Frontier AI Governance Under DORA: What the ESA Statement and FCA Review Signal for Risk Committees

Frontier AI Governance Under DORA: What the ESA Statement and FCA Review Signal for Risk Committees

Two supervisory documents, 33 days apart. Neither creates a new obligation, and both are worth an hour of a risk committee's attention.

On 31 July 2026 the Joint Committee of the European Supervisory Authorities published a statement on ICT risks from frontier AI models (JC 2026 25). On 2 September 2026 the Financial Conduct Authority published a multi-firm review on frontier AI and cyber resilience.

Taken at face value, both look like documents for the technology function. They are not, or at least not only. A good deal of what each contains lands on governance, and specifically on the machinery by which a firm decides what to do about something it has just found out.

1. What the ESAs said

The ESA statement opens from a position on capability. The advanced capabilities of recent frontier AI models significantly accelerate cyber risks, and AI-enabled cyber tools could generate systemic risks through their ability to rapidly discover and exploit vulnerabilities, to target vulnerabilities in shared infrastructure, and to leverage single points of failure across entities.

On the legal position the statement is unambiguous. The current EU regulatory framework, and DORA and the AI Act in particular, provide a solid foundation for tackling these risks. The DORA requirements remain highly relevant through the ICT risk management framework, testing, incident and recovery management, and ICT third-party risk management. The AI Act supplies a framework for general-purpose AI models with systemic risk, with additional obligations on providers covering transparency, technical documentation and cybersecurity.

The ESAs are not adding a new set of requirements here. What they do is encourage financial entities to act fast and proactively, because the vulnerability discovery and exploitation cycle has shortened, and to adjust ICT risk management processes, procedures and controls under three mitigation strategies: prevention, detection and management. An Annex sets out illustrative actions under each heading, and says in terms that it establishes no additional requirements and is not a comprehensive checklist.

Why a statement that creates no additional requirements is still worth reading: the ESAs record that supervisory dialogue with financial entities already pays particular attention to these risks and to the measures entities have in place to safeguard operational resilience. The Annex adds that its illustrative examples may also be considered by entities in their dialogue with ICT third-party service providers. So this is not an inspection programme, but it is a reasonable indication of the ground that dialogue is likely to cover, and useful preparation for it.

2. What the FCA found

The FCA document is a different instrument. It summarises observations reported by firms during the FCA's engagement, and states that it does not introduce new rules, guidance or regulatory expectations. It follows the joint statement issued with the Bank of England and HM Treasury in May 2026, which described these models as a step-change in capability with significant implications for cybersecurity and operational resilience.

The FCA is explicit that it is publishing so that smaller and medium-sized firms in particular can learn from what others reported. That makes it a useful peer reference point rather than a new regulatory expectation. It should therefore be read differently from the ESA statement.

Its five headline themes compress to one sentence: frontier AI is accelerating vulnerability discovery faster than firms can respond, and in doing so it is revealing whether the governance, risk ownership, engineering capacity and remediation processes needed to act on that discovery are actually there.

Several firms characterised frontier AI as a stress test of their existing cyber-resilience capabilities. That line is reported by firms rather than asserted by the regulator, which is part of why it is useful.

3. Where the two publications meet

The ESA Annex identifies management body accountability as an area requiring change, on the basis that AI-driven attacks target not only technical systems but also governance weaknesses, decision-making gaps and risk oversight failures. Without clear accountability at the highest level, entities may underestimate the risks, fail to allocate sufficient resources, or lack a coordinated response. The action the Annex describes is a move:

"from periodic oversight to continuous, informed decision making"

Elsewhere the Annex notes that the frequency of risk reporting may prove insufficient for detecting and mitigating AI-enhanced attacks, and points towards more automated monitoring and faster, more adaptive escalation procedures.

The FCA arrives in the same territory by another route. It reports that governance forums, risk committees and senior leaders may need clearer visibility of how frontier AI affects vulnerability registers, remediation, supplier dependencies, risk and operational resilience, and that firms may need to consider whether their governance and escalation routes are sufficiently responsive. It also notes that firms may need to distinguish between observed risks, firm-specific evidence and more speculative scenarios, so that responses stay prompt without becoming disproportionate.

