerated discovery of vulnerabilities and development of exploits. Although FAIMs may also support defensive capabilities, their development represents a material change in the cyber-threat landscape. The Authority is not, through this Circular, introducing a separate set of supervisory expectations specifically addressing FAIMs. Rather, the developments highlighted by the European authorities reinforce the continued relevance of existing regulatory requirements and of the governance, risk management and prudential principles previously communicated by the MFSA, including through its Dear CEO Letter on Artificial Intelligence issued on 4 June 2026. 5 August 2026
Read the rest free, and get an email when MFSA publishes again
Source: Malta Financial Services Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from MFSA
MFSA published 1 document in the last 30 days. We email you each new one the day it's published.