ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB Banking Supervision published letter SSM-2026-0301, addressed to the CEOs of significant institutions. The ECB called on those institutions to develop a comprehensive action plan and stated that it should be submitted to the respective Joint Supervisory Team by 31 October 2026.

None of the three documents creates or amends a DORA reporting template. The ECB letter requests a separate supervisory action plan from significant institutions and reschedules the IT Risk Questionnaire collection. The ESRB warning and Joint-ESA statement may reasonably lead to greater supervisory attention to existing DORA controls and evidence, but they do not expressly amend the incident-reporting rules, the register of information or the Article 28 and Article 29 assessment requirements.

The reach of the policy message goes beyond the euro area’s significant banks, but the instruments must be separated. The ESRB adopted a warning of a general nature and asked ESRB members and relevant authorities to reflect the risk within their respective mandates. The ESAs separately urged financial entities to adapt their cybersecurity capabilities and invited competent authorities to reflect the developments in supervisory activities. Neither document imposes the ECB’s 31 October 2026 submission date on the wider DORA population.

Related reading: the ECB’s AI cybersecurity letter and DORA ICT risk reporting.

What the ESRB actually warned, and why a warning is a supervisory event

The ESRB adopted the warning on 25 June 2026 and published it, with the ESAs’ support statement and the ECB letter, on 7 July. The board describes frontier AI models as capable of discovering vulnerabilities, generating working exploits, and autonomously executing full-scale cyber-attacks at a speed, scale and level of accuracy far exceeding previous AI models. According to the ESRB, its General Board had raised its assessment of systemic cyber risk to severe in June 2026, up from elevated in March.

An ESRB warning is not a rule, and reading it as one is the first mistake. The board has no supervisory or enforcement power. It flags a systemic vulnerability and calls on named actors, in this case AI providers, software providers, security firms, open-source maintainers, financial institutions, and national and Union authorities, to respond. The teeth come from the supervisors who choose to act on it. Here two of them acted immediately: the ESAs as a college, and the ECB as the euro-area prudential supervisor.

The ESAs (the EBA, ESMA and EIOPA) welcomed and supported the warning through their Joint Committee. Their statement makes three moves worth marking. It states that DORA and the AI Act provide a solid foundation for managing cyber and AI-related risks. The statement does not conclude that the framework contains no legal, supervisory or implementation gaps. It points to the ESAs’ first annual report on major ICT-related incidents, published in June 2026, in which they had already urged firms to strengthen cybersecurity. And it records that, in their role as Overseers of critical ICT third-party providers, the ESAs are engaging those providers directly on how they are adapting.

The dated supervisory request: SSM significant institutions and 31 October 2026

The 31 October 2026 date is a supervisory submission request addressed to significant institutions under ECB Banking Supervision. It is not a DORA regulatory return or a generally applicable filing obligation. Less significant institutions, insurers, funds, payment institutions and crypto-asset service providers are not addressees of the ECB letter. A national competent authority could develop comparable expectations, but the cited documents do not establish an equivalent deadline for those entities.

ECB letter SSM-2026-0301, dated 7 July 2026, calls on significant institutions to assess the impact of the evolving threat landscape without delay and develop a comprehensive action plan. The requested plan should outline concrete control measures, allocate necessary resources, assign clear roles and responsibilities, and define implementation timelines. It should build on the bank’s existing cyber-risk strategy and address immediate priorities and longer-term strategic aspects.

Three short-term focus areas are named in the letter. The first is to accelerate vulnerability and patch management at scale. The second is to enhance monitoring, detection and AI-enabled defensive capabilities. The third is to verify that third-party risk management is fit for purpose given the role of ICT service providers in critical supply chains. The plan goes to the respective Joint Supervisory Team by 31 October 2026, after which the JST engages the bank on it and monitors progress, and the ECB runs a horizontal analysis across all submitted plans.

The ECB also puts the responsibility where DORA already puts it. The letter states that responding to the evolving cyber-risk environment lies primarily with the bank’s management body, and that strategic ICT decisions, including ICT investment and the ICT risk tolerance framework, may need to be revisited. This is a board-ownership signal, and it is the part most likely to be quoted back at institutions in the next supervisory dialogue.

Why this rides on DORA and the AI Act, and how to keep them apart

The ECB frames the action-plan request as being in line with DORA and states that DORA’s requirements remain highly relevant and valid in the changing threat landscape. The action plan itself is an ECB supervisory request, not a new reporting obligation created by DORA. That matters for how firms structure their response, because DORA and the AI Act pull on different levers and confusing them produces wasted work.

