Brussels Did Not Write a Rule for AI Vendors. It Wrote Their Next Questionnaire.
By Jean-Hugues Migeon
The Joint Committee of the European Supervisory Authorities (ESA) published a statement on frontier AI models under DORA on 31 July, and it imposes no legal obligation whatsoever on the companies that build or supply those models. That is precisely why I, as a lawyer, think suppliers should read it.
The statement is addressed to regulated financial entities: banks, investment firms, asset managers, insurers. It takes the European Commission's EU Action Plan on Cybersecurity and Artificial Intelligence, published on 7 July, and translates it into supervisory expectations for how those entities should manage the ICT risks posed by frontier models. Nothing in it creates a duty for a model developer. And yet within two quarters it will change what developers get asked, because DORA does not regulate suppliers directly. It regulates their customers, then requires those customers to write the supplier's obligations into a contract.
The effect is simple:
The regulator tells the bank what it must prove.
The bank then asks the supplier to provide the proof.
Anyone who lived through cloud outsourcing supervision will recognise the mechanism. A regulator tells a bank what it must demonstrate. The bank cannot demonstrate it on its own, so the requirement reappears a few months later as a clause on incident notification, audit and inspection rights, subcontracting consent, data portability and exit, and cooperation with regulators. DORA already codifies that list. Where the financial entity determines that a service supports a critical or important function, the obligations become more stringent, including participation in threat-led penetration testing. The ESAs did not need to write a rule for AI providers. They wrote one for the counterparty holding the pen on the contract.
What the statement asks for sits under three headings, and the first is worth reading closely. Under prevention, financial entities are expected to maintain comprehensive, continuously updated inventories of all IT assets, and the statement clarifies that this includes AI and machine learning components, as well as infrastructure, applications, data repositories, and APIs. Detection covers scaling vulnerability discovery to match the threat, continuous monitoring rather than periodic sweeps, and red teaming augmented with AI tooling. Management covers resilience testing, disaster recovery, and adaptation of existing risk frameworks and governance structures to ensure accountability keeps pace with AI-assisted attacks and multi-system failures.
The key word is “continuous” The ESA statement focuses on three areas: prevention, detection and management.
Notice what "continuously updated" is doing in that first pillar. A quarterly spreadsheet does not satisfy it, nor does an inventory that lists applications but stops short of the models within them. If a bank's own asset register has to reach model level, the diligence it runs on its suppliers has to reach model level too. Goodwin's alert on the statement, published 6 August, sets out where the questions get more specific: governance of model development and deployment, resilience of supporting infrastructure, transparency about model limitations and failure modes, incident management and reporting, dependency on subcontractors and cloud infrastructure with pass-through of obligations, and business continuity arrangements. That is not a procurement questionnaire. It is an ICT risk function's diligence pack, and it arrives from a different part of the bank than the one that signs the order form.
The article numbers matter here, because that is where the pressure actually lands. Article 28 of DORA requires the financial entity to run documented due diligence before contracting and to maintain a Register of Information covering every ICT arrangement. Article 29 adds the concentration risk assessment. Article 30 dictates what the contract itself must contain in two tiers, with the heavier tier reserved for services that support a critical or important function. Supervisors have already identified Articles 28 to 30 as the main source of compliance gaps across the sector, with incomplete registers, missing criticality classifications and thin pre-contract evidence at the top of the list. A statement that raises the bar on frontier AI is landing on a control area the ESAs already consider weak.
Articles 28–30 are where DORA becomes real: due diligence, concentration risk and contractual obligations, and frontier AI is now raising the bar in exactly the areas supervisors already see as weak
Suppliers do have one real lever: proportionality. Article 4 of DORA requires financial entities to calibrate to their size, risk profile, and the nature, scale, and complexity of what they do. The ESAs restate it explicitly. A provider facing terms designed for a systemically important payment rail, pushed by a mid-sized manager onto a low-criticality service, has a defensible argument. But proportionality cuts both ways. If the service does sit under a critical or important function, the calibration argument evaporates, and the heavy obligations are simply the correct ones.
The scoping question is worth settling early because the definition will not settle on its own. The statement adopts the Action Plan's framing of frontier AI as the most advanced models available or under development, capable of a broad range of tasks that approach, reach or exceed the current state of the art. That is a moving target by construction, so the conversation with a financial customer about whether you are in scope is one you will have repeatedly rather than once. Building a commercial strategy on the argument that your model is not at the frontier seems like a weak position to me.
What strikes me most is how closely this rhymes with what happened in the United States this summer. Fannie Mae, which is not a regulator, gave itself the right to demand a full AI inventory from servicers without notice, and the effect on vendors was immediate. Here, the instrument is a supervisory statement rather than a lender letter, and the pressure still comes through a contract rather than enforcement. Two very different legal systems, the same conclusion: the institution deploying the model answers for it, and it will make its suppliers answer first.
That leaves a narrow and answerable operational question. When a bank's ICT risk team asks which models sit behind the service they buy from you, what those models depend on, who your subcontractors are, and how an incident would reach them, where does the answer come from? If it has to be assembled from three teams and a shared drive, the register is being reconstructed on demand rather than maintained, and the next request will cost exactly the same again. Anove's insAIght platform is built to keep that register standing between requests, with each system tied to the obligations that actually reach it, so a diligence pack is drawn rather than assembled.
None of this is enforcement, and it may never become enforcement. It does not need to be. The statement will do its work quietly, in the redlines on service agreements signed over the next two quarters, and suppliers waiting for a regulator to address them directly will find the terms were settled without them.
Sources
- Joint Committee of the European Supervisory Authorities, statement on frontier AI models (JC 2026 25), 31 July 2026.
- European Commission, EU Action Plan on Cybersecurity and Artificial Intelligence, 7 July 2026.
- Regulation (EU) 2022/2554 (DORA), in particular Article 4 on proportionality and Articles 28 to 30 on ICT third-party risk, concentration risk and key contractual provisions.
- Goodwin, Frontier AI and DORA: AI Service Providers to European Financial Entities Take Note, 6 August 2026.
- Fannie Mae Lender Letter LL-2026-04, covered in our own analysis of the US vendor liability shift, August 2026.
Learn more
- insAIght, Anove's AI governance and risk platform, for keeping an AI register and its evidence current between diligence requests.
- The Toughest AI Governance Demand of 2026 Did Not Come From a Regulator, on the same dynamic playing out through US contract counterparties.
- ExplAIn, our free tool for checking what an AI system actually discloses about itself.
If frontier AI sits anywhere in what you supply to an EU financial entity, or in what you buy from one of your own vendors, book a demo and we will walk through how insAIght holds the inventory, the mappings and the evidence in one place.