Three weeks ago we wrote that AI is now a DORA risk. On 31 July 2026, the regulators made it official.
The Joint Committee of the ESAs published a statement (JC 2026 25) on how financial entities should manage ICT risk from frontier AI models under DORA. It builds on the European Commission's EU Action Plan on Cybersecurity and Artificial Intelligence from 7 July 2026, and it applies to every DORA-regulated entity.
No new rules, but a preview of your next inspection
The statement does not change DORA, and it puts no direct obligations on AI providers. Everything in it is a supervisory expectation under rules that already apply: the ICT risk management requirements in Chapter II and the proportionality principle in Article 4.
Still, take it seriously. Statements like this shape the questions national supervisors ask in inspections. The three areas below are a good preview of that checklist.
What is "frontier AI"? The most advanced models available or in development. In practice, that means the large general-purpose models most firms already use through APIs, copilots and AI features built into SaaS tools. The regulators' point is that this technology cuts both ways. It makes threat detection better, and it makes attackers faster.
The three expectations
1. Prevention. Keep a complete and updated inventory of IT assets. The statement is explicit that this includes AI and machine learning components, APIs and data stores. Build security in from the start, patch proactively, and understand how your assets depend on each other. If your asset register cannot show where AI sits in your systems, that is now a visible gap. 2. Detection. Scale up vulnerability scanning to match attackers who use AI. Detect and respond continuously, not periodically. Strengthen your SOC and red team with AI tools. In short: use the same technology for defence that attackers use for offence. 3. Management. Adapt resilience testing, disaster recovery and backups to AI-driven threats, including scenarios where several systems fail at once. Update your risk framework and test methods. And keep the board involved. The management body owns ICT risk under Article 5, and that includes this.Your AI vendors just inherited your questionnaire
Most financial entities buy AI rather than build it. That pulls the statement straight into your third-party framework under Article 28. Your due diligence on AI providers should now cover:
- how they govern model development and deployment
- how resilient the infrastructure behind the model is
- how open they are about model limits and failure modes
- how they handle and report incidents
- which subcontractors and cloud providers they depend on
- their business continuity and exit arrangements
If the AI service supports a critical or important function, the full contract requirements in Article 30(3) apply, audit rights included. AI vendors are about to face the same contract demands cloud providers have handled since 2025.
Five things to do this quarter
- Tag AI in your asset inventory. AI components, model APIs and AI features in SaaS, linked to the functions they support.
- Update your risk register. Add scenarios for AI-assisted attacks, deepfake fraud and compromised models.
- Extend vendor due diligence with the six points above. A structured questionnaire makes this repeatable.
- Brief the board. One page on the statement, your exposure and your gaps. Put it in the minutes.
- Document your proportionality call. Whatever you decide, write down why.
How DORA GRC helps
In DORA GRC you can register AI systems as ICT assets linked to functions, add AI scenarios to the risk register, and extend vendor questionnaires with AI questions. When the supervisor asks, the 360° Intelligence Hub shows the whole chain from asset to risk to control to vendor.
Sources: ESAs Joint Committee, Statement on frontier AI models (JC 2026 25), 31 July 2026. European Commission, EU Action Plan on Cybersecurity and AI, 7 July 2026. Regulation (EU) 2022/2554, Articles 4, 5, 8, 28 and 30.