My reading is that the two publications converge on a practical governance question: how quickly a validated finding can reach somebody with authority to act on it. That is an interpretation, not a shared regulatory conclusion. Neither document says that a quarterly reporting cycle is inherently deficient, and neither identifies reporting cadence as a point of failure.

The question to put to your own arrangements: a quarterly cycle may be perfectly adequate for routine reporting while still requiring a separate route for urgent findings. The useful exercise is to establish what the elapsed time actually is between a material finding being validated and somebody with authority being in a position to act, and whether the route that shortens it exists anywhere other than on a diagram.

4. Vulnerability chaining and what it does to prioritisation

One finding in the FCA review deserves to reach every vulnerability management policy owner.

Firms told the FCA that frontier AI models can combine multiple lower-rated security flaws, an approach the review calls vulnerability chaining, and create alternative routes to compromise. Those firms reported that the relationships between vulnerabilities, systems and dependencies which make such routes possible may not have been visible through traditional approaches to testing and scanning.

The consequence they described is a shift in how remediation is prioritised. Several firms noted that with better visibility of those relationships, their decisions are increasingly informed by the disruption that would follow if an attack path were exploited, rather than by the ratings of vulnerabilities considered in isolation. The FCA frames this as a broader, risk-based view drawing on exploitability, business service impact, prerequisites to exploit, risk-reduction controls and dependency on the vulnerable system.

The ESAs identify the same mechanism under a different heading. Their Annex notes that threat actors can use AI to map dependencies, identify single points of failure and chain exploits for maximum impact, and asks entities to identify and monitor dependencies across software, infrastructure and operations, assess their criticality and risk, and mitigate accordingly.

None of this makes severity ratings useless. What it questions is whether a policy that ranks on severity ratings alone can express the thing that firms told the FCA they were starting to see, which is a route rather than a defect.

5. The Risk Appetite Framework point

This is one of the clearest governance actions in either document, and it is not simply a technical control question.

The ESAs say the Risk Appetite Framework should be reviewed to update or incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them.

The statement does not define either category, so it is worth being careful about what is being asked. Internal use might, by way of example, cover a firm's own deployment of frontier AI in its operations, including for cyber discovery. Indirect exposure might cover exposure arising through adversaries or through suppliers using the same class of capability. Those are illustrations rather than regulatory definitions. The ESAs' point is simpler: the framework should address both.

The ESAs also say that, in all cases and without delay, financial entities should establish governance structures that support effective management of frontier AI related risk and closely monitor it, while noting that a one-size-fits-all approach would be neither proportionate nor efficient. Entities are to take into account their size and overall risk profile, and the nature, interconnectedness, scale and complexity of their services, activities and operations. That proportionality anchor is DORA Article 4.

Why this one is worth doing first: a RAF review is a defined action with a dated, evidenceable output. If the topic comes up in supervisory dialogue, a completed review that treats internal use and indirect exposure as distinct questions is a stronger position than a policy statement about responsible AI.

6. Third parties, and what 2027 actually refers to

Both documents push into the supply chain, and the ESA statement carries the harder detail.

The ESAs, acting as Lead Overseers, initiated targeted engagement with relevant critical ICT third-party service providers to understand how they identify and manage these challenges, covering risk identification and assessment, mitigation measures implemented, and adaptation to the associated opportunities. Those insights have fed the annual risk assessment cycle and the prioritisation of activities under the 2027 Oversight Plan. The ESAs have also begun embedding AI-related risks into the Oversight Examination Methodology, and expect these threats to be reflected in the scope of oversight examinations and other oversight activities in 2027.

It is worth being precise about who is being examined. The 2027 examinations described here are CTPP oversight examinations conducted by the Lead Overseers. They are not examinations of an individual financial entity's own compliance with DORA Chapter V. What the passage does is raise the prominence of AI-related third-party risk within the DORA oversight environment as a whole, which is a different and more indirect proposition.

