The European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority published a joint statement on frontier AI models on 31 July 2026. Filed as JC 2026 25, it asks supervisors and firms to treat the cyber risk from the most capable AI systems as a question of operational resilience rather than one of technology adoption.
What the authorities actually asked for
The statement calls for a cross-sectoral, risk-based and consistent supervisory approach to the information and communication technology risks stemming from frontier models. That wording matters. It does not propose a new rulebook. It asks the three authorities and national supervisors to apply the powers they already hold in the same way across banking, insurance and securities markets.
The concern named in the statement is concentration rather than novelty. AI-enabled cyber tools, the authorities argue, can discover and exploit vulnerabilities quickly, aim at weaknesses in shared infrastructure, and turn a single point of failure into an event affecting many firms at once. That is a systemic framing, and it explains why the response sits with supervisors rather than with individual risk teams.
The legal ground already exists
The statement leans on the Digital Operational Resilience Act, which has applied across the EU since 17 January 2025. Under that regime the three authorities act as Lead Overseers for critical ICT third-party providers, and they say they have already begun targeted discussions with those providers about how AI risk is managed inside them.
That detail is the practical core of the announcement. The leverage does not run through thousands of supervised firms. It runs through the small number of providers on whose infrastructure those firms depend.
How it connects to the Commission plan
The statement follows the European Commission, which presented its Action Plan on Cybersecurity and Artificial Intelligence on 7 July 2026. The authorities also cite earlier work by the European Systemic Risk Board, the EU Agency for Cybersecurity and the Single Supervisory Mechanism, which places the statement inside an existing chain of analysis rather than at the start of a new one.
What to watch
No named official speaks in the statement, and it carries no deadline, no threshold and no reporting template. Its weight therefore depends entirely on what national supervisors do with it. The signal to watch is whether AI-specific questions start appearing in routine resilience examinations, and whether the Lead Overseer discussions with critical providers produce anything published.