ESAs call for faster cyber resilience as frontier AI reshapes ICT risk
The European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement urging financial institutions to strengthen their cyber resilience in response to the growing risks posed by frontier artificial intelligence models. While recognising AI's significant benefits for cybersecurity, the ESAs warn that increasingly capable AI systems can also enable malicious actors to identify vulnerabilities, exploit shared infrastructure and launch attacks at unprecedented speed, potentially creating systemic risks for the financial sector. The statement builds on the European Commission's recent Action Plan on Cybersecurity and Artificial Intelligence and complements existing warnings from the European Systemic Risk Board (ESRB) and ENISA.
Rather than proposing new regulatory requirements, the ESAs stress that the existing frameworks under DORA and the AI Act already provide a solid basis for managing these risks. Instead, supervisors encourage financial entities to act proactively by adapting their ICT risk management frameworks to reflect the faster pace of AI-enabled cyber threats. Any measures should remain proportionate, considering an institution's size, business model and overall risk profile.
The statement identifies three priority areas for action. First, financial entities should strengthen prevention by maintaining comprehensive ICT asset inventories, embedding security-by-design principles, improving patch management and reducing vulnerabilities across supply chains. Second, they should enhance detection through continuous monitoring, more frequent vulnerability scanning and stronger behavioural analytics capable of identifying AI-assisted attacks. Finally, institutions should reinforce operational resilience by updating governance arrangements, incident response plans, business continuity frameworks and resilience testing to reflect AI-driven cyber scenarios, while ensuring management bodies remain actively engaged in overseeing these evolving risks.
What it means for CEE markets
The statement is particularly relevant for financial institutions across Central and Eastern Europe as they continue implementing DORA and expanding their use of AI-enabled technologies. Although the ESAs do not introduce new compliance obligations, the document signals the direction of future supervisory expectations by encouraging firms to review whether existing ICT risk management, cyber resilience and governance arrangements remain adequate in an AI-driven threat environment.
For many CEE financial institutions, particularly smaller banks, insurers and pension providers with limited cybersecurity resources, the emphasis on proportionate but more dynamic risk management is likely to accelerate investment in continuous monitoring, vulnerability management and operational resilience capabilities. The statement also highlights that supervisors are increasingly viewing frontier AI as a cross-sector operational resilience issue, suggesting that institutions should expect greater scrutiny of AI-related cyber risks as DORA implementation matures and supervisory practices become more consistent across the EU.
EBA ESG dashboard shows stable climate risk exposures and improving data quality
The European Banking Authority (EBA) published its latest ESG Risk Dashboard, providing an overview of climate-related risks in the EU/EEA banking sector based on banks' disclosures for the second half of 2025. Overall, the findings point to a relatively stable climate-risk profile. Banks' exposures to sectors highly contributing to climate change remained broadly unchanged at 62% of total corporate exposures, while physical climate-risk indicators also showed little change compared with the first half of the year.
At the same time, the dashboard highlights an important structural improvement: the quality of climate-related data continues to increase. Banks reported a further decline in mortgage exposures without energy performance information, together with a reduction in estimated energy performance scores. Although these changes may appear incremental, they improve the reliability of climate-risk assessments and strengthen banks' ability to integrate environmental risks into lending, portfolio management and supervisory reporting.
What it means for CEE markets
One of the most relevant findings for Central and Eastern Europe is the relatively wide dispersion of physical climate-risk exposures across banks. While the regional median remains broadly comparable to other parts of Europe, CEE displays substantially greater variation between institutions than Western and Northern Europe.

Figure 1. Share of exposures sensitive to physical climate risk – Total (dispersion across banks, by region). Source: European Banking Authority (EBA), ESG Risk Dashboard, published 6 August 2026 (based on December 2025 ESG disclosure data).
This illustrates that climate-related risks cannot be viewed as a single regional phenomenon; banks' exposure profiles continue to depend heavily on geography, economic structure, sectoral lending patterns and portfolio composition.
For investors and supervisors, this underlines the importance of institution-specific rather than country-level analysis. Banks operating in markets with higher exposure to floods, droughts or other physical climate hazards will face different risk-management challenges from peers whose portfolios are concentrated in less climate-sensitive sectors or regions.

Figure 2. Share of mortgage exposures across energy-efficiency categories by country. Source: European Banking Authority (EBA), ESG Risk Dashboard, published 6 August 2026 (based on December 2025 ESG disclosure data).
The dashboard also demonstrates that climate-risk management is becoming increasingly data-driven. Across the EU/EEA, banks continue to improve the availability of energy-performance information for residential mortgage portfolios, reducing reliance on estimated energy ratings. Better-quality data allow banks to assess transition risks more accurately, improve internal risk models and respond more effectively to evolving supervisory expectations.
For Central and Eastern Europe, this development may prove just as significant as changes in underlying climate-risk exposures. As ESG disclosures mature, banks with stronger data governance, more complete energy-performance information and better climate-risk capabilities are likely to be better positioned to meet supervisory expectations, attract sustainable investment and strengthen their long-term competitiveness.
