Regulations

Frontier AI, DORA, and the Case for Faster Security Validation

DORAFrontier AICybersecurityOperational ResilienceESAFSBFinancial ServicesAI Governance

Executive Summary

  • Recent statements from the European Supervisory Authorities, the Financial Stability Board, and OpenAI point to the same operational concern: cyber risk may develop faster than traditional security and resilience processes can absorb.
  • The conclusion is not that annual testing, penetration testing, or disaster recovery exercises have become obsolete. They remain required or valuable controls in many financial-services regimes. The issue is whether a programme built primarily around fixed intervals can identify and remediate material exposure quickly enough when vulnerability discovery and exploitation are accelerating.
  • For EU financial entities, DORA already requires a comprehensive, risk-based digital operational resilience testing programme. The ESAs’ July 2026 statement on frontier AI does not add new legal duties, but it expressly encourages firms to strengthen prevention, detection, and cyber-risk management. Its illustrative measures include continuous monitoring, continuous vulnerability scanning, more frequent testing, and resilience scenarios involving AI-assisted threats and multi-system failures.
  • For boards and senior management, the practical question is straightforward: can the institution show that its control environment detects, prioritises, tests, remediates, and recovers at a pace consistent with its risk profile and critical dependencies?

1. What Has Changed

Three public statements in a short window establish the context.

OpenAI, 1 September 2026. OpenAI stated that Astra met the Critical cybersecurity capability threshold in its Preparedness Framework. OpenAI reported that, with appropriate tools and access, Astra can identify previously unknown vulnerabilities and develop exploit paths across many hardened systems without step-by-step human guidance. It also reported expert-led testing in which the model produced a browser sandbox escape and local privilege-escalation chains. These are OpenAI’s own assessments, not independent regulatory findings.

ESAs, 31 July 2026. The European Supervisory Authorities published a joint statement on ICT risks from frontier AI models (JC 2026 25). The statement is grounded in existing DORA and AI Act obligations. It observes that shorter vulnerability discovery and exploitation cycles require financial entities to act quickly and proactively, while retaining a proportionate approach. It recommends that monitoring shift from periodic to continuous and that firms increase the frequency of scans, tests, and compliance checks when appropriate. The annex is explicitly illustrative and does not establish additional requirements.

FSB, 31 August 2026. FSB Chair Andrew Bailey told G20 finance ministers and central bank governors that the potential effect of frontier AI on cyber risk was the financial system’s most immediate AI-related concern. The letter warns that frontier AI could alter the speed, scale, and economics of cyber risk, with consequences for market confidence and common technology dependencies. It is a policy warning rather than a binding requirement.

2. What DORA Requires, and What It Does Not

DORA requires most in-scope financial entities to establish, maintain, and review a sound and comprehensive digital operational resilience testing programme. The programme must be risk-based and consider the evolving ICT risk landscape, criticality of assets and services, and the entity’s specific exposure.

Appropriate testing must occur at least annually for ICT systems and applications that support critical or important functions. DORA also provides for threat-led penetration testing for entities identified by their competent authorities, ordinarily at least every three years.

DORA does not prescribe continuous penetration testing or continuous disaster recovery exercises. Nor does it excuse unsafe change. Faster remediation still requires sound testing, segregation of duties, rollback arrangements, and clear risk acceptance.

The ESA statement supports a more nuanced conclusion: fixed-interval controls may remain necessary, but they may no longer be sufficient as the primary source of assurance for rapidly changing exposure.

3. The Operational Implication

A mature programme should distinguish between continuous controls and periodic assurance.

Continuous controls may include asset and dependency discovery, exposure management, vulnerability scanning, security monitoring, threat intelligence, identity telemetry, and evidence of patch deployment. These controls reduce the time between exposure, detection, prioritisation, and containment.

Periodic assurance remains necessary for questions that require deeper examination: independent penetration tests, threat-led exercises, recovery tests, scenario-based resilience testing, and validation of material changes. These exercises should increasingly include compressed attack timelines, compromised third parties, simultaneous failures, and dependencies shared across business lines or firms.

This is an interpretation of the regulatory direction, not a new legal requirement. The appropriate balance depends on the institution’s size, critical functions, architecture, threat exposure, and supervisory expectations.

4. Board and Executive Priorities

Senior leaders should seek evidence in five areas:

  1. Exposure visibility. Is there a current inventory of critical assets, externally exposed services, software dependencies, APIs, and material ICT providers?
  2. Remediation speed. Can the institution measure the time from a credible vulnerability signal to triage, risk decision, tested remediation, and confirmed closure?
  3. Control validation. Are detection controls, protective controls, and recovery controls tested against realistic AI-assisted attack paths, rather than only against known scenarios?
  4. Dependency resilience. Have critical third-party and concentration risks been mapped, including common cloud, identity, network, software, and AI dependencies?
  5. Governance and escalation. Do management information and escalation thresholds reflect compressed attack timelines and plausible multi-system disruption?

Conclusion

Frontier AI does not make established resilience practices irrelevant. It makes the interval between assurance activities more consequential.

DORA still requires a risk-based testing programme, including annual testing for critical or important functions. The ESA statement does not replace that programme with a universal continuous-testing mandate. It does, however, provide a clear supervisory signal that monitoring, vulnerability management, testing methodology, recovery planning, and governance should adapt to faster and more complex threats.

For financial-services leaders, the objective is not simply more testing. It is timely, risk-based evidence that the institution can identify material exposure, make controlled changes, contain disruption, and recover critical services before an accelerated threat becomes a wider operational-resilience event.

References

  1. European Supervisory Authorities. Joint Statement on ICT risks from frontier AI models, JC 2026 25, July 2026. https://www.eba.europa.eu/sites/default/files/2026-07/9c0d597c-79ff-482f-a3fe-d9ad66e96bac/JC%202026%2025_ESA%20Statement%20on%20frontier%20AI%20models_.pdf
  2. European Parliament and Council. Regulation (EU) 2022/2554, Digital Operational Resilience Act (DORA), Articles 24 to 26. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
  3. Financial Stability Board. FSB Chair’s letter to G20 Finance Ministers and Central Bank Governors, August 2026. https://www.fsb.org/2026/08/fsb-chairs-letter-to-g20-finance-ministers-and-central-bank-governors-august-2026/
  4. Financial Stability Board. FSB Chair warns of risks arising from frontier AI models, August 2026. https://www.fsb.org/2026/08/fsb-chair-warns-of-risks-arising-from-frontier-artificial-intelligence-ai-models/
  5. OpenAI. Astra safety and capability statement, September 2026. https://openai.com/index/astra-safety-and-capability-statement/
Ask the Vault
Ask me anything about the published blog posts.