DORA governs the operational-resilience response to the cyber threat, including ICT risk management, incident reporting, resilience testing and ICT third-party risk. The AI Act’s obligations apply on a staged timetable and depend on the firm’s role as provider, deployer or other operator and on the category and intended purpose of the AI system or model. Its obligations are not confined to Annex III high-risk systems. A bank that buys and uses an AI-enabled security tool may be a deployer under the AI Act and should determine which AI Act provisions apply to that use case and from what date. A threat actor’s use of AI does not by itself make the bank an AI Act operator. The ECB action plan remains a DORA-aligned supervisory request, but any AI system that the bank develops or deploys should be classified under the AI Act and assessed against the provisions applicable at the relevant date.

The cleaner way to read the ECB letter is as a targeted DORA-aligned supervisory push, framed around one threat vector, with the AI Act sitting alongside where a firm develops, provides or deploys an AI system or general-purpose AI model in a role regulated by that Act; the applicable obligations depend on the firm’s role, the system or model, its intended purpose and the relevant application date. The ESAs’ statement supports that reading: it grounds the response in DORA’s harmonised ICT framework and treats the AI Act as complementary rather than as the operative instrument here.

How the ESRB warning changes DORA cyber risk reporting in practice

No new return is created by the warning, the ESAs statement, or the ECB letter. The ESAs have invited competent authorities to reflect the developments in their supervisory activities, so greater scrutiny of existing DORA controls and evidence is a reasonable expectation rather than a confirmed change imposed by these documents. The documents do not establish that incident-reporting volumes will increase. Three existing reporting and evidence areas are relevant.

The first is DORA ICT incident reporting. Under Article 18 of DORA, financial entities classify ICT-related incidents against criteria whose materiality thresholds are set by Commission Delegated Regulation (EU) 2024/1772. Under Article 19, they report a major incident through an initial notification, an intermediate report and a final report, with the content and time limits fixed by Commission Delegated Regulation (EU) 2025/301 and the templates by Commission Implementing Regulation (EU) 2025/302.

Under Article 5 of Commission Delegated Regulation (EU) 2025/301, the initial notification is due as early as possible and, in any event, within four hours from classification as major and no later than 24 hours from awareness. If classification occurs more than 24 hours after awareness, it is due within four hours from classification. The intermediate report is due no later than 72 hours from submission of the initial notification. The final report is due no later than one month after submission of the intermediate report or, where applicable, the latest updated intermediate report. Article 5 also contains weekend and bank-holiday provisions; for credit institutions these do not extend the initial or intermediate deadline.

An AI-enabled intrusion is classified against the same criteria as any other, so the framework already captures it. The operational pressure is on detection, triage and timely classification. A higher volume or faster pace of attacks could increase the number of incidents requiring assessment, but an incident becomes reportable only if it meets the existing DORA major-incident criteria and materiality thresholds. Our DORA ICT incident reporting guide walks through where the four-hour clock actually starts, which is the point teams misjudge most often.

The ESAs’ first Article 22(2) report provides an anonymised and aggregated overview of major incidents occurring in 2025. It identifies divergent reporting practices and early-stage data-quality limitations, but it does not establish a public or formal firm-level benchmark against which an individual institution’s 2026 incident volume will be assessed. Competent authorities and the ESAs receive the underlying incident reports under DORA; any firm-specific benchmarking or supervisory use would be separate from the published annual report.

The third surface is the supervisory questionnaire calendar, and it contains the operational detail most likely to slip past a planning team. The ECB letter extends the deadline for the annual collection of its IT Risk Questionnaire from September 2026 to February 2027, to let significant institutions focus resources on the action plan first. A firm that has hard-coded a September submission window into its internal calendar needs to re-plan, and a firm that reads the extra months as free capacity has misread the intent, because they are time reallocated to the action plan.

ICT concentration risk: the register of information becomes the evidence base

The topic that gives supervisors the clearest line of sight into systemic exposure is ICT third-party concentration risk, and here it helps to be precise about what “concentration-risk reporting” means under DORA. There is no standalone concentration-risk return. Instead, DORA builds the picture from two connected pieces.

Article 28(4) of DORA requires a financial entity, before entering a contractual arrangement, to identify and assess all relevant risks, including whether the arrangement may reinforce ICT concentration risk. Article 29 specifies concentration-risk considerations including substitutability, multiple arrangements with the same or connected providers, subcontracting and potentially long or complex subcontracting chains. Separately, Article 28(3) requires the register of information to be maintained and updated at entity, sub-consolidated and consolidated levels, as applicable. The register records contractual arrangements and dependencies; it does not replace the documented Article 28 and Article 29 risk assessment. Critical ICT third-party providers are designated by the ESAs through the Joint Committee under the Article 31 process after assessment against the statutory criteria. The DORA register of information is where that dependency map is built and kept current.

