91010

Immagine creata con IAAI-generated image

Frontier artificial intelligence reaches the board: a report due by 31 December

On 16 July 2026 the Official Journal of the European Union published a warning of the European Systemic Risk Board describing frontier artificial intelligence models as a source of systemic risk for the Union’s financial system. The following day the Bank of Italy and IVASS asked the boards of supervised intermediaries and of insurance undertakings to meet jointly with the board of statutory auditors, to draw up a report on their level of exposure and to attach a work plan to be sent to the authority by 31 December 2026. At the end of the same month the three European supervisory authorities issued a joint statement on the same subject. Within five weeks, exposure to hostile artificial intelligence has become a documentary burden with a fixed date resting on the administrative body, and it has happened without a single provision being amended.

What the European Systemic Risk Board warned about

Warning ESRB/2026/3, adopted on 25 June 2026 and published in the Official Journal of 16 July, defines frontier artificial intelligence models as “advanced general purpose AI models capable of materially affecting offensive or defensive cyber operations”. The Board notes that such models possess a high degree of capability in cybersecurity and are able to carry out fully automated cyberattacks against complex systems, discovering vulnerabilities and weaponising exploits. This is not a forward looking scenario: the text states that current evidence already points in that direction.

The legally densest passage concerns the assessment of consequences. The Board recognises that the same models will also strengthen the defensive capabilities of financial institutions, but it warns that in the short and medium term the increase in the speed, scale and accuracy of offensive capabilities is likely to outweigh the benefits. Should those risks materialise simultaneously across functions and institutions, the result would be a permanent increase in systemic cyber risk for which, at present, no fully effective mitigation framework is available. That admission carries weight, because it comes from a body whose task is to indicate mitigating instruments and which here states that it has none that are fully effective.

The collapse of defence time margins

The most concrete part of the warning concerns time, and it explains why the subject does not stay confined to technical functions. Historically the discovery of a critical vulnerability was a rare event, and software providers were granted a standardised period, usually 90 days, to fix it before public disclosure. Patching practices in the financial system, the Board observes, are predominantly reactive and rest precisely on that margin. Producing a weaponised exploit used to take skilled humans days or weeks, whereas it can now be done by frontier models in a matter of minutes or hours.

From this follows a problem the Board describes without softening it: if too many critically impactful vulnerabilities were identified within a short period, financial institutions might have to decide whether to expose themselves to significant cyber risks or to lower patch testing requirements, thereby risking operational incidents and disruption. The dilemma has no technical solution, because both options involve assuming risk, and for that reason it becomes a decision about the governance of the undertaking rather than a choice for the IT function.

Three asymmetries

The Board identifies three asymmetries that frontier models alter. The first is between jurisdictions: the geographical concentration of the main providers outside the Union exposes Europe to strategic dependency and geopolitical risk, and the text calls for measures facilitating adequate and proportionate access to newly developed models, warning that arrangements granting access only to certain categories of entities or in certain jurisdictions would contribute to fragmenting the single market. The second is between attackers and defenders: frontier models lower the price of entry for attackers, while defenders remain constrained by operational requirements, dependencies and regulatory obligations, which lengthens their adjustment times. The third is between better resourced institutions and less equipped ones, with the consequence that the weakest link in the chain can affect the stability of the system.

Against that background the warning formulates the request that later reappears, almost word for word, in the national measures: financial authorities should ensure that the boards of private financial institutions are fully committed to mitigating cybersecurity risks driven by frontier models, that clear governance and accountability frameworks are in place, and that timely responses are adequately planned together with the corresponding internal investment. The locus of the decision is once again the board, as had already happened with the NIS 2 Directive and the Cyber Resilience Act, a shift examined in Cyber accountability moves up to the board.

What the Bank of Italy and IVASS are asking for

On 17 July 2026, the day after the warning was published, the Bank of Italy issued a communication to the market on digital operational resilience and advanced artificial intelligence models, addressed to entities supervised by its Banking and Financial Supervision Department: less significant banks and banking groups, including Bancoposta, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, alternative investment fund managers, management companies, crowdfunding service providers and financial intermediaries entered in the register under article 106. On the same day IVASS published a communication with the same subject matter, addressed to insurance and reinsurance undertakings with their registered office in Italy and to the general representative offices in Italy of undertakings based in a country outside the European Economic Area.

