On 31 July 2026 the three European Supervisory Authorities told financial entities to rebuild ICT risk management around frontier AI. Read next to the letter the ECB sent bank CEOs twenty-four days earlier, one paragraph is near-identical — and one thing is missing.
Frontier AIDORARisk appetiteThird-party riskThe ESAs' joint statement of 31 July 2026, Toward a consistent and risk-based approach for ICT risks from frontier AI models (JC 2026 25), is supervisory-convergence material. Its Annex says so on its face:
"This Annex does not establish additional requirements, nor should be regarded as a comprehensive checklist. Instead, it is to be read as illustrative examples to be considered by financial entities, also in their dialogue with ICT third-party service providers."
The binding instruments remain DORA and the AI Act. The statement records that the existing framework "provide[s] a solid foundation", that "the regulatory framework remains technology-neutral", and that the AI Act already covers "General-purpose AI models with systemic risk" with additional provider obligations on transparency, technical documentation and cybersecurity. Proportionality is anchored on a named article: DORA Art.4.
Get that distinction right first. A firm that treats JC 2026 25 as a new rulebook will build controls it cannot map to an obligation. A firm that dismisses it will be unprepared for the supervisory dialogue the ESAs say it is meant to seed.
On 7 July 2026 ECB Banking Supervision wrote to the CEOs of significant euro-area institutions on AI-enabled cybersecurity threats. Annex 1 of that letter says:
"Risk appetite frameworks should be reviewed in order to update and/or incorporate metrics, tolerance thresholds and control measures — including those related to increased patch management frequency — consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them."
Paragraph 7 of JC 2026 25, twenty-four days later, says:
"The Risk Appetite Framework should be reviewed to update and/or incorporate metrics, tolerance thresholds, and control measures consistent with the evolving risk profile stemming both from the internal use of such models and from indirect exposure to them."
The final twenty-one words are identical. What the cross-sectoral text drops is the operative example — increased patch-management frequency — which was the one clause telling a risk committee what a tolerance threshold on this risk would actually be measured in.
Two words survive in both and carry the weight: indirect exposure. A firm can inventory the models it deploys. It cannot inventory the models used against it, nor those embedded upstream in a provider's stack. A risk appetite statement that only bounds internal AI use answers half the paragraph.
The ECB letter is an instruction with a date. Significant institutions are asked to submit an action plan to their Joint Supervisory Team by 31 October 2026 — eighty-seven days after this briefing — covering vulnerability and patch management at scale, monitoring and AI-enabled defensive capability, and third-party risk management. The ECB paid for the effort in the same letter: the annual IT Risk Questionnaire collection moves from September 2026 to February 2027.
JC 2026 25 sets no comparable date for anyone. Its forward dates are the supervisors' own: insights from CTPP engagement have "informed the annual risk assessment cycle and the prioritisation of activities under the 2027 Oversight Plan"; AI risk is being embedded into the Oversight Examination Methodology, work continuing "throughout 2027"; and these threats "are expected to be reflected in the scope of the oversight examinations and other oversight activities in 2027".
That asymmetry is the practical finding. The remedy is dated for banks and undated for insurers, while the exposure is shared — most obviously through the ICT third parties both sectors buy from. An insurer waiting for its own deadline will be answering questions in 2027 about a control environment it was told to fix in 2026.
Paragraph 1 names how AI-enabled cyber tools could generate systemic risk: the ability to "i) rapidly discover and exploit vulnerabilities; ii) target vulnerabilities in shared infrastructure; and iii) leverage single points of failure across entities".
Those are three different correlation channels, and only the first is a firm-specific control problem. Channels (ii) and (iii) are common-mode: they describe an event that arrives at many firms at once, through infrastructure no single firm owns. That is an operational-risk tail question and a reinsurance question, not a patching question — and it is not answered by hardening your own perimeter.
Across prevention, detection and management, the anchors worth quoting to a committee:
On governance, the Annex asks that management-body oversight "evolve from periodic oversight to continuous, informed engagement", because AI-driven attacks "target not only technical systems but also governance weaknesses, decision-making gaps, and risk oversight failures".
For a firm operating in both the UK and the EU, this runs in parallel with the UK Critical Third Parties regime, and the instruction is the one we gave then: build the dependency register once, evidence it twice.
The ESRB warning cited throughout JC 2026 25 carries two dates, and both are correct. It was adopted on 25 June 2026 — the date the instrument bears as ESRB/2026/3, and the date the ESAs' footnote uses — and published on 7 July 2026, the same day the ECB letter went to bank CEOs. Where a citation looks inconsistent between sources, this is usually why. We cite the adoption date for the instrument and the publication date for the event.
A firm-specific walk-through of correlated ICT third-party failure — dependency map to operational-risk tail to capital consequence, evidenced end to end.