The ECB’s third short-term priority is to verify that third-party risk management remains fit for purpose in light of ICT providers’ role in critical supply chains. A JST reviewing the action plan is likely to examine the register of information and the Article 29 concentration-risk assessments as supporting evidence; the ECB letter creates no new register requirement or reporting instruction and does not specify which records JSTs will test. Firms should therefore keep the register and the separate supporting risk assessments complete, current and traceable under the existing DORA requirements.

AI governance: what boards own, and what the plan has to show

The governance ask in the ECB letter is deliberate. It places primary responsibility for the response with the management body, and it locates the action plan in the ICT risk tolerance framework at board level, above any security team’s backlog. For firms outside the SSM, the same logic reads as a supervisory template even without a filing date, because DORA already assigns ICT risk governance to the management body across all financial entities.

A credible plan, on the letter’s own terms, connects the short-term measures to structural ones: reinforcing defence-in-depth and cyber hygiene, replacing legacy, unsupported or end-of-life technology, and improving response and recovery mechanisms including crisis management and information sharing. The annex to the letter goes further on attack-surface protection, singling out internet-facing and externally exposed assets, third-party software and open-source components, and perimeter technologies as the first priorities for remediation. A plan that lists tooling purchases without a governance trail, an owner, and a timeline is the version a JST is most likely to send back. For firms mapping the AI dimension of this alongside their model obligations, EU AI Act compliance for financial institutions sets out where the two regimes meet.

One caution belongs here. The ECB letter encourages AI-based defensive tooling, but it conditions that encouragement: any such deployment should follow a proper assessment of its benefits and risks and stay under human oversight and adequate risk management. A plan that answers an AI threat by bolting on unassessed AI tools inverts the point.

Who has to do what, by jurisdiction

The obligations fan out unevenly, so it is worth separating them cleanly. SSM significant institutions have a dated deliverable: the AI cyber action plan to their JST by 31 October 2026, and a rescheduled IT Risk Questionnaire in February 2027. Less significant institutions and other DORA financial entities across the Union do not inherit that date, but they remain subject to the same applicable DORA obligations. The ESAs have invited competent authorities to reflect the developments in their supervisory activities, but the cited documents do not establish a uniform national follow-up timetable or requirement. Critical ICT third-party providers face direct engagement from the ESAs as Overseers, separate from any single firm’s action plan.

For any entity, the underlying DORA duties are unchanged and immediate: classify and report major incidents on the existing timelines, keep the register of information complete and current, and be able to evidence the ICT concentration-risk assessments behind critical contracts. The warning raises the cost of doing those three things badly.

Frequently Asked Questions

Does the ESRB warning create a new reporting obligation or template?

No. The ESRB has no rule-making or supervisory power; it issues warnings and recommendations. The warning, the ESAs’ support statement and the ECB letter all work through existing DORA obligations. The only new deliverable is the ECB’s action plan for SSM significant institutions, and that is a supervisory request rather than a regulatory return with a template.

Which firms are asked to submit the action plan by 31 October 2026?

Only the significant institutions supervised directly by the ECB under the Single Supervisory Mechanism. The plan goes to the firm’s Joint Supervisory Team. Less significant institutions, insurers, funds, payment and e-money institutions and crypto-asset service providers are not addressees of the ECB letter, though their own competent authorities may set comparable expectations.

Do the DORA incident-reporting deadlines change because of AI threats?

No. The existing timelines continue to apply. The initial notification is due as early as possible and within four hours from classification as major, subject to the 24-hour outer limit from awareness and the late-classification rule in Article 5(2) of Commission Delegated Regulation (EU) 2025/301. The intermediate report is due within 72 hours from submission of the initial notification, and the final report within one month after the intermediate report or latest updated intermediate report. An AI-enabled incident is assessed against the existing Article 18 criteria and the thresholds in Commission Delegated Regulation (EU) 2024/1772.

What is the link between the ECB letter and the register of information?

The letter’s third priority, third-party risk management, maps onto the same ICT dependencies that DORA’s register of information already records under Article 28. Supervisors can test whether the register is complete and whether concentration assessments under Article 29 reflect the real subcontracting chains. The register is the evidence base a JST is likely to use when reviewing the third-party section of an action plan.

Is this an AI Act compliance exercise?

