EU supervisors urge unified AI‑risk governance and DORA oversight for finance sector
On 31 July 2026 the European Banking Authority, EIOPA and ESMA issued a joint statement calling for a cross‑sectoral, risk‑based supervisory approach to frontier AI models and for stronger DORA oversight of critical ICT third‑party providers.

On 31 July 2026 the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) released a joint statement that calls for a cross‑sectoral, risk‑based and consistent supervisory approach to mitigate ICT risks arising from frontier artificial‑intelligence (AI) models. The statement also urges financial entities to adopt robust governance arrangements and to apply the Digital Operational Resilience Act (DORA) to critical ICT third‑party providers (CTPPs).<\/p>
Joint statement and regulatory context
The press release issued by ESMA confirms that the three core elements of the claim – cross‑sectoral supervision, risk‑based oversight and DORA‑aligned governance – are central to the ESAs’ response to emerging AI‑related cyber‑risk vectors. The document references the EU Commission’s Action Plan on Cybersecurity and AI, as well as guidance from the European Systemic Risk Board (ESRB), the European Union Agency for Cybersecurity (ENISA) and the Single Supervisory Mechanism. By anchoring the new supervisory expectations in existing frameworks, the ESAs aim to avoid regulatory fragmentation while ensuring that financial institutions adopt consistent safeguards.<\/p>
Banking sector: contract negotiations and operational resilience
For banks, the call for enhanced DORA oversight translates into a likely shift in how they manage contracts with cloud‑service vendors and other ICT providers that host or process frontier AI models. Under DORA, banks must ensure that critical third‑party providers meet stringent resilience standards, including incident‑reporting obligations and regular testing of security controls. The ESAs’ statement signals that supervisors will scrutinise whether banks have embedded AI‑risk assessments into their vendor‑selection criteria and whether governance bodies – such as risk committees – have clear accountability for AI‑related cyber exposures.<\/p>
In practice, banks may need to renegotiate service‑level agreements (SLAs) to include clauses on AI model transparency, audit rights and mandatory breach notifications. The supervisory emphasis on a risk‑based approach suggests that institutions with higher exposure to AI‑driven trading algorithms, credit‑scoring models or fraud‑detection tools will face the most intensive oversight. While the statement does not prescribe specific quantitative thresholds, it makes clear that the supervisory lens will be calibrated to the materiality of AI‑related ICT risk within each bank’s operational profile.<\/p>
Insurance and pensions: safeguarding policy‑holder data
Insurers and occupational pension funds are similarly positioned to feel the impact of the ESAs’ guidance. The statement highlights the need for robust governance of AI models that process large volumes of personal and health data. Under DORA, insurers must demonstrate that their CTPPs can withstand cyber‑attacks that could compromise policy‑holder information or disrupt claims‑processing systems powered by AI.<\/p>
Supervisors are expected to examine whether insurers have integrated AI‑risk indicators into their enterprise‑wide risk‑management frameworks and whether they conduct regular stress‑testing of AI‑enabled underwriting platforms. The cross‑sectoral nature of the ESAs’ call means that insurance regulators will coordinate with banking and securities supervisors to ensure that comparable standards are applied across the financial ecosystem. This coordination could lead to joint supervisory inspections focused on AI governance, data‑privacy safeguards and the resilience of outsourced ICT services.<\/p>
Asset managers and the broader market: downstream effects on ICT providers
Asset managers, who increasingly rely on frontier AI for portfolio construction, risk analytics and client reporting, will also need to align their ICT procurement practices with the DORA expectations outlined in the joint statement. The ESAs note that oversight of critical ICT third‑party providers is a key lever for mitigating systemic risk. Consequently, asset managers may face heightened due‑diligence requirements when onboarding cloud platforms that host AI‑driven analytics tools.<\/p>
From the provider side, ICT firms that supply AI infrastructure to the financial sector can anticipate more rigorous supervisory scrutiny. The statement’s reference to “robust governance” implies that providers will be required to furnish detailed documentation on model provenance, data‑training pipelines and security controls. Failure to meet DORA‑aligned standards could result in supervisory actions, including restrictions on market access for non‑compliant providers.<\/p>
What remains uncertain
The joint statement does not specify a timeline for the rollout of the enhanced supervisory regime, nor does it quantify the expected compliance costs for financial institutions or ICT providers. The ESAs also stopped short of detailing how they will monitor the effectiveness of the new governance framework once implemented. As a result, market participants will be watching for follow‑up guidance from the European Commission and from national supervisory authorities to clarify reporting obligations and enforcement mechanisms.<\/p>
Analysts anticipate that the ESAs’ coordinated approach will drive a wave of contractual renegotiations and internal policy revisions across banks, insurers and asset managers throughout the second half of 2026. The emphasis on a risk‑based, cross‑sectoral methodology suggests that institutions with the most advanced AI deployments will be the first to feel supervisory pressure, while smaller firms may receive proportionate oversight.<\/p>
In the absence of detailed quantitative targets, the primary takeaway for financial market participants is clear: the supervisory landscape for AI‑related ICT risk is moving from fragmented, sector‑specific guidance to a unified, DORA‑anchored framework. Firms that proactively embed AI‑risk governance into their operational resilience programs are likely to navigate the transition more smoothly than those that treat AI oversight as an after‑thought.<\/p>
