Consistent and risk-based approach ICT risks, AI models

On 31 July 2026, the European Supervisory Authorities ("ESAs") published a joint statement on the implications of frontier artificial intelligence for information and communication technology ("ICT") risk within the financial sector.

At first glance, the statement appears familiar. It reiterates principles already embedded within the Digital Operational Resilience Act ("DORA"), including governance responsibilities, ICT asset management, vulnerability management, security testing and third-party risk.

Yet a closer reading suggests something more significant.

The statement does not amend DORA. Instead, it changes the context in which DORA is expected to operate.

DORA's obligations remain the same

Boards remain responsible for ICT risk management.

Institutions must continue to maintain ICT asset inventories, implement vulnerability management processes, conduct security testing, manage ICT third-party risk and oversee their digital operational resilience framework.

None of these obligations are new. They have been part of DORA since its adoption.

The ESAs' latest statement therefore should not be understood as introducing additional regulatory requirements. Rather, it provides supervisory insight into how existing obligations may now be interpreted in light of rapidly evolving technologies, particularly frontier AI.

Principles evolve with the threat landscape

One of DORA's defining characteristics is that many of its obligations are deliberately principle based.

Requirements are framed using concepts such as "timely", "appropriate", "effective" and "proportionate".

Those concepts are intentionally flexible. They allow regulatory expectations to evolve alongside technological developments and emerging cyber threats without requiring legislative amendments.

The latest statement demonstrates precisely this dynamic.

As AI-enabled cyber capabilities accelerate the speed and sophistication of attacks, supervisory expectations regarding what constitutes timely vulnerability management or proportionate security measures may also evolve.

Processes that previously reflected accepted industry practice may no longer satisfy supervisory expectations if they fail to keep pace with the changing threat environment.

Frontier AI reshapes operational resilience

The ESAs highlight that frontier AI has the potential to compress the time between vulnerability discovery and exploitation.

This has practical implications for operational resilience.

For example, vulnerability scanning that was previously performed periodically may increasingly be expected to operate on a continuous basis for critical assets. Similarly, annual security testing, while remaining an important control, may no longer be viewed as sufficient where rapidly evolving threats create significant exposure between scheduled assessments.

The regulatory framework itself has not changed.

The operational benchmark against which institutions may be assessed has.

Governance implications for Boards

For Boards, the statement reinforces that DORA compliance cannot be viewed as a static exercise.

Compliance should instead be understood as an ongoing governance process requiring continuous reassessment of whether existing controls remain appropriate in the current threat landscape.

This also has implications for historical findings.

Issues identified during previous supervisory inspections or sector-wide exercises may now assume greater significance where supervisory expectations have evolved. A control environment considered adequate several years ago may warrant reassessment even where no formal legal obligation has changed.

Emerging questions around AI supply chains

The statement also raises broader governance questions regarding exposure to frontier AI.

Institutions may increasingly be expected to understand indirect exposure arising through technology providers, software dependencies and digital supply chains.

This presents practical challenges.

Traditional third-party risk management under DORA is largely structured around contractual relationships. Frontier AI ecosystems, however, increasingly involve open-source components, community-developed models and complex software dependencies that may not fit neatly within conventional supplier governance frameworks.

Accordingly, institutions may need to rethink how ICT dependencies are identified, assessed and monitored beyond traditional contractual relationships.

Compliance is no longer a fixed destination

Perhaps the most important message arising from the ESAs' statement is that compliance with DORA is not simply a question of whether regulatory requirements have been implemented.

It is equally a question of whether those controls continue to reflect the reality of today's technological and cyber risk environment.

The legal framework has remained largely unchanged.

What continues to evolve are the supervisory expectations through which that framework is interpreted.

For financial entities, Boards and senior management, the question may therefore no longer be whether they are "DORA compliant", but whether their interpretation of DORA continues to align with the pace of technological change.

For any additional information or assistance, please contact us at info@gtg.com.mt

Author: Dr Ian Gauci

Disclaimer This article is not intended to impart legal advice and readers are asked to seek verification of statements made before acting on them.
Skip to content