Global Trustee and Fiduciary Services Bite-Sized Issue 8 2026
10 AIFMD CRYPTOASSETS EMIR FINTECH IOSCO MIFID II/MIFIR OPERATIONAL RESILIENCE SUSTAINABLE FINANCE/ESG T+1 ASIA PACIFIC EUROPE NORTH AMERICA UNITED KINGDOM Global Trustee and Fiduciary Services Bite-Sized | Issue 8 | 2026 Quick Links NCA exercise to run: second half 2026 to first half 2027 Consolidated final report due: Second half 2027 Link to Announcement here CSSF – Evolving Opportunities and Risks in AI and its Adoption On 7 July 2026, Luxembourg’s Commission de Surveillance du Secteur Financier (CSSF) published a Communiqué discussing recent advances in the capabilities of frontier Artificial Intelligence (AI) models across a wide range of domains. The CSSF says that, while these technologies offer significant opportunities, they also introduce new cybersecurity challenges. The ability of frontier AI models to process vast amounts of information, generate sophisticated code, or automate complex workflows can be leveraged by a growing number of malicious actors to increase the scale, speed, and effectiveness of cyberattacks. As such, traditional cybersecurity measures such as vulnerability and patch management show serious limitations in the current evolving cyber threat landscape augmented with frontier AI models capacities. The CSSF says its observations of the security measures in place at many financial institutions suggest that, in most cases, vulnerability scans are not sufficiently frequent, and fixes come often too late. Furthermore, the CSSF says it has noted that a considerable number of supervised entities do not review the safeguards for ensuring the security of networks as frequently as required and lack automated and frequent reviews of secure configuration baselines. In this context, the CSSF invites supervised entities to carefully review the following publications by the European Systemic Risk Board (ESRB) and the Financial Stability Board (FSB) on AI: • ESRB’s warning on systemic cyber risks stemming from frontier AI models, published on 7July 2026 (Frontier AI models could strain cyber resilience in the financial system, ESRB warns) . • FSB’s consultation on sound practices for responsible adoption of AI, published on 10 June 2026 with comments due by 22 July (Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report – Financial Stability Board) The CSSF says that, considering this rapidly evolving cyber risk environment driven by frontier AI models and in linewith the InformationandCommunications Technology riskmanagement requirements set out inDORAor other relevant national regulations, itwould like to clarify that it expects financial institutions’ management body to establish governance structures that support effective management of frontier AI related risk, and in particular to closely monitor this risk and to support, to the best possible, the strengthening of your organization’s resilience against AI-enabled threats. The CSSF says, for a better efficient use of scarce cybersecurity resources and budget, it recommends a balance of cybersecurity efforts, not putting all the efforts in high-frequency patching only, but adopting a more holistic approach, covering the traditional cybersecurity functions: identify, protect, detect, respond and recover. The CSSF encourages firms to liaise with their peers, industry associations and cybersecurity experts and when defining the content and coverage of a financial institution’s action plan to better face the new wave of AI-augmented cyberattacks, consider, notably, the measures and pieces of advice listed in the communiqué covering: • Reducing the attack surface; • Prioritising secure patch management by exposure and exploitability, not theoretical severity; • Securing the software development pipeline; • Engineering for containment to reduce the blast radius; • Proactive Threat Hunting; • “No-Patch” Responses;
Made with FlippingBook
RkJQdWJsaXNoZXIy MTM5MzQ2Mw==