Global Trustee and Fiduciary Services Bite-Sized Issue 8 2026

11 AIFMD CRYPTOASSETS EMIR FINTECH IOSCO MIFID II/MIFIR OPERATIONAL RESILIENCE SUSTAINABLE FINANCE/ESG T+1 ASIA PACIFIC EUROPE NORTH AMERICA UNITED KINGDOM Global Trustee and Fiduciary Services Bite-Sized | Issue 8 | 2026 Quick Links • Adopting AI for defence; and • Testing cybersecurity defences and incident response plans. Link to CSSF Communique here FSC: ‘AI Models Increase the Urgency of Cyber Resilience’ On 7 July 2026, the Dutch Authority for the Financial Markets (AFM) published details of the Dutch Financial Stability Committee (FSC) meeting of 26 June 2026, that discussed that advanced AI models are profoundly changing the cyber threat landscape. In its report, the FSC stresses that financial institutions must adapt their cyber resilience accordingly and calls for stronger coordination and better information exchange, nationally, across Europe, and across sectoral boundaries. The report states that risks to financial stability remain high due to cyber threats, geopolitical uncertainty, vulnerabilities in financial markets and concerns about the sustainability of public finances in the euro area and beyond. In addition to cyber resilience, the FSC also discussed the rapid growth of private credit. It says that it is important to follow this development closely and to collect better data on it, and also to better understand interconnectedness with other parts of the financial sector. The report summarises the discussions on: • Advanced AI models call for strengthening cyber resilience; • Maintaining resilience remains essential; and • More insight needed on private credit. Link to the Report (In Dutch) here Frontier AI Models Could Strain Cyber Resilience in the Financial System, ESRBWarns On 7 July 2026, the European Systemic Risk Board (ESRB) published a warning on systemic cyber risks stemming from frontier AI models (FAIMs). This warning comes after the ESRB General Board assessed systemic cyber risk as “severe” in June, up from “elevated” in March. The ESRBwarning explains how thesemodels are reshaping the cyber threat landscape, assesses the resulting systemic risks and outlines implications for public authorities and private financial institutions. The ESRB says FAIMs are a paradigm shift for cybersecurity. Eventually, these models are likely to strengthen cyber resilience. In the short to medium term, however, they provide an advantage to threat actors, enabling them to discover vulnerabilities and execute cyberattacks with increased speed, scale and sophistication. In addition, the concentration of leading AI providers outside the European Union (EU) exposes it to strategic dependency and geopolitical risks. The ESRB says, that as AI technology proliferates, it is important to ensure that all critical infrastructure and especially financial institutions are prepared to face cyber-attacks powered by FAIMs, and make timely and appropriate preparations. The ESRB also says that defensive efforts by single entities would be insufficient, and a more effective response and risk mitigation would require a coordinated answer involving all affected parties including AI providers, software providers, security firms, open-source maintainers, financial institutions, and authorities at both national and EU level. Reflecting this, the ESRB says it welcomes the letter to CEOs of significant euro area banks from ECB Banking Supervision, also published on 7 July. The letter sets out supervisory expectations for addressing the evolving AI-related cyber threat landscape. The ESRB says it will continue to monitor the use and development of FAIMs with cyber capability and their impact on the financial sector from a systemic risk perspective. The ESRB General Board will reassess such developments in its quarterly risk assessments and consider further appropriate action in its remit when needed. The ESRB General Board also approved the publication of a note entitled “Addressing Frontier AI Models with cyber capabilities from a financial stability perspective” . This note provides further analysis of the risks identified.

RkJQdWJsaXNoZXIy MTM5MzQ2Mw==