The stated basis is Regulation (EU) 2022/2554, the Digital Operational Resilience Act. The Bank of Italy writes that it is acting in line with the approach of European single supervision and bearing in mind the requirements laid down in DORA, which retain their full force in this context as well. IVASS, for its part, states that it is acting in line with the requirements laid down in DORA. Neither authority introduces a new obligation: both read an existing obligation in the light of a changed threat. For those working across overlapping regimes, the perimeters are mapped in NIS 2, DORA and the Cyber Resilience Act.

The report, the plan and the point of accountability

The operative part is what binds the agenda of the coming months. The Bank of Italy expects the board of directors, in a joint sitting with the board of statutory auditors, to examine the content of the communication, and expects that same sitting to start work on a report which, separately for each of the areas identified, sets out the current level of risk exposure and the adequacy of existing safeguards, identifies the main shortcomings and the related intervention priorities, and defines a work plan indicating the actions, timelines and investment required, proportionate to the risk profile, the complexity of the services and the activity and operations of the intermediary. The plan must also specify how the board itself will monitor progress, and every entity must identify and notify to the authority a specific point of accountability within the organisation, indicated by way of example as the second line ICT risk control function. The deadline is set in plain terms: the report, with the work plan attached, must be sent to the supervisory authority by 31 December 2026. The IVASS communication follows the same design and the same year end deadline for insurance undertakings.

The report must be organised around six areas: governance, cyber hygiene, management of IT assets and of the potential exposure surface, management of vulnerabilities and patches, monitoring together with detection and defence measures, and finally testing activities. This is not a closed questionnaire but an expository framework: for each area the board must state where the entity stands, what is missing, in what order it will act and with what resources. It is precisely the kind of document that, in the event of an incident, is read backwards.

Technological competence of the body and risk appetite

Two indications in the Bank of Italy communication deserve attention because they touch on the composition of the body and not merely on its acts. The first concerns risk appetite: the management and administrative bodies must revise the risk appetite framework so as to incorporate the risks arising from frontier technologies. This is not a procedural update, because the risk appetite framework is the instrument by which the board declares how much risk it is prepared to assume, and amending it means revisiting a strategic choice.

The second concerns competence: the communication states that it is important for the administrative and management body to include members with adequate technological skills, including in the field of artificial intelligence, and to provide for a budget sufficient to ensure their ongoing training. That expectation sits alongside the one article 4 of the Artificial Intelligence Act addresses to providers and deployers on literacy, with the not insignificant difference that here the addressee is named precisely and is the top of the undertaking. On the contours of that European obligation, and on how much of it survived the Digital Omnibus, see AI literacy: what is left of article 4.

Critical aspects: supervisory expectations, not new rules

On 31 July 2026 the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority published a joint statement calling for a cross-sectoral, risk based and consistent supervisory approach to the ICT risks stemming from frontier models. The accompanying announcement specifies that financial entities “should have robust governance and risk management frameworks in place” and that the statement is offered to entities and competent authorities “as a basis for supervisory dialogue”. It also reports on the DORA oversight activities concerning critical ICT third party providers.

This is where the critical point lies. A warning of the European Systemic Risk Board, a statement of the European supervisory authorities and two communications to the market are not sources that create new obligations, and none of them carries a penalty of its own for non compliance. What they produce is a documented and dated supervisory expectation, which operates on a different plane: a report that was never drawn up or a plan that was never prepared becomes a factor in the dialogue with the authority and, in the event of an incident, an indicator of the diligence of the body in relation to a risk that had been formally brought to its attention. It is the same mechanism by which adherence to a voluntary instrument weighs on the assessment without ever standing in for the rule.

One discrepancy in the calendar is also worth flagging. The warning itself reports that the European Central Bank, in its role as banking supervisor, has asked significant institutions to assess promptly the impact of the evolving threat landscape and to develop, by 31 October 2026, a wide ranging action plan setting out concrete measures to address those risks. The result is that, for the same risk and under the same rules, the deadline falls on 31 October for significant institutions and on 31 December for less significant intermediaries and for insurance undertakings. The difference is consistent with how supervision is structured, but it means that a group whose components answer to different authorities must coordinate two deadlines and two addressees for a single self assessment exercise.

For anyone sitting on the board of an intermediary or an insurance undertaking the practical consequence is already fixed. By the end of the year there must be a joint sitting with the board of statutory auditors recorded in the minutes, a report covering the six areas identified, a plan with actions, timelines and investment, a mechanism for monitoring progress, and the name of the internal point of accountability to be notified to the authority. The risk appetite framework must be reopened to take in frontier technologies, and training for the body must be given a budget. None of these steps arises from a rule that entered into force this summer: they arise from the reading that supervisors are now giving to obligations already in force since January 2025, and for that very reason the argument that it is all new is not available.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article