RegulationAugust 6, 2026

Supervisors sound the alarm on AI that finds flaws faster

On 31 July 2026 the three European supervisors EBA, EIOPA and ESMA called for tighter governance and more consistent oversight of frontier AI in the financial sector. Two days later PYMNTS described how those same models compress the window between discovering a flaw and exploiting it.

Article image for: Supervisors sound the alarm on AI that finds flaws faster

On 31 July 2026 the three European supervisors EBA, EIOPA and ESMA published a joint statement on the ICT risks of frontier AI models in the financial sector. The message: governance around the use of these models must tighten, and supervision of them must become more consistent between member states. The authorities explicitly choose a risk-based, cross-sectoral approach and refer to the European Commission's Action Plan on Cybersecurity and AI.

Why now

The statement did not come out of nowhere. On 3 August 2026 PYMNTS described how advanced AI models sharply shrink the window between a vulnerability existing and being exploited. Where a researcher once spent weeks inside a single codebase, a model can now sweep thousands of projects at once looking for implementation mistakes. Last week's Coldcard flaw, where a misconfigured build undermined the entropy of seed generation, is precisely the kind of mistake that surfaces that way.

Scott Aaronson, scientific adviser at StarkWare, put it bluntly in the same piece: the time to start thinking about migrating to quantum-resistant encryption is now, not later.

Where DORA comes in

For the sector itself this attaches directly to DORA. That regulation requires financial institutions to demonstrably manage their ICT risks and brings critical third-party ICT providers under direct European oversight. An AI model deployed for code review, fraud detection or customer contact falls under that in practice. The supervisors make clear that buying in such a model does not move the responsibility.

The same line runs for CASPs under MiCA. If you hold an authorisation in the EU, your operational resilience has to be in order, and that includes the suppliers you hire.

What this is not

It is not a new rule and not a consultation. It is a joint signal indicating where supervision will be looking in the period ahead. Concrete obligations follow from DORA and the AI Act, not from this statement.

What this means for you

As a private user you see nothing of this supervision directly, but the direction is useful. Assume the time between a vulnerability becoming public and being exploited is getting shorter, not longer. That means: do not let firmware updates for wallets and devices sit for weeks, and when a flaw is reported, secure your balance first and work out afterwards whether you fall in the affected group. If you work at a firm covered by DORA, this is the moment to map the AI suppliers in your chain before the supervisor asks.

Sources: EBA, EIOPA and ESMA (joint statement, 31 July 2026), PYMNTS (3 August 2026), Regulation (EU) 2022/2554 (DORA). Last checked: 6 August 2026.

#DORA#AI#ESMA#regulatie