2026-06-15
Added
The FSMA Communication FSMA_2026_15, dated June 15, 2026, addresses entities subject to the European DORA regulation and recommends its application to other financial entities. It states that "Frontier AI Systems" significantly increase IT risk, requiring entities to reassess cyberattack probabilities and impacts. The FSMA expects all DORA-subject companies to promptly implement measures across four categories: identifying IT assets, protecting them, detecting and responding to incidents, and ensuring IT service providers also take adequate measures. These measures are also relevant for financial entities not subject to DORA, as failure to comply increases the risk of cyberattacks.
Get FSMA alerts — same-day email on every new publication.
Congress Street 12-14 1000 Brussels / www.fsma.be Communication FSMA_2026_15 of 15-06-26
Impact of 'Frontier AI Systems' on Cyber Risk
Scope of Application
This communication is primarily addressed to entities subject to the European DORA regulation. The FSMA also invites financial entities not subject to DORA to apply these recommendations.
Summary
Recent developments in artificial intelligence lead to a sharp increase in the IT risk to which regulated companies are exposed. The capabilities of certain artificial intelligence models are now such that entities which, particularly due to their size or activities, previously considered themselves safe from IT attacks must reassess upwards the probability and impact of such an attack against their systems. The DORA Regulation includes measures to be adopted to reduce your IT risk.
1 “Frontier AI Systems” models significantly increase IT risk for all entities
Like other financial supervisory authorities 1, the FSMA draws the attention of the companies it supervises to the developments in artificial intelligence over recent months. The emergence of so-called “Frontier AI Systems 2” models with advanced capabilities in detecting vulnerabilities in IT systems certainly allows for the development of more secure IT applications and the testing of existing applications. However, it also has the corollary of multiplying the possibilities for malicious use.
These models make it possible to uncover a large number of vulnerabilities within IT systems, including in old and/or very widely used applications, industrially and very quickly, as well as to combine and exploit them automatically. Using these models does not require advanced skills in the field.
1 See, for example, the messages from the French Financial Markets Authority (Cyber resilience: the AMF calls on financial actors to strengthen their systems in the face of rapidly evolving threats linked to artificial intelligence) and the Dutch Authority for Financial Markets (Faster AI attacks require stronger resilience).
2 This designation refers to the most advanced AI models at a given time.
Communication
2/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA
As of today, the models in question are not yet widely or fully available. However, it is expected that the possibilities in this area will only expand. Models with equal or superior capabilities could become very widely available in the near future.
These developments have the following consequences, among others:
The economic damage likely to be caused by malicious use of these models is very high.
2 DORA offers a useful framework for dealing with these risks and entities must comply with it
In Europe, the DORA Regulation 3 has, since early 2025, harmonized the rules aimed at strengthening the digital operational resilience of financial entities. The implementation of the requirements of this regulation helps to provide a very useful response to the risks associated with these models. A brief overview of the measures that can be taken by entities is provided below.
The measures that entities should take are divided into four categories:
3 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011.
3/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA
Identify, list, and document in an inventory the different components of your IT infrastructure: your computers, network devices, servers and their configuration, the software you use, your data, etc.
Implement measures to protect your IT assets:
Implement devices and procedures to quickly detect and resolve IT incidents, and take measures to prevent the incident from recurring:
4/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA
A large part of entities' IT infrastructure is in the hands of IT service providers. Entities that outsource their IT infrastructure remain responsible for their cyber resilience and risk management within the supply chain. It is essential that providers also take adequate measures to protect themselves against the risks described here.
At the end of 2025, the European supervisory authorities (EBA, ESMA, and EIOPA, together 'the ESAs') identified 19 critical third-party IT service providers, based on the information registers submitted by entities subject to DORA. 5 In their supervision of these critical providers, the ESAs take into account the issues related to Frontier AI Systems. Some of these providers are, moreover, very large companies benefiting from full access to the models concerned.
Entities must be aware that a failure of one of their IT service providers can very quickly have a serious impact on themselves. It is therefore particularly important that they address this issue with their providers, especially those not considered critical by the ESAs.
4 See for this purpose the Practical Guide of 12 January 2026: DORA – Reporting of Major Incidents and Significant Cyber Threats.
5 Communication FSMA_2025_02 relating to the DORA information register.
3 Digital operational resilience must be a strategic priority for entities
The FSMA calls on the companies under its supervision to critically review the measures they have so far implemented to ensure that their systems, protocols, and tools meet the adequacy, reliability, capacity, and resilience requirements of the DORA Regulation.
The FSMA expects all companies subject to the DORA Regulation to quickly implement all the measures cited here. Otherwise, they now run a much greater risk of falling victim to cyberattacks. In this regard, artificial intelligence presents not only risks but also opportunities. You can use this technology to identify, prioritize, and correct vulnerabilities more quickly.
The FSMA also emphasizes that these measures are also relevant for financial entities not subject to the DORA regulation.
As a reminder, the FSMA has made educational documentation available to financial entities explaining and illustrating the content of the DORA Regulation.
Read the rest free
Source: Financial Services and Markets Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works