Technology, Media and Telecommunications (TMT)

ESRB Warning ESRB/2026/3: Systemic Cyber Risks from Frontier AI Models — What Financial Institutions Need to Know

Published on 22nd July 2026

The ESRB’s Warning ESRB/2026/3 elevates frontier AI models (FAIMs) to a source of severe systemic cyber risk for the EU financial system. FAIMs can autonomously discover vulnerabilities and weaponise exploits within minutes, undermining traditional patching assumptions and exposing ICT infrastructure, payment systems and financial market infrastructures to large‑scale attacks.

The Warning, anchored in DORA, the AI Act and the Cyber Resilience Act, drives intensified supervisory expectations rather than new legal duties. Significant institutions under ECB supervision must submit comprehensive FAIM-focused cybersecurity action plans by 31 October 2026, with broader expectations on board‑level governance and third‑party/supply chain risk management. UK regulators recognise similar risks but signal a more collaborative, less prescriptive supervisory approach.

Circuitboard swathed in blue light

Background

Frontier AI Models (FAIMs) — advanced AI systems capable of autonomously identifying software vulnerabilities and crafting weaponised exploits — have materially altered the cyber-threat landscape, outperforming earlier AI models in cost, speed and accuracy and now rivalling leading human security experts. The European Systemic Risk Board (ESRB), responsible for macroprudential oversight of the EU financial system, considers these developments to be a source of systemic risk with the potential to generate significant adverse effects on cybersecurity across interconnected financial institutions.

Reflecting the pace of change, the ESRB formally upgraded its systemic cyber risk classification from "elevated" to "severe" in June 2026, prompting the adoption of Warning ESRB/2026/3 on 25 June 2026, published on 7 July 2026. The Warning is grounded in the EU's existing regulatory architecture — principally the Digital Operational Resilience Act (DORA), the AI Act, and the Cyber Resilience Act — which together form the legislative backbone against which supervisory expectations in this area are being calibrated.

The Warning forms part of a coordinated EU institutional response, issued in parallel with the European Commission's own action plan on advanced AI model cybersecurity risks and accompanied by a joint press release from the three European Supervisory Authorities (EBA, EIOPA, and ESMA) welcoming and supporting the ESRB's findings. 

What is subject to the Warning

The Warning addresses the systemic cyber risks to the EU financial system arising from the development and deployment of Frontier AI Models — advanced AI systems capable of discovering vulnerabilities, generating working exploits, and autonomously executing large-scale cyberattacks at a speed, scale and level of accuracy far exceeding previous AI models. 

The following matters fall within its scope:

  • FAIM-enabled offensive cyber operations — the Warning covers threats from advanced general-purpose AI models capable of materially affecting offensive or defensive cyber operations, including automated vulnerability discovery and exploit weaponisation. 
  • ICT infrastructure of financial institutions — systems underpinning the ICT environments on which financial infrastructure relies, including major operating systems and software used across financial institutions' environments, are primary targets of FAIM-driven attacks. 
  • Systemically important payment and settlement systems and financial market infrastructures — these are specifically identified as entities that must review and update cybersecurity frameworks to address vulnerabilities emerging from FAIM use and development. 
  • Third-party technology dependencies — risks arising from critical third-party providers, shared technological ecosystems, and widely used open-source components fall within scope, given the potential for rapid incident propagation. 
  • Board governance and risk management frameworks — the adequacy of board-level governance, accountability structures, and internal investment in cybersecurity in relation to FAIM-driven risk is within scope of the Warning's expectations. 
  • Supervisory and oversight activities of competent authorities — the calibration of supervisory expectations, stress testing, and preparedness measures in the context of FAIM capabilities are within scope of the calls to action addressed to relevant authorities. 
Key exclusions and exemptions

The Warning is a general systemic risk warning and contains no formal sector-specific carve-outs or exclusions. It operates without prejudice to the monetary policy mandates of central banks in the Union.  As a non-binding instrument, it does not independently impose direct legal obligations on financial institutions beyond the existing DORA, AI Act, and Cyber Resilience Act frameworks within which it operates.

Who is subject to the Warning

The Warning is formally addressed to all ESRB members — including national central banks, national competent authorities, the European Supervisory Authorities, and the ECB — who are called upon to reflect its findings in their macroprudential and microprudential policy actions and supervisory work. 