Looking ahead, the dashboard suggests that climate risk is becoming an increasingly integrated component of prudential supervision rather than a standalone sustainability exercise. For CEE banks, competitive advantage will depend not only on reducing climate-related exposures over time, but also on demonstrating robust governance, reliable data and effective climate-risk management as supervisory scrutiny continues to increase.
Digital Omnibus: Parliament begins shaping the next phase of EU digital simplification
The European Parliament has started substantive discussions on the Digital Omnibus proposal, marking the beginning of the legislative phase that will determine how far the EU is prepared to simplify its digital rulebook without weakening existing protections. While the first batches of amendments have now been published, they cover only a limited part of the proposal - primarily the new Single-Entry Point (SEP) for incident reporting. Broader political compromises on GDPR, the Data Act, ePrivacy, cookies, data access and AI-related provisions are expected to emerge after the summer as negotiations intensify.
The initial parliamentary debate suggests broad agreement on the overall objective of reducing unnecessary administrative burdens and improving Europe's digital competitiveness. However, MEPs remain divided over how simplification should be achieved. Centre-right groups favour a more risk-based approach to GDPR implementation, greater legal certainty for businesses and improved access to data for innovation and AI development. Centre-left, Greens and other groups broadly support simplification but oppose reopening core principles of the GDPR, weakening data-subject rights or removing existing safeguards for consumers and SMEs. Several political groups have also questioned the Commission's decision to reopen politically sensitive legislation without a full impact assessment.
The first published amendments illustrate this emerging direction of travel. Most focus on redesigning the proposed Single-Entry Point for cybersecurity incident reporting rather than rejecting simplification itself. Several amendments seek to replace a centrally managed EU reporting portal with interoperable national reporting hubs connected through common technical standards. Others propose harmonised reporting templates, aligned reporting deadlines and stronger interoperability between NIS2, DORA, the Cyber Resilience Act, GDPR and other reporting frameworks. While approaches differ, the common objective is to reduce duplicate reporting obligations while preserving Member States' supervisory responsibilities.
What it means for CEE markets
For Central and Eastern Europe, the Digital Omnibus is becoming less about deregulation and more about regulatory efficiency. Many financial institutions, telecom operators, manufacturers and digital businesses across the region must already comply simultaneously with GDPR, DORA, NIS2, the AI Act and sector-specific reporting obligations. If Parliament ultimately delivers more harmonised reporting templates, aligned reporting timelines and interoperable reporting systems, compliance costs could fall without materially reducing supervisory oversight.
The debate also highlights a broader strategic trend. Rather than fundamentally rewriting the EU's digital rulebook, Parliament appears to be searching for targeted simplifications that preserve legal certainty while making existing legislation easier to implement. This approach is particularly relevant for CEE economies, where many companies operate with smaller compliance teams and more limited administrative resources than larger Western European firms. Simplification that genuinely reduces duplication could therefore improve competitiveness while allowing businesses to focus more resources on investment, innovation and digital transformation.
Looking ahead, the most politically sensitive negotiations are still to come. Parliament is expected to publish additional compromise amendments after the summer covering GDPR, pseudonymisation, cookie rules, data access, AI-related processing and the future architecture of the EU data framework. These discussions will provide a much clearer indication of whether the Digital Omnibus remains a targeted simplification exercise or evolves into a broader reconsideration of Europe's digital regulatory framework.
Irish Presidency pushes MISP towards October Council agreement
The Irish Presidency is accelerating work on the Market Integration and Supervision Package (MISP), with the objective of securing a Council general approach by October 2026. Following discussions at the July ECOFIN meeting, technical negotiations are expected to intensify over the coming months as Member States seek compromises on the package's most politically sensitive elements. While there is broad support for deeper and more integrated EU capital markets, significant differences remain over how supervisory responsibilities should be divided between the European Securities and Markets Authority (ESMA), national competent authorities (NCAs) and central banks.
The main outstanding issues closely mirror the debates emerging in the European Parliament. These include the scope of ESMA's direct supervision over large cross-border asset managers, trading venues and market infrastructures, the governance of ESMA's proposed Executive Board, the criteria for determining which entities should fall under direct EU supervision, and the respective roles of ESMA, national supervisors and central banks. Although political positions differ, the emerging direction suggests that negotiations are converging around a compromise combining stronger supervisory convergence with targeted EU-level supervision of the most systemic entities, while preserving a significant role for national authorities.
What it means for CEE markets
For Central and Eastern Europe, the outcome of the MISP negotiations will be particularly significant. Most CEE capital markets remain smaller and less integrated than those of Western Europe, with national supervisors continuing to play a central role in overseeing domestic financial institutions and market infrastructures. Any transfer of supervisory responsibilities to ESMA will therefore need to balance the objective of greater market integration with the importance of preserving local market expertise and ensuring proportionate supervision.
At the same time, deeper supervisory convergence could make CEE markets more attractive to international investors by reducing regulatory fragmentation and improving confidence in cross-border investment. However, supervisory reform alone will not create a genuine Savings and Investments Union. As several parliamentary amendments also recognise, achieving deeper capital markets will require parallel progress on broader structural barriers, including insolvency frameworks, company law, securities law and investor protection.
The coming months are therefore likely to determine not only the future architecture of EU financial supervision but also the pace at which Central and Eastern European capital markets become more closely integrated into the wider European financial system.



