Warning for finance firms on ‘frontier’ AI
(Pic: Shutterstock)

Warning for finance firms on ‘frontier’ AI

The main EU financial regulators have urged financial firms to take action to prevent, detect, and manage cyber-security risks posed by what they describe as “the advance capabilities” of newer ‘frontier’ AI models.

The European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority said that the latest AI models “significantly accelerate” cyber-risks.

The three watchdogs said that AI-enabled cyber tools could generate systemic risks due to their ability to:

  • Rapidly discover and exploit vulnerabilities,
  • Target vulnerabilities in shared infrastructure, and
  • Leverage single points of failure across entities.

“While these models can help deliver substantial defensive improvements, they can also provide an advantage to malicious actors, which could leverage these capabilities,” they warned.

Models ‘broke free’

Lawyers at Pinsent Masons pointed out that the joint statement came days after two major AI companies, OpenAI and Anthropic, admitted that AI models under their development had been behind cyber-security incidents.

In both cases, the models were being tested but managed to break free from those environments and go on to probe systems operated by third parties via the internet.

The EU regulators said that the current EU regulatory framework – including the Digital Operational Resilience Act (DORA) and the AI Act – provided a “solid foundation” to tackle risks stemming from the release of highly capable AI models.

The bodies said that they had begun “targeted engagement” with critical third-party providers of technology to financial firms under DORA to understand how they were identifying and managing the new challenges they faced.

Governance structures

Among the measures they suggested for financial firms were:

  • “Comprehensive and continuously updated” inventories of all IT assets,
  • Enhanced detection measures,
  • Operational resilience testing, and
  • Enhanced disaster-recovery and data back-up capabilities.

“In all cases and without delay, the financial entities should establish governance structures that support effective management of frontier AI-related risk and closely monitor this risk,” the regulators added.

They stressed, however, that a ‘one-size-fits-all’ approach would not be proportionate and firms should take into account their size and overall risk profile when designing their risk-mitigation strategies.

Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland

Copyright © 2026 Law Society Gazette. The Law Society is not responsible for the content of external sites – see our Privacy Policy.