The three European Supervisory Authorities issued a joint statement (JC 2026 25) asking banks, insurers and investment firms to strengthen governance, risk management and operational resilience against cyber threats from frontier AI models. National supervisors are asked to take a consistent, cross-sectoral, risk-based approach, linked to DORA oversight of critical ICT third-party providers.
Why it matters
It brings frontier AI cyber risk into the EU's DORA supervisory regime, adding to AI Act duties for EU financial firms.
Line of Thought
Follow this story
Pick any item to keep going. Your path builds up above as a line you can share.
Directly linked
Connections our researchers recorded
- DevelopmentBoE, FCA and HM Treasury tell firms frontier AI cyber skills exceed human experts15 May 2026 · Statement · GBFollows from: EU supervisors follow the UK's May statement with parallel expectations
What led here
Earlier developments on the same thread
- DevelopmentOpenAI says its models escaped an eval sandbox and breached Hugging Face21 Jul 2026 · Incident · US, INTL
- DevelopmentRBI drafts model risk rules covering AI/ML for all regulated lenders24 Jun 2026 · Rule change · IN
- DevelopmentUS export-control order forces global shutdown of Claude Fable 5 and Mythos 512 Jun 2026 · Enforcement or ruling · US
- DevelopmentAnthropic withholds Claude Mythos Preview, gives it to defenders via Project Glasswing7 Apr 2026 · Model release · US
What happened next
Later developments on the same thread
- DevelopmentOpenAI pauses frontier RL training over cyber risk after Hugging Face breach18 Aug 2026 · Statement · US
- DevelopmentSEBI chief says AI/ML rules will mandate kill switches and human oversight19 Aug 2026 · Statement · IN
- DevelopmentKansas City Fed's Schmid asks whether the AI ecosystem is becoming too big to fail25 Sep 2026 · Statement · US
- DevelopmentOpenAI ties large reasoning-distillation campaign to people linked to Moonshot AI30 Sep 2026 · Incident · US, CN
Same story elsewhere
What other countries and bodies did on this
- DevelopmentBessent and Powell summon bank CEOs over Anthropic Mythos cyber risk7 Apr 2026 · Statement · US, GB
- DevelopmentBank of England flags AI debt boom, circular financing and AI cyber threat7 Jul 2026 · Report · GB
- DevelopmentHalf of Fed survey contacts now name AI as a salient financial-stability risk8 May 2026 · Report · US
- DevelopmentOpenAI launches GPT-6 Astra, first model it rates 'Critical' for cyber capability3 Sep 2026 · Model release · US
Rules in play
Laws and guidance this touches
- RuleGPAI Code of PracticeEU · In force · 10 Jul 2025
- RuleGreat American AI ActUS · Proposed · 4 Jun 2026
- RuleEO 14409 (covered frontier models)US · In force · 2 Jun 2026
- RuleSB 813 / AB 1405US-CA · Enacted, not yet in force · 9 Sep 2026
- RuleIllinois AI Safety Measures ActUS-IL · Enacted, not yet in force · 6 Jul 2026
Threads by topic: Cybersecurity Frontier models Financial risk