The following categories are directly or indirectly affected:

  • Significant institutions under ECB supervision — the ECB has written to the CEOs of significant institutions setting out supervisory expectations and requiring submission of a comprehensive action plan by 31 October 2026; these institutions face the most immediate and concrete compliance pressure. 
  • Financial market infrastructures and payment systems — systemically important payment and settlement systems are explicitly highlighted as entities required to review and update their cybersecurity frameworks against FAIM-driven vulnerabilities. 
  • All EU financial entities under DORA — the ESAs urge all financial entities to make appropriate arrangements to adapt cybersecurity capabilities, and are working with national competent authorities to translate the Warning into consistent supervisory expectations under the DORA framework. 
  • Critical ICT third-party providers — the ESAs, in their capacity as Overseers of Critical ICT Third-Party Providers, are engaging with these providers on the measures they are taking to adapt to the situation and ensure continuity of services. 
  • National competent and macroprudential authorities — relevant authorities should consider cooperation arrangements and sectoral coordination alongside existing testing frameworks to reduce asymmetries introduced by FAIMs. 
Indirectly affected parties

AI providers, software providers, security firms, and open-source maintainers are identified as essential participants in an effective coordinated response.  While the Warning imposes no direct legal obligations on them, increased supervisory scrutiny of financial institutions' third-party risk management under DORA is likely to generate contractual and operational pressure on these providers.

Territorial scope

The Warning applies across the EU and EEA. It specifically identifies the geographical concentration of leading AI providers outside the Union as a source of strategic dependency and geopolitical risk, calling for measures to facilitate proportionate access to newly developed FAIMs for the Union and its Member States.  Financial institutions established outside the EU but operating as third-party ICT providers to EU financial entities may also be affected through DORA's existing third-country provisions.

Practical impact

  • [Priority] Significant institutions must submit a comprehensive cybersecurity action plan to their Joint Supervisory Team by 31 October 2026. The plan must assess the impact of the evolving AI-driven threat landscape, strengthen relevant controls, allocate resources, assign clear roles and responsibilities, and define implementation timelines, building on the institution's existing cyber-risk strategy.  The ECB will conduct a horizontal analysis of submitted plans and share conclusions with institutions — failure to engage substantively risks adverse supervisory findings under DORA. 
  • [Priority] Boards must take active ownership of FAIM-driven cyber risk — this is no longer solely an IT or operational matter. The Warning explicitly requires that financial institutions' boards are fully committed to mitigating FAIM-driven cyber risks and that clear governance and accountability frameworks are in place.  Institutions should expect supervisors to assess board-level engagement as part of DORA supervisory reviews.
  • Cybersecurity frameworks and patching processes must be reassessed against a materially faster threat timeline. The time required to weaponise an exploit has collapsed from days or weeks to minutes or hours, fundamentally undermining the assumption that reactive patching provides adequate defence.  Institutions may need to reconsider the balance between patch-testing requirements and speed of deployment to avoid simultaneous exposure to multiple critical vulnerabilities. 
  • Third-party and supply chain risk management must be upgraded to reflect FAIM-specific concentration risks. The Warning identifies concentration in a limited number of AI providers, cloud providers, and open-source components as a distinct systemic risk vector.  Institutions should review relevant contractual arrangements and ensure DORA third-party risk management frameworks address FAIM-specific scenarios, particularly in light of ESA engagement with Critical ICT Third-Party Providers.
  • The ECB IT Risk Questionnaire deadline has been extended to February 2027 — but this reflects the scale of the task, not a relaxation of scrutiny. The ECB has extended the annual IT Risk Questionnaire deadline from September 2026 to February 2027  to allow institutions to focus on action plan development. The overarching message from both the ECB and the ESRB is one of urgency: institutions are expected to rapidly beef up their IT security capabilities. 
  • UK-regulated entities should monitor closely: the Bank of England has identified the same risks but signalled a different supervisory approach. The Bank of England warned concurrently of elevated financial stability risks from frontier AI but indicated it is working closely with banks rather than "issuing edicts", suggesting a less prescriptive but equally attentive UK supervisory posture.  Firms operating in both the EU and UK should ensure their action plans are coherent across both jurisdictions and anticipate UK supervisory engagement in due course.

How we can help

Osborne Clarke's financial regulation and technology teams have extensive experience advising financial institutions, financial market infrastructures, and technology providers on DORA compliance, AI governance, and operational resilience — the three pillars at the heart of the ESRB's Warning.

We can assist your organisation in conducting a targeted regulatory gap analysis to assess how your existing ICT risk management, third-party oversight, and cybersecurity governance frameworks measure up against the heightened supervisory expectations flowing from this Warning, including supporting the development and review of the comprehensive action plans now required by the ECB.

Where existing contracts with AI providers, cloud service providers, and critical ICT third parties require updating to reflect the risks and responsibilities identified, our team can advise on contractual amendments and on the integration of FAIM-specific risk scenarios into your DORA documentation.

We also offer tailored board and senior management briefings to ensure governance and accountability structures are fit for purpose, as well as ongoing regulatory monitoring support as the ESAs translate the Warning into binding supervisory expectations. Please get in touch with Szymon Ciach to discuss how we can support your organisation.
 

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Interested in hearing more from Osborne Clarke?