2026-06-15

Added · Updated

Impact of Frontier AI Systems on Cyber Risk

The Belgian Financial Services and Markets Authority (FSMA) warns that frontier AI systems significantly lower the barrier for cyberattacks, compelling all regulated entities to reassess and increase their cyber risk exposure. The regulator mandates strict compliance with the EU DORA Regulation by implementing specific measures to identify ICT assets, protect systems through rapid patching, and detect incidents swiftly. Furthermore, firms are required to ensure their ICT service providers adopt equivalent resilience standards to mitigate supply chain vulnerabilities.

Financial Services and Markets Authority logo

Belgium

Financial Services and Markets Authority

Click to view thumbnail

12–14 Rue du Congrès 1000 Brussels / www.fsma.be Communication FSMA_2026_15 of 15-06-26 Impact of 'Frontier AI systems' on cyber risk Scope This communication is primarily intended for entities subject to the European DORA Regulation. The FSMA also encourages entities that are not subject to DORA to apply these recommendations. Summary Recent developments in artificial intelligence are leading to a sharp increase in the cyber risk to which regulated firms are exposed. The capabilities of certain artificial intelligence models are now such that entities which previously considered themselves at low risk of cyberattacks, due in particular to their size or activities, must reassess the likelihood and impact of such an attack on their systems. The DORA Regulation sets out measures to reduce your cyber risk. 1 Frontier AI systems significantly increase the cyber risk for all entities Like other financial supervisory authorities1 , the FSMA draws the attention of the firms it supervises to the developments which occurred in recent months in the field of artificial intelligence. The emergence of so-called frontier AI Systems2 with advanced capabilities for detecting vulnerabilities in ICT systems certainly enables the development of more secure ICT applications and the testing of existing ones. However, it also has the corollary effect of multiplying the possibilities for malicious use. These models make it possible to not only very rapidly identify on an industrial scale a large number of vulnerabilities within IT systems, including in legacy and/or widely used applications, but also combine and exploit them automatically. Using these models does not require advanced expertise in the field. As things stand, those models are not currently yet widely available, nor in their entirety. However, it is expected that the possibilities in this area will only continue to expand. Models with equal or superior capabilities could become widely available in the near future. 1 See, for example, the statements from the French Autorité des marchés financiers (Résilience cyber : l'AMF appelle les acteurs financiers à renforcer leurs dispositifs face à l’évolution rapide des menaces liées à l’intelligence artificielle) and the Dutch Autoriteit voor Financiële Markten (Snellere AI-aanvallen vragen om sterkere weerbaarheid). 2 This term refers to the most advanced AI models at any given time. Communication

2/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA These developments have the following consequences:

  • The threshold at which it becomes worthwhile to attack an IT system is significantly lowered. Entities which previously considered themselves to be at low risk of cyberattacks, for example due to their size or the nature of their activities, must now consider revising upwards the likelihood of such an attack and the impact it would have on their operations. Regulated firms cannot ignore these technological advances, at the risk of significantly underestimating their ICT risk.
  • Given the capabilities of these models, the patching cycle for ICT applications is significantly shortened. The potential economic damage caused by the malicious use of these models is very high. 2 DORA provides a useful framework to address these risks and entities must comply with it In Europe, the DORA Regulation3 has, since early 2025, harmonised the rules aimed at strengthening the digital operational resilience of financial institutions. The implementation of this Regulation’s requirements contributes to providing a very useful response to the risks associated with these models. Below is a brief overview of the measures that entities can take. The measures that entities should take are divided into four categories: 3 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011.
  1. Identify Know your ICT assets
  2. Protect Scan incoming data Screen your ICT assets for vulnerabilities Patch and update your ICT assets
  3. Detect and respond to breaches Detect intrusions React swiftly
  4. Challenge your ICT providers Steps 1, 2 and 3

3/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA

  1. Identify your ICT assets Identify, list and document in an inventory the various components of your ICT infrastructure: your computers, network devices, servers and their configuration, the software you use, your data, etc.
  2. Protect your ICT assets Put measures in place to protect your ICT assets: • Protect external touchpoints: points of contact with the internet (websites, emails, connected applications, etc.), hardware devices (computers, servers, USB sticks, etc.) and connections (Wi-Fi). • Implement and keep up to date logical access control measures (two-factor authentication), firewalls and antivirus software. • Raise awareness among your staff about the risks posed by incoming emails and about phishing. • Scan your ICT systems regularly to detect vulnerabilities. • Apply properly tested patches as soon as possible. • Set up a backup system. • Segment your network. • Consider migration options for legacy systems. • Carry out penetration tests on your systems by a specialised third party. • Ensure that your procedures are working properly and that your security systems are configured correctly.
  3. Detect incidents and respond quickly Put in place systems and procedures to quickly detect and resolve ICT incidents, and take steps to prevent the incident from happening again: • Clearly define responsibilities for ICT incident management, from prevention to resolution. • Monitor incoming and outgoing internet traffic and unusual activity to detect suspicious developments. • Establish an incident management procedure that includes at a minimum: o the assessment of the incident’s severity, o the identification of its causes, o the assessment of its consequences, o its reporting to the FSMA4 (if it is a major incident), and o its resolution (including system recovery). 4 See in this regard the Practical Guide of 12 January 2026: DORA – Reporting of major incidents and significant cyber threats.

4/4 / Communication FSMA_2026_15 of 15/06/2026 / FSMA • Allocate sufficient resources to ICT incident management to ensure that incidents are handled quickly and correctly. 4) Require your ICT service providers to take measures at their level as well A large part of entities’ ICT infrastructure is in the hands of ICT service providers. Entities that outsource their IT infrastructure remain responsible for their cyber resilience and for managing risks within the supply chain. It is essential that service providers also take appropriate measures to guard against the risks described here. It is essential that service providers also take appropriate measures to protect themselves against the risks described here. By the end of 2025, the European Supervisory Authorities (EBA, ESMA and EIOPA, together ‘the ESAs’) had identified 19 critical ICT third-party providers based on the registers of information submitted by the entities subject to the DORA Regulation5 . In their supervision of these critical providers, the ESAs take into account the issues related to frontier AI systems. Some of these providers are, moreover, very large companies with full access to the models in question. Entities must be aware that a failure on the part of one of their ICT service providers can very quickly have a serious impact on them. It is therefore particularly important that they address this issue with their service providers, especially with those not considered critical by the ESAs. 3 Digital operational resilience must be a strategic priority for entities The FSMA calls on entities to critically assess the measures they have put in place to ensure that their ICT systems, protocols and tools meet the requirements of adequacy, reliability, capacity and resilience of the DORA Regulation. The FSMA expects all firms subject to the DORA Regulation to swiftly implement all the measures outlined here. Failure to do so will expose them to a much greater risk of falling victim to cyberattacks. In this regard, artificial intelligence presents not only risks but also opportunities. This technology can be used to identify, prioritise and fix vulnerabilities more quickly. The FSMA also emphasises that these measures are equally relevant for firms not subject to the DORA Regulation. As a reminder, the FSMA has made educational materials available to financial institutions explaining and illustrating the content of the DORA Regulation. 5 FSMA Communication 2025_02 on the DORA register of information.