Out-Law / Your Daily Need-To-Know

OUT-LAW NEWS 3 min. read

Frontier AI: financial regulators set expectations for managing risks

Frankfurt financial district view

The financial district in Frankfurt, where EIOPA is based. Deejpilot/iStock.


The speed with which the latest AI models can expose cyber vulnerabilities requires financial services firms to move quickly to enhance the way they prevent, detect and manage cyber risks arising from such ‘frontier AI’, EU regulators have said.

For the first time, the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) have suggested “risk mitigation strategies and actions” for financial firms (8-page / 408KB PDF) to adopt to address frontier AI risk specifically.

The authorities stressed that while firms do not face “additional requirements” beyond requirements they face in existing frameworks such as the EU’s Digital Operational Resilience Act (DORA), and confirmed their expectations that firms act proportionately with regard to their size, complexity, interconnectedness and risk exposure, they said the “shorter vulnerability discovery and exploitation cycles” associated with the latest frontier AI models calls for firms to “act fast and proactively”.

Their joint statement identifies an “urgent need for robust cybersecurity measures and rapid incident response capabilities” and for financial entities to act “without delay” to “establish governance structures that support effective management of frontier AI related risk” and enable that risk to be closely monitored.

Risks posed by frontier AI, flagged by the three authorities, could arise from the operation of “traditional static security models”, which they said “may not be able to respond timely to AI-enhanced attacks”. This is because those security models “rely on predefined rules, signatures, and fixed patterns, while AI-driven threats are dynamic and adaptive”.

They also warned how cutting-edge AI models can “analyse and exploit architectural flaws” – citing “poorly secured APIs, excessive permissions, or monolithic system designs” as examples – and “even attempt to reverse engineer protected code in search of known vulnerabilities”.

Specific actions that firms are being asked to consider include automating vulnerability scanning and patch management. Firms should further look into segmenting systems to “reduce the attack surface”, enforcing cybersecurity standards across the supply chain, implementing comprehensive logging and behavioural monitoring strategies to detect anomalies, and updating and regularly testing incident response and business continuity plans.

The authorities said they have also “initiated targeted engagement” with some ‘critical ICT third-party service providers’ (CTPPs) subject to their oversight under DORA to “understand how they identify and manage the new challenges they face”. That work included a review of the way those providers assess and mitigate frontier AI risks. The authorities implied that CTPPs can expect to have their approach to addressing frontier AI risks further scrutinised in the months ahead.

Publication of the authorities’ joint statement comes just days after two major AI companies, OpenAI and Anthropic, admitted that AI models under their development had been behind cybersecurity incidents. In both cases, the models were being tested but managed to break free from those environments and go on to probe systems operated by third parties via the internet. They are the first reported cases of agentic AI tools ‘going rogue’ in a cybersecurity context, though some commentators have questioned whether the incidents are a public stunt designed to show off the powerful nature of the developers’ new tools.

Last month, the European Central Bank (ECB) wrote to the biggest banks (7-page / 226KB PDF) across the EU to underline the increased threat they face from AI-related cyber attacks. It has imposed a deadline of the end of October for those institutions to each submit a “comprehensive action plan” explaining how they will address those risks both in the immediate and longer-term.

In her letter, Claudia Buch, chair of the ECB’s supervisory board, said: “In the short term, particular focus should be placed on the following areas: accelerate vulnerability and patch management at scale; enhance monitoring, detection and AI-enabled defensive capabilities; verify that third-party risk management is fit for purpose in the current situation, in light of the role of ICT service providers in critical supply chains.”

“As part of the short-term effort, prioritising protection of perimeter technologies and internet-facing and externally exposed ICT assets, including third-party software and open-source components, is key to preparing for the rise in AI-enabled cybersecurity threats,” Buch added, suggesting longer-term action could include replacing or updating legacy technologies and bolstering response and recovery mechanisms, including their approach to crisis management.

The ECB’s warning was echoed by the European Systemic Risk Board (ESRB). The EU’s financial risk body published its own report (24-page / 319KB PDF) on the dangers of AI-powered cyber risks to financial institutions, warning that the latest frontier AI models “sharply” increase the risk of fully automated cyber attacks.

“The crafting of weaponised exploits was previously largely done manually and took human experts days or weeks, whereas it can now be done … in a matter of minutes or hours,” the ESRB said. It warned of the “collapse of defensive time buffers” and potential absence of available mitigation measures and said the situation “poses a systematic risk and has the potential to create systemic fragilities”.

The European Commission published an action plan for dealing with the risks of advanced AI cyber attacks last month. It builds on legislative initiatives such as NIS2 and seeks to assist members states in coordinating their approach to AI risks. National banks in Ireland and the Netherlands (29-page / 1.1MB PDF) are among those to have called on financial institutions in their own countries to enhance their cyber resilience.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.