Decoding the world of cybersecurity

· ·

EU supervisors flag external technology dependencies

Europe’s financial watchdogs have put non-EEA technology dependencies alongside cyber threats and emerging AI risks among the vulnerabilities requiring closer scrutiny across the EU financial system.

EU supervisors flag external technology dependencies
Summary
  • EU financial supervisors have identified external technology dependencies, cyber threats, and rapidly developing AI as vulnerabilities requiring continued monitoring.
  • Dependence on ICT providers and infrastructure outside the EEA could amplify disruption or geopolitical shocks across interconnected financial services.
  • The warning extends the operational-resilience pressure already placed on regulated firms through DORA from individual supplier controls towards systemic concentration and dependency.

Europe’s financial supervisors have warned that dependence on technology providers and infrastructure outside the European Economic Area could magnify the effects of cyber incidents, operational disruption, and geopolitical shocks across the financial system.

The European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority identified external dependencies and emerging technologies among the main vulnerabilities in their Autumn 2026 joint risk update. The assessment also covers private credit and wider market risks, but its cyber findings place ICT dependency firmly within the EU’s financial-stability discussion.

The supervisors said reliance on non-EU providers and infrastructure could amplify the consequences of geopolitical or operational disruption. ICT service providers outside the EEA were singled out as a particular concern, alongside cyber risks associated with increasingly capable AI models and longer-term developments such as quantum computing.

The assessment does not identify a particular provider or claim that outsourcing beyond Europe is inherently insecure. Instead, it points to the way concentration, geographic dependency, and interconnection can convert an incident at one supplier into a problem spanning multiple regulated organisations.

That distinction has become increasingly important since the Digital Operational Resilience Act, or DORA, brought ICT third-party risk into a common regulatory framework for much of the EU financial sector. DORA requires regulated entities to understand and govern technology dependencies rather than treating cloud, software, and outsourced services purely as procurement decisions.

Earlier this month, the EBA also finalised third-party risk guidelines focused on arrangements supporting critical or important functions. Cyber Insider has separately examined how European banking supervisors are tying AI and cyber risk to operational resilience, supplier oversight, exposed assets, and board accountability.

The latest joint assessment moves the issue beyond the resilience of individual firms. A bank or insurer may have credible controls over its own outsourcing arrangements while still sharing critical providers, platforms, or infrastructure with large parts of the sector. The resulting concentration can become difficult to diversify quickly when technology is deeply embedded in applications, identity systems, data processing, or network architecture.

AI introduces another layer to that dependency problem. Financial organisations increasingly consume AI through cloud services, embedded software, specialised model providers, and third-party platforms. The risk therefore encompasses not only malicious use of AI, but the operational and governance consequences of incorporating external AI systems into regulated processes.

The European supervisors are not arguing that the financial system is presently unstable. Their assessment says EU banks, insurers, and investment funds continue to show strong fundamentals despite geopolitical tension, volatile energy prices, natural catastrophes, cyber threats, and rapid technological change.

The recommendation is nevertheless for supervisors and market participants to strengthen crisis preparedness, resolution coordination, and monitoring of external dependencies. That increasingly turns supplier visibility into a resilience question extending beyond conventional due diligence: organisations need to understand which dependencies are genuinely substitutable, which are shared across the market, and which could become difficult to replace during a disruption.

For Europe’s financial sector, that places infrastructure location, service concentration, AI dependency, and the ability to recover from a supplier failure within the same operational-resilience picture. DORA created the regulatory structure for much of that work; the supervisors’ latest assessment shows why dependency itself is becoming a financial-system concern.

×