2026-06-15
Added · Updated
The Belgian Financial Services and Markets Authority (FSMA) warns that frontier AI systems significantly lower the barrier for cyberattacks, compelling all regulated entities to reassess and increase their cyber risk exposure. The regulator mandates strict compliance with the EU DORA Regulation by implementing specific measures to identify ICT assets, protect systems through rapid patching, and detect incidents swiftly. Furthermore, firms are required to ensure their ICT service providers adopt equivalent resilience standards to mitigate supply chain vulnerabilities.
FSMA published 1 document in the last 30 days — get each new one by email the day it lands.
12–14 Rue du Congrès 1000 Brussels / www.fsma.be Communication FSMA_2026_15 of 15-06-26 Impact of 'Frontier AI systems' on cyber risk Scope This communication is primarily intended for entities subject to the European DORA Regulation. The FSMA also encourages entities that are not subject to DORA to apply these recommendations. Summary Recent developments in artificial intelligence are leading to a sharp increase in the cyber risk to which regulated firms are exposed. The capabilities of certain artificial intelligence models are now such that entities which previously considered themselves at low risk of cyberattacks, due in particular to their size or activities, must reassess the likelihood and impact of such an attack on their systems. The DORA Regulation sets out measures to reduce your cyber risk. 1 Frontier AI systems significantly increase the cyber risk for all entities Like other financial supervisory authorities1 , the FSMA draws the attention of the firms it supervises to the developments which occurred in recent months in the field of artificial intelligence. The emergence of so-called frontier AI Systems2 with advanced capabilities for detecting vulnerabilities in ICT systems certainly enables the development of more secure ICT applications and the testing of existing ones. However, it also has the corollary effect of multiplying the possibilities for malicious use. These models make it possible to not only very rapidly identify on an industrial scale a large number of vulnerabilities within IT systems, including in legacy and/or widely used applications, but also combine and exploit them automatically. Using these models does not require advanced expertise in the field. As things stand, those models are not currently yet widely available, nor in their entirety. However, it is expected that the possibilities in this area will only continue to expand. Models with equal or superior capabilities could become widely available in the near future. 1 See, for example, the statements from the French Autorité des marchés financiers (Résilience cyber : l'AMF appelle les acteurs financiers à renforcer leurs dispositifs face à l’évolution rapide des menaces liées à l’intelligence artificielle) and the Dutch Autoriteit voor Financiële Markten (Snellere AI-aanvallen vragen om sterkere weerbaarheid). 2 This term refers to the most advanced AI models at any given time. Communication
Read the rest free, and get an email when FSMA publishes again
Source: Financial Services and Markets Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FSMA
FSMA published 1 document in the last 30 days. We email you each new one the day it's published.