The FCA records the firm-level counterpart. Some firms told the regulator they are engaging suppliers on how they are using AI-enabled vulnerability discovery, how they validate findings, whether they notify customers, and whether they are able to remediate quickly.

The ESA Annex adds that cybersecurity standards should be assessed, monitored and enforced across the whole supply chain, with more rigorous controls where exposure is greater and supply chains more complex, and that this extends beyond service providers and partners to software and hardware providers and open-source communities.

7. What neither document does

Precision matters here, because this material is easy to overstate.

Neither adds a new obligation. The ESA statement provides context on existing legislation and supervisory expectations, and its Annex disclaims any additional requirements. The FCA review states that it introduces no new rules, guidance or regulatory expectations.

Neither is enforcement. There is no case, no penalty and no finding against a named firm in either.

Neither names a specific senior management function. The FCA refers to senior leaders, governance forums and risk committees. The ESAs refer to the management body. Allocating this to a named individual is a firm-level decision.

The FCA document is not a survey. It reports what firms said during engagement, with no counts, no proportions and no sample description. It should not be cited as evidence of how common any practice is.

The link to DORA supervisory dialogue is my inference. The FCA review does not mention DORA at any point. Reading its questions as a preview of the ground DORA dialogue may cover is an interpretation offered here, not a position taken by either authority.

8. What to change before the next risk committee

Five actions, none of which requires new technology.

Review the Risk Appetite Framework against both categories the ESAs identify, internal use of frontier AI models and indirect exposure to them. Record the review, its date and its conclusions.

Establish the escalation interval. Work out how long it currently takes for a validated critical finding to reach someone with authority to act outside the normal reporting cycle, and whether that route has ever been used in practice.

Re-examine remediation prioritisation. Test whether the policy can express exploitability, dependency and business service impact, or relies on severity ratings alone. If it relies on severity ratings alone, it may not adequately capture the significance of the chained attack paths firms described to the FCA.

Find the bottleneck. The FCA lists validation capacity, engineering resource, patch testing, emergency change controls, evidence of closure, and the ability to maintain important business services during accelerated remediation. Work out which of those constrains your firm first.

Put the supplier question in writing. Ask key ICT third-party service providers how they are preparing for AI-enabled vulnerability discovery and increased patch volumes, and keep the answers. Given where the ESAs say oversight attention is heading in 2027, that correspondence is worth having on file.

The test: if a critical, chained attack path were validated in your firm on a Friday afternoon, who decides what happens to it before Monday, and does that route exist anywhere other than on a diagram?

9. Sources

EU supervisory statementESA Statement, Toward a consistent and risk-based approach for ICT risks from frontier AI models (JC 2026 25),31 July 2026, including the Annex of illustrative mitigation strategies
UK multi-firm reviewFCA, Frontier AI and cyber resilience, 2 September 2026
UK joint statementFCA, Bank of England and HM Treasury joint statement on frontier AI models and cyber resilience, May 2026
Systemic risk warningWarning of the European Systemic Risk Board of 25 June 2026 on systemic cyber risks stemming from frontier artificial intelligence models (ESRB/2026/3)
EU action planEuropean Commission, Action Plan on Cybersecurity and Artificial Intelligence, 7 July 2026
Core frameworkRegulation (EU) 2022/2554 (DORA),in particular Article 4 on proportionality, Chapter II on ICT risk management and Chapter V on ICT third-party risk
AI frameworkRegulation (EU) 2024/1689 (AI Act),provisions on general-purpose AI models with systemic risk

Know what supervisors are looking for. Our seminars work through supervisory expectations, thematic findings and enforcement decisions as they land, with CPD hours recognised for CySEC-licensed professionals.

Explore seminars at cpds.academy

This article is provided for general information and professional education purposes only. It reflects publicly available information as at the date of publication and does not constitute legal or compliance advice. Firms should assess their own obligations with reference to their regulatory permissions and, where appropriate, take independent advice.

Nikolas Demetriades

Article by Nikolas Demetriades

Published 03 Sep 2026