2026-06-15
Added · Updated
The Belgian Financial Services and Markets Authority (FSMA) warns that frontier AI systems significantly lower the barrier for cyberattacks, compelling all regulated entities to reassess and increase their cyber risk exposure. The regulator mandates strict compliance with the EU DORA Regulation by implementing specific measures to identify ICT assets, protect systems through rapid patching, and detect incidents swiftly. Furthermore, firms are required to ensure their ICT service providers adopt equivalent resilience standards to mitigate supply chain vulnerabilities.
12–14 Rue du Congrès 1000 Brussels / www.fsma.be Communication FSMA_2026_15 of 15-06-26 Impact of 'Frontier AI systems' on cyber risk Scope This communication is primarily intended for entities subject to the European DORA Regulation. The FSMA also encourages entities that are not subject to DORA to apply these recommendations. Summary Recent developments in artificial intelligence are leading to a sharp increase in the cyber risk to which regulated firms are exposed. The capabilities of certain artificial intelligence models are now such that entities which previously considered themselves at low risk of cyberattacks, due in particular to their size or activities, must reassess the likelihood and impact of such an attack on their systems. The DORA Regulation sets out measures to reduce your cyber risk. 1 Frontier AI systems significantly increase the cyber risk for all entities Like other financial supervisory authorities1 , the FSMA draws the attention of the firms it supervises to the developments which occurred in recent months in the field of artificial intelligence. The emergence of so-called frontier AI Systems2 with advanced capabilities for detecting vulnerabilities in ICT systems certainly enables the development of more secure ICT applications and the testing of existing ones. However, it also has the corollary effect of multiplying the possibilities for malicious use. These models make it possible to not only very rapidly identify on an industrial scale a large number of vulnerabilities within IT systems, including in legacy and/or widely used applications, but also combine and exploit them automatically. Using these models does not require advanced expertise in the field. As things stand, those models are not currently yet widely available, nor in their entirety. However, it is expected that the possibilities in this area will only continue to expand. Models with equal or superior capabilities could become widely available in the near future. 1 See, for example, the statements from the French Autorité des marchés financiers (Résilience cyber : l'AMF appelle les acteurs financiers à renforcer leurs dispositifs face à l’évolution rapide des menaces liées à l’intelligence artificielle) and the Dutch Autoriteit voor Financiële Markten (Snellere AI-aanvallen vragen om sterkere weerbaarheid). 2 This term refers to the most advanced AI models at any given time. Communication
2/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA These developments have the following consequences:
3/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA
4/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA • Allocate sufficient resources to ICT incident management to ensure that incidents are handled quickly and correctly. 4) Require your ICT service providers to take measures at their level as well A large part of entities’ ICT infrastructure is in the hands of ICT service providers. Entities that outsource their IT infrastructure remain responsible for their cyber resilience and for managing risks within the supply chain. It is essential that service providers also take appropriate measures to guard against the risks described here. It is essential that service providers also take appropriate measures to protect themselves against the risks described here. By the end of 2025, the European Supervisory Authorities (EBA, ESMA and EIOPA, together ‘the ESAs’) had identified 19 critical ICT third-party providers based on the registers of information submitted by the entities subject to the DORA Regulation5 . In their supervision of these critical providers, the ESAs take into account the issues related to frontier AI systems. Some of these providers are, moreover, very large companies with full access to the models in question. Entities must be aware that a failure on the part of one of their ICT service providers can very quickly have a serious impact on them. It is therefore particularly important that they address this issue with their service providers, especially with those not considered critical by the ESAs. 3 Digital operational resilience must be a strategic priority for entities The FSMA calls on entities to critically assess the measures they have put in place to ensure that their ICT systems, protocols and tools meet the requirements of adequacy, reliability, capacity and resilience of the DORA Regulation. The FSMA expects all firms subject to the DORA Regulation to swiftly implement all the measures outlined here. Failure to do so will expose them to a much greater risk of falling victim to cyberattacks. In this regard, artificial intelligence presents not only risks but also opportunities. This technology can be used to identify, prioritise and fix vulnerabilities more quickly. The FSMA also emphasises that these measures are equally relevant for firms not subject to the DORA Regulation. As a reminder, the FSMA has made educational materials available to financial institutions explaining and illustrating the content of the DORA Regulation. 5 FSMA Communication 2025_02 on the DORA register of information.