Not primarily. The ECB action plan is a DORA-aligned supervisory request addressing operational resilience. The AI Act does not create a generic obligation labelled a separate assessment; the firm should determine its role, the system’s classification and intended purpose, and which provisions apply from the relevant application date. Buying and deploying an AI-enabled security tool can therefore engage both DORA and the AI Act, depending on the tool’s classification, intended purpose and the firm’s role. A threat actor’s use of AI does not by itself place the targeted firm within the AI Act for that attack.

What happened to the September 2026 IT Risk Questionnaire?

The ECB extended the annual collection of the IT Risk Questionnaire from September 2026 to February 2027 so that significant institutions can prioritise the action plan. Teams that scheduled a September submission need to re-plan, and the additional months are meant to be spent on action-plan work.

What should a firm outside the SSM do now?

Treat the ECB letter as a supervisory reference point rather than a binding instruction outside its addressees. Confirm that incident detection and classification can cope with higher volumes, that the register of information is current, and that ICT concentration-risk assessments are documented for critical contracts. The ESAs have invited competent authorities to reflect the developments in their supervisory activities, but the cited documents do not establish when or how each authority will do so.

Related Articles

Key Takeaways

  • The ESRB published a formal warning on 7 July 2026 (adopted 25 June) that frontier AI models are a systemic cyber risk to the EU financial system; the ESAs backed it the same day.
  • The ECB letter SSM-2026-0301 turns the warning into a dated supervisory task for SSM significant institutions: an AI cyber action plan to the Joint Supervisory Team by 31 October 2026.
  • The requested plan should state concrete control measures, resources, roles and timelines and build on the existing cyber-risk strategy; the ECB letter places primary responsibility for responding to the evolving cyber-risk environment with the management body.
  • Three ECB short-term priorities: accelerate vulnerability and patch management, strengthen monitoring and AI-enabled detection, and verify third-party risk management against critical supply chains.
  • No new template appears; DORA incident-reporting timelines under Article 19 and the classification thresholds in Regulation (EU) 2024/1772 are unchanged.
  • DORA separately requires pre-contract risk and concentration assessment under Articles 28(4) and 29 and maintenance of the register of information under Article 28(3). There is no standalone concentration-risk return, and the ECB letter does not prescribe a new return or state which specific records JSTs will test.
  • The ECB moved its IT Risk Questionnaire collection from September 2026 to February 2027 so firms can prioritise the action plan.
  • Non-SSM entities inherit no filing date but should expect their national competent authority to reflect the warning in supervision.

Sources and References

  • European Systemic Risk Board, press release, “Frontier AI models could strain cyber resilience in the financial system, ESRB warns” (7 July 2026): esrb.europa.eu
  • European Systemic Risk Board, “Warning of the European Systemic Risk Board of 25 June 2026 on systemic cyber risks stemming from frontier artificial intelligence models” (PDF): esrb.europa.eu
  • European Banking Authority (for the ESAs), “The ESAs support ESRB warning on systemic cyber risks from frontier AI models” (7 July 2026): eba.europa.eu
  • ESMA, “The ESAs support ESRB warning on systemic cyber risks from frontier AI models” (7 July 2026): esma.europa.eu
  • ECB Banking Supervision, letter SSM-2026-0301, Claudia Buch, “Addressing AI-enabled cybersecurity threats” (7 July 2026): bankingsupervision.europa.eu
  • Regulation (EU) 2022/2554 (DORA): eur-lex.europa.eu
  • Commission Delegated Regulation (EU) 2024/1772 (RTS on classification of ICT-related incidents and materiality thresholds): eur-lex.europa.eu
  • Commission Delegated Regulation (EU) 2025/301 (RTS on content and time limits for incident reports): data.europa.eu
  • Commission Implementing Regulation (EU) 2025/302 (ITS on forms, templates and procedures for incident reporting): data.europa.eu
  • ESAs, “2025 report on major ICT-related incidents” (June 2026, Article 22(2) DORA): eba.europa.eu
  • Regulation (EU) 2024/1689 (Artificial Intelligence Act): eur-lex.europa.eu

Where the 31 October deadline leaves your DORA evidence base

The warning stress-tests the parts of DORA a firm already lives with. For SSM banks the near-term work is the action plan, but the durable work is the evidence underneath it: incident classification that keeps pace, a register of information that matches reality, and concentration-risk assessments a supervisor can follow. For everyone else, the deadline may indicate themes that national competent authorities could examine, but the cited documents do not establish a uniform follow-up process or timetable. Firms outside the SSM have no ECB action-plan deadline, but their existing DORA duties already apply. Any identified weakness should be remediated now: the ESAs have urged financial entities to adapt their cybersecurity capabilities proactively rather than wait for a national competent authority to issue a firm-specific request.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts