Within three days at the end of July 2026, the Monetary Authority of Singapore (MAS) and the three European Supervisory Authorities (ESAs) both concluded that frontier artificial intelligence is an information and communication technology (ICT) risk to be supervised through existing operational-resilience frameworks — not through a new AI rulebook. The United Kingdom’s Financial Conduct Authority (FCA) has reached the same position by a different route, and the practical consequence for firms is that AI governance evidence is now discoverable under regimes that already carry eight-figure penalties.
The Association of Banks in Singapore and MAS announced the AI-Driven Cyber and Technology Risk Taskforce (ACT) on July 29, 2026. The ESAs — the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) — published their joint statement on frontier AI models on July 31, 2026. Neither creates a new licence, a new permission, or a new reporting line. Both instead route frontier-AI risk into machinery that already exists: the Digital Operational Resilience Act (DORA) in the European Union, and MAS technology-risk supervision in Singapore. This analysis sets out what the two documents require, how four jurisdictions now diverge, why an operational-resilience framing raises rather than lowers firms’ exposure, and what remains contested.
Key facts
- July 29, 2026 — MAS and ABS announce the AI-Driven Cyber and Technology Risk Taskforce (ACT); members have been convening since May 2026 (Retail Banker International).
- July 31, 2026 — EBA, EIOPA and ESMA publish a joint statement on ICT risks from frontier AI models, calling for a cross-sectoral, risk-based and consistent supervisory approach (EBA).
- Three mitigation strategies — the ESAs frame expectations around prevention, detection and management, and specifically call for comprehensive IT asset inventories and secure-by-design principles.
- ACT membership — MAS, ABS, DBS, OCBC, UOB, Singapore Exchange (SGX), Network for Electronic Transfers (NETS) and Banking Computer Services (BCS).
- £48,650,000 — the combined FCA and Prudential Regulation Authority (PRA) penalty against TSB Bank plc on December 20, 2022 for operational risk management and outsourcing failures, the benchmark for what this category of failure costs (FCA).
- 36 hours — the US notification window for banking organisations after determining a computer-security notification incident, under the interagency rule effective May 1, 2022.
Methodology and sources
This analysis relies on primary supervisory publications issued between July 28 and August 4, 2026: the ESAs’ joint statement on frontier AI models and its accompanying EBA press release; the MAS and ABS media release establishing the ACT taskforce; and the FCA’s published position on AI supervision. Enforcement context draws on the FCA and PRA Final Notices against TSB Bank plc dated December 20, 2022, and the PRA’s April 2023 action against TSB’s former chief information officer. Jurisdictional scope is the EU, the UK, Singapore and the US. Where a regulator’s own document was unavailable at the time of writing — the MAS media release was intermittently unreachable — quotations are taken from trade press reproductions and are attributed accordingly. Figures for DORA oversight populations reflect the position as previously reported by The Industry Spread and should be re-verified against the ESAs’ current register before operational use.
What the ESAs actually said
The July 31 statement is not a consultation and it does not create binding technical standards. It is a supervisory expectation-setting document, and its significance lies in classification rather than in obligation.
The ESAs’ central claim is that frontier AI models materially change the ICT threat surface by compressing the interval between a vulnerability existing and that vulnerability being exploited at scale. Where a capable adversary previously needed time and skill to discover, weaponise and deploy an exploit, model-assisted tooling shortens each step. The supervisory conclusion the ESAs draw from this is deliberately unglamorous: firms should maintain comprehensive IT asset inventories, apply secure-by-design principles, and adjust ICT risk management processes, procedures and controls across three axes — prevention, detection and management.
An asset inventory is an odd headline recommendation for a document about frontier AI, and that oddity is the point. The ESAs are not asking firms to govern models. They are asking firms to know what they run, because an accelerated exploitation cycle punishes unknown assets disproportionately. A firm that cannot enumerate its estate cannot patch it inside the compressed window. This is a resilience argument, not an AI-ethics argument, and it lands on infrastructure teams rather than on model-risk committees.
The operative sentence for regulated firms is the one about supervision. The ESAs stated that ongoing and planned oversight activities under DORA involving critical ICT third-party providers (CTPPs) will increasingly address risks associated with frontier AI models. That folds frontier AI into a designation regime that already exists, with an oversight population The Industry Spread has tracked as DORA’s 19-provider oversight regime. No new designation round is required for the scope to expand.
How four jurisdictions now compare
| Jurisdiction / regulator | Instrument and date | Scope | Key requirement | Penalty exposure |
|---|---|---|---|---|
| EU (EBA, EIOPA, ESMA under DORA) | Joint ESA statement, July 31, 2026 | Financial entities in scope of DORA, plus designated CTPPs | Adjust ICT risk management across prevention, detection, management; maintain IT asset inventories; secure-by-design | DORA national penalties plus CTPP oversight remediation; periodic penalty payments up to 1% of average daily worldwide turnover |
| UK (FCA and PRA) | Existing regimes; AI Input Zone closed June 19, 2026 | Authorised firms; senior managers individually | Evidence, not policy: governance, resilience, oversight, assurance, deployment controls, consumer outcomes | £48.65m combined FCA/PRA precedent (TSB, December 20, 2022); individual SM&CR penalties |
| Singapore (MAS and ABS) | ACT taskforce announced July 29, 2026 | Banks, SGX, NETS, BCS in the first instance | Use-case sharing, proof-of-concept trials of AI-enabled defence, then published guidance | No new penalty; MAS technology risk supervision unchanged pending guidance |
| US (OCC, Federal Reserve, FDIC) | Computer-security incident notification rule, effective May 1, 2022 | Banking organisations and bank service providers | Notify the primary federal regulator within 36 hours of determining a notification incident | Enforcement under existing safety-and-soundness authority; no AI-specific tier |
Sources: EBA, FCA, MAS/ABS and US interagency rule as cited throughout. Position as at August 9, 2026.
Three of the four converge on substance and diverge sharply on enforceability. The EU has the hardest edge, because DORA supplies both a designation mechanism and a penalty schedule that the ESAs can point frontier-AI expectations at without new legislation. The UK has the sharpest evidentiary demand but the least novel machinery — the FCA has explicitly declined to build a separate AI rulebook, and is instead testing whether the Consumer Duty, the Senior Managers and Certification Regime (SM&CR), operational resilience requirements and the Critical Third Parties regime already reach AI-enabled firms. Singapore has the most collaborative posture and, for now, the least binding one: ACT produces guidance, not rules.
The US is the outlier, and the gap is structural rather than deliberate. There is no US federal financial-sector frontier-AI ICT instrument. The closest analogue is the 36-hour notification duty, and as The Industry Spread reported when bank regulators gave themselves 72 hours while banks get 36, the asymmetry in that rule is already contested on its own terms. A firm operating across all four jurisdictions therefore faces one substantive standard and four different consequences for missing it — the classic precondition for supervisory arbitrage, except that here the arbitrage runs in the wrong direction. Group-wide ICT controls are typically built once, to the strictest applicable standard, because fragmenting them by entity is more expensive than complying.
Why the operational-resilience framing raises exposure
The instinctive industry reading of “no new AI rulebook” is that the compliance burden is lighter than feared. That reading is wrong, and the reason is evidentiary.
A dedicated AI regime would have arrived with a defined perimeter, a phase-in and, most usefully, a set of safe harbours. Routing frontier-AI risk through operational resilience removes all three. There is no perimeter, because any model touching a critical or important function is in scope by function rather than by label. There is no phase-in, because DORA and the UK operational-resilience rules are already in force. And there are no safe harbours, because the standard is outcome-based: the system either remained secure, resilient and under control, or it did not.
Colin Payne, head of Innovation at the FCA, has framed the regulator’s demand in three words: “Not theory. Evidence,” as reported by QA Financial. The FCA is seeking specific examples spanning governance, resilience, oversight, assurance, deployment controls and consumer outcomes — not attestations that a policy exists. That is a materially harder standard to meet than a documentary one, and it applies retrospectively to deployments already running.
The MAS framing is more cooperative but points the same way. “Through this Taskforce, MAS will work closely with industry partners to strengthen our collective defences and ensure Singapore’s financial sector remains resilient against AI-enabled risks,” said Vincent Loy, Assistant Managing Director (Technology) and Chief Technology Officer at MAS, in the taskforce announcement. Ong-Ang Ai Boon, Director of the Association of Banks in Singapore, added that the sector “remains vigilant, agile and committed to strengthening cyber and technology resilience in the face of evolving AI-related risks and emerging technologies.” Guidance produced by a taskforce whose members include the three largest local banks and the exchange will function as a supervisory baseline long before it is formally binding.
Enforcement context: what this category of failure costs
Because frontier-AI risk is being supervised as operational resilience, the relevant enforcement precedent is operational resilience — and the benchmark is TSB.
On December 20, 2022, the FCA and the PRA fined TSB Bank plc £48,650,000 for operational risk management and governance failures relating to its 2018 IT migration, split as an FCA penalty of £29.75 million and a PRA penalty of £18.9 million. The bank qualified for a 30% settlement discount; without it the combined figure would have been £69.5 million. The migration moved customer data to a platform provided by Sabadell; the data transfer succeeded but the platform failed, disrupting branch, telephone, online and mobile services for a significant proportion of TSB’s 5.2 million customers, with normal service not restored until December 2018.
Two features of that case make it the right lens for frontier AI. First, the regulators’ finding was not that the technology was defective but that TSB failed to organise and control the programme adequately and failed to manage the operational risks arising from outsourcing to a critical third-party supplier — precisely the two failure modes the ESAs now flag for AI-enabled estates and CTPP dependency. Second, liability did not stop at the entity: the PRA separately fined TSB’s former chief information officer in April 2023 for breaching senior-manager conduct rules. Under an operational-resilience framing, an AI deployment that degrades a critical function is a senior-manager problem as well as a firm one.
What this means for brokers, exchanges, CASPs and compliance teams
Brokers and futures commission merchants. Order-routing, best-execution monitoring and surveillance tooling increasingly embeds vendor models. Under DORA, the relevant question is not whether the model is “AI” but whether the vendor supports a critical or important function and appears in the register of information. Firms should expect CTPP oversight questions to reach model provenance, update cadence and rollback capability.
Exchanges and market infrastructure. SGX’s inclusion in ACT is a signal that infrastructure operators will be asked to demonstrate AI-enabled defensive capability, not merely defend against AI-enabled attack. Proof-of-concept trials conducted under the taskforce will become the reference standard for what “reasonable” looked like in 2026.
Crypto-asset service providers. CASPs authorised under the Markets in Crypto-Assets Regulation (MiCA) are in DORA scope, and their ICT estates are typically younger and more vendor-dependent than incumbent banks’. The asset-inventory expectation is the immediate gap for most.
Legal and compliance. The practical work is evidentiary, not policy drafting. Firms need dated artefacts — test results, monitoring output, incident post-mortems, deployment approvals — that show controls operating, not existing. Anything produced now to satisfy the FCA’s evidence request is also discoverable in an operational-resilience enforcement action later.
Forward view: what remains contested
Three questions are genuinely open.
The first is whether the ESAs’ statement acquires teeth through DORA technical standards or remains supervisory expectation. Extending CTPP oversight to frontier-AI risk without a new designation round is legally economical, but it also means the scope expands by supervisory practice rather than by rulemaking — a route that invites challenge from designated providers.
The second is the interaction with the EU AI Act. The Act regulates AI by risk classification and use case; the ESAs regulate the same systems by function and resilience. Firms will be supervised under both, and the timelines no longer align — as we reported, the AI Act omnibus delay spared credit-scoring AI while August 2026 duties remained. A model can be low-risk under the Act and critical under DORA.
The third is the US gap. Supervisory convergence among the EU, UK and Singapore without a US counterpart is unstable for globally active firms, and the resolution is more likely to arrive through third-party risk guidance than through AI-specific rulemaking. Until it does, the operative standard for a US-headquartered group with EU operations is the European one — which, as with DORA’s third-party oversight split across the EU, UK and US, is how extraterritorial reach usually arrives: not by assertion, but by being the strictest rule in the group.
TL;DR
MAS launched the ACT taskforce on July 29, 2026 and the EBA, EIOPA and ESMA issued a joint statement on frontier-AI ICT risk on July 31, 2026. Neither creates new AI-specific obligations; both route frontier-AI risk into existing operational-resilience supervision, and the ESAs confirmed DORA oversight of critical ICT third-party providers will increasingly cover it. The UK reaches the same place through the FCA’s demand for evidence rather than policy. That framing increases rather than reduces exposure, because operational resilience carries no safe harbour and real penalties: the FCA and PRA fined TSB Bank plc £48,650,000 in December 2022 for exactly this class of failure, and separately sanctioned its former chief information officer. The US has no equivalent instrument beyond a 36-hour incident notification duty.
FAQ
Does the ESA statement create new legal obligations?
No. It is a supervisory expectation-setting statement, not a regulation or binding technical standard. Its force comes from routing frontier-AI risk into DORA, which is already in effect and already carries penalties. Firms gain no new permissions to seek and no new filings to make, but their existing ICT risk management is now expected to address frontier-AI-accelerated threats explicitly.
Why do regulators emphasise IT asset inventories rather than model governance?
Because the supervisory concern is the compressed interval between vulnerability and exploitation. Model-assisted tooling shortens discovery and weaponisation, so the patching window narrows. A firm that cannot enumerate its estate cannot remediate inside that window, which makes inventory completeness a resilience control rather than a documentation exercise.
Is the ACT taskforce binding on Singapore firms?
Not currently. ACT is an industry initiative co-led by MAS and the Association of Banks in Singapore, producing use-case sharing, proof-of-concept trials and eventually practical guidance. Because its members include DBS, OCBC, UOB and SGX, the guidance it produces is likely to be treated as the supervisory baseline before it acquires formal status.
What penalty exposure does an AI-related resilience failure carry in the UK?
There is no AI-specific tariff. Exposure runs through existing operational resilience and outsourcing requirements, where the benchmark is the £48,650,000 combined FCA and PRA penalty against TSB Bank plc on December 20, 2022. Individual senior managers face separate exposure under the SM&CR, as the PRA’s April 2023 action against TSB’s former chief information officer demonstrates.
How does this interact with the EU AI Act?
They classify differently and apply in parallel. The AI Act regulates by use case and risk tier; DORA and the ESA statement regulate by function and operational resilience. A system can sit outside the AI Act’s high-risk tier while supporting a critical or important function under DORA, in which case the resilience obligations bind regardless of the Act’s classification.
What should firms do first?
Complete and date the IT asset inventory, including embedded vendor models, then map which assets support critical or important functions. That single artefact answers the ESAs’ primary recommendation, feeds the DORA register of information, and forms the evidence base the FCA is asking for.
This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.