LatestBC Conservatives down 16 seats, nine MLAs quit under Findlay

Canadian business, markets & economy · Saturday, 5 September 2026

Economy

EU Supervisors Call for Unified, Risk‑Based AI Oversight and DORA Governance

On 31 July 2026 the European Banking Authority, EIOPA and ESMA issued a joint statement urging a cross‑sectoral, risk‑based supervisory regime and stronger governance, backed by DORA, to mitigate ICT risks from frontier AI models in the EU financial sector.

GPU server rack with DORA compliance label in a European bank data centre

The European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) jointly published a statement on 31 July 2026 calling for a cross‑sectoral, risk‑based supervisory regime and robust governance frameworks, backed by the Digital Operational Resilience Act (DORA), to mitigate ICT risks stemming from frontier AI models across the EU financial sector.

Joint statement and its core demands

The press release on the ESMA website states: “The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross‑sectoral, risk‑based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.” The statement further underlines that “financial entities should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models.” Finally, it adds that the ESAs “update on ongoing and planned DORA oversight activities for critical ICT third‑party providers (CTPPs) to address this risk.

These three excerpts capture the full thrust of the ESAs’ call: a unified supervisory methodology, mandatory governance standards, and an expansion of DORA’s reach to cover providers that supply critical ICT services to financial firms.

Regulatory context and DORA oversight

The statement situates the new supervisory expectations within the broader EU regulatory landscape. It references the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, recent guidance from the European Systemic Risk Board (ESRB) and the European Union Agency for Cybersecurity (ENISA), as well as the Single Supervisory Mechanism (SSM). By linking the call to these existing frameworks, the ESAs signal that the proposed regime is not a stand‑alone initiative but an integration of AI risk management into the existing supervisory architecture.

DORA, which entered into force in 2024, already imposes operational resilience requirements on financial entities and their ICT service providers. The ESAs’ statement clarifies that DORA oversight will be extended to cover “critical ICT third‑party providers” that are essential for the deployment of frontier AI models. This extension is intended to ensure that the same resilience standards applied to banks, insurers and securities firms also bind the technology vendors that underpin AI‑driven services.

Below is a concise summary of the three authorities and the specific focus each brings to the joint statement:

Key roles of the European Supervisory Authorities in the AI‑risk statement
AuthorityPrimary supervisory focus in the statement
EBABanking sector oversight, ensuring AI‑related ICT risk controls align with prudential standards.
EIOPAInsurance and pensions supervision, emphasizing governance and risk‑management frameworks for AI‑driven underwriting and claims processing.
ESMASecurities markets supervision, targeting AI use in trading algorithms and market infrastructure, and coordinating DORA oversight for ICT providers.
Source: ESMA press release, 31 July 2026.

Implications for financial entities and third‑party providers

Financial institutions operating in the EU will now be expected to embed AI‑specific risk assessments within their existing governance structures. The statement does not prescribe a single template, but it makes clear that “robust governance and risk‑management frameworks” must be demonstrable to supervisors. In practice, this could translate into:

  • Formal AI risk registers that map model capabilities to potential ICT vulnerabilities.
  • Board‑level oversight committees tasked with reviewing AI deployment plans.
  • Periodic stress‑testing of AI‑enabled systems against cyber‑attack scenarios, aligned with DORA’s testing requirements.

For critical ICT third‑party providers (CTPPs), the expanded DORA oversight means that they will be subject to supervisory reviews not only of their own operational resilience but also of the AI models they host or supply. Providers will need to furnish evidence that their AI pipelines incorporate security‑by‑design principles, that data provenance is auditable, and that model updates are governed by change‑management controls comparable to those required of the financial entities they serve.

Supervisors are encouraged to use the statement as a basis for “supervisory dialogue,” suggesting that regulators will engage with firms early to clarify expectations and to co‑design compliance pathways. This collaborative tone aims to avoid a heavy‑handed enforcement approach and to give firms time to adapt their AI governance structures before formal supervisory assessments commence.

What remains unclear

While the statement is comprehensive in its high‑level demands, several implementation details are still pending:

  • Timelines for compliance. The ESAs have not set a definitive date by which financial entities must have the new governance frameworks fully operational.
  • Scope of “critical” ICT providers. The criteria that will determine which third‑party vendors fall under the expanded DORA regime have not been published.
  • Enforcement mechanisms. It is not yet clear whether non‑compliance will trigger supervisory penalties, remedial action plans, or a phased approach.
  • Interaction with national regulators. The statement references the Single Supervisory Mechanism, but the exact coordination model between the ESAs and national supervisory authorities is not detailed.

These gaps mean that firms will need to monitor forthcoming guidance from the ESAs and national regulators closely. In the meantime, many large banks, insurers and asset managers are already conducting internal reviews to gauge how their existing AI governance aligns with the ESAs’ expectations.

Analysis: why the joint call matters now

The timing of the statement – 31 July 2026 – aligns with the EU’s Action Plan on Cybersecurity and Artificial Intelligence, which was released earlier in the year, and with recent guidance from the ESRB and ENISA on AI‑related systemic risk. By issuing a coordinated message, the three ESAs are signalling that AI risk is no longer a niche concern but a cross‑sectoral systemic issue that requires harmonised supervision.

From a market perspective, the statement could have several effects:

  • Increased demand for AI‑risk consultancy services as firms scramble to build compliant frameworks.
  • Potential re‑pricing of contracts with ICT vendors, as providers factor the cost of additional DORA‑related audits into their pricing.
  • Greater transparency for investors, who will now have a clearer regulatory backdrop against which to assess AI‑related exposures in financial firms.

Overall, the ESAs’ unified stance is likely to accelerate the maturation of AI governance across the EU financial sector, reducing the probability of cyber‑induced disruptions linked to advanced AI models.

What to watch next

Stakeholders should keep an eye on three forthcoming developments:

  1. Detailed technical standards from the European Banking Authority, EIOPA and ESMA that translate the high‑level principles into actionable requirements.
  2. Guidance from the European Commission on the definition of “critical ICT third‑party providers” for the purpose of DORA oversight.
  3. National supervisory road‑maps that outline how each Member State will integrate the ESAs’ expectations into its own supervisory processes.

Until those details emerge, the safest approach for firms is to begin aligning their AI governance with the three pillars highlighted in the statement: cross‑sectoral risk‑based supervision, robust governance and risk‑management, and DORA‑aligned oversight of ICT partners.

About the author

Emma Sinclair

Reporting for CityAM Canada on economy and the wider Canadian economy.

All work by Emma Sinclair ›