The ESAs’ frontier AI governance statement — JC 2026 25, published 31 July 2026 — does not ask insurers to wait and see. The EBA, EIOPA and ESMA warn that the advanced capabilities of recent frontier AI models significantly accelerate cyber risks, and they want that acceleration reflected in documents insurers already own: the risk appetite framework, the ICT third-party register, the board’s risk tolerance thresholds. Compliance and risk teams now have a checklist, not just a warning.
DORA was already the answer, the ESAs say
The statement’s framing is deliberate. Rather than propose new rules, the ESAs’ joint statement on frontier AI models points back to the regulation already on insurers’ desks. DORA and the AI Act provide, in the ESAs’ words, the foundation for tackling risk from highly capable AI models, and the three authorities are explicit that the ICT risk management framework, testing, incident and recovery management, and ICT third-party risk management requirements already set out in DORA remain the core levers. That framing did not appear from nowhere: the statement follows the European Commission’s 7 July 2026 Action Plan on Cybersecurity and Artificial Intelligence, and it leans on Regulation (EU) 2022/2554, dated 14 December 2022, for its legal authority. For providers of general-purpose AI models with systemic risk under the AI Act, the ESAs note added obligations on transparency, technical documentation and cybersecurity — obligations insurers will increasingly ask their model vendors to evidence during due diligence. For compliance officers, the practical upshot is that no new legal basis needs to be invented before Monday morning: the instruments already sit in the contract templates, the outsourcing registers and the incident-reporting workflows built for DORA. What changes is the level of scrutiny applied to how thoroughly those instruments are actually used when the third party in question is an AI model provider rather than a conventional cloud host.
What belongs in a risk appetite framework now
Boards cannot outsource this to IT. The ESAs are direct: the Risk Appetite Framework should be reviewed to update and/or incorporate metrics, tolerance thresholds and control measures consistent with the evolving risk profile that frontier AI introduces. In practice, that means naming AI-driven dependencies as a distinct risk category rather than folding them into generic cyber risk, and setting thresholds a board can actually monitor quarter to quarter. The statement also grounds proportionality directly in law: under DORA Article 4, entities must size their mitigation strategies to their scale, interconnectedness and complexity rather than copy a single template. Around that proportionality test, the ESAs organise expectations into three risk mitigation strategies — prevention, detection and management, which gives compliance teams a structure to map existing controls against, rather than starting a gap analysis from a blank page. It is, as InsuraBeat noted when the ESAs first endorsed the ESRB’s frontier-AI warning, a shift from acknowledging systemic risk to acting on it. Audit committees should expect the next line of questioning from supervisors to be procedural rather than theoretical: not whether the board has heard of frontier AI, but which named model dependency triggered the last threshold review and what control was tightened as a result.
Why the Lead Overseer role is where this bites
The sharpest edge of the statement is not aimed at insurers directly — it is aimed at the vendors insurers depend on. Acting in their capacity as Lead Overseers, the ESAs have initiated targeted engagement with relevant critical ICT third-party providers (CTPPs) to understand how those providers identify and manage the new challenges they face. That engagement is not a one-off letter. The ESAs say they have begun embedding AI-related risks into their Oversight Examination Methodology and will continue to strengthen this work throughout 2027, which means the CTPP oversight architecture insurers already feed data into — via the register of information on contractual arrangements with ICT third-party service providers that DORA’s Implementing Technical Standards require entities to maintain and update — becomes the channel through which frontier-AI dependency gets mapped across the sector. Insurers who treated that register as a compliance formality after the ESAs’ first DORA ICT-incident baseline should expect it to carry more supervisory weight from here, not less. Technical standards the ESAs published under DORA — the Regulatory Technical Standards on the ICT risk management framework, adopted under DORA Articles 15, 16(3), 18(3), 28(9) and 28(10), published 17 January 2024 — are the mechanics behind that register, harmonising the tools, methods, processes and policies supervisors now expect firms to route AI risk assessment through.
A concentration problem the register can’t hide
None of this exists in a vacuum. The oversight push traces back to a concentration problem the ESAs did not invent: frontier AI models are currently developed by only a small number of AI providers, several of whom have themselves flagged that upcoming models may be too powerful for unrestricted public access. When a handful of firms supply the frontier models sitting behind insurers’ underwriting, claims and fraud-detection tools, a single provider’s outage or model failure can propagate across the sector faster than a conventional IT incident. That is precisely why the AI Act’s regime for general-purpose AI models with systemic risk and DORA’s third-party oversight machinery are being pointed at the same handful of names. It also explains why the CTPP register matters more than a paperwork exercise: it is how supervisors will see concentration building before it becomes a market-wide event, echoing what EIOPA’s own oversight report signalled about tougher supervisory convergence even before frontier AI entered the picture. For risk teams, the practical takeaway is to stop treating the third-party register as a static inventory and start treating it as the document that will surface, provider by provider, exactly where the sector’s AI dependency is concentrated.