Technology & Cyber regulatory updates from European Union.
We track 62 Technology & Cyber updates from European Union regulators, published by ECB, ESMA and EBA. The archive covers 50 news items, 6 speeches and 4 consultations. Most recent update: September 2026. Coverage runs from 2025 to 2026.
ESAs call for vigilance over external dependencies, cyber threats and private credit risks 23 September 2026 Joint Committee Risk monitoring The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for…
Why this matters
This is an autumn 2026 joint risk and vulnerabilities report from the ESAs presented to the EU's Financial Stability Table. It identifies material systemic risks (non-EEA ICT dependencies, AI-enabled cyber threats, private credit growth) and explicitly calls on supervisors and market participants to strengthen crisis...
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for the EU financial system in their Autumn 2026 risk update.
Why this matters
This is an Autumn 2026 risk update and press release from the three ESAs (EBA, EIOPA, ESMA) presenting findings on systemic vulnerabilities. The content is informational and advisory in nature—calling for vigilance and preparedness rather than imposing new rules or enforcement actions.
This is a substantive policy speech by a senior ECB official addressing digital innovation's impact on bank business models and financial stability. It signals supervisory priorities (data aggregation remediation, AI governance, cyber resilience, quantum-resistant cryptography, outsourcing dependencies) and describes...
Ongoing geopolitical and economic vulnerabilities masked by strong investor optimism 10 September 2026 Press Releases Risk monitoring The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its second risk monitoring report of 2026 , setting out the…
Why this matters
This is ESMA's H1 2026 financial stability report identifying key market vulnerabilities and structural developments. It contains noteworthy regulatory signals on valuation risks, infrastructure resilience, cyber/AI operational risks, and crypto-financial system linkages affecting multiple firm types across capital...
ESMA to host Data Day 2026: ‘Data in the Savings and Investment Union – from burden to opportunity’ 04 September 2026 Market data Technology, use of data and simplification of reporting requirements will be at the centre of the European Securities and Markets Authority (ESMA) Data Day 2026 , taking place on 24…
Why this matters
The content is a news announcement about ESMA's Data Day 2026 event. It describes the event's purpose (discussing supervisory reporting, regulatory disclosures, and data integration) and agenda topics (simplification, financial transaction reporting, ESAP, crypto-asset monitoring).
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector 31 July 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for…
Why this matters
This is a regulatory guidance statement from ESAs addressing AI-related cybersecurity risks across the EU financial sector. It provides supervisory expectations and governance recommendations for managing frontier AI model risks, applicable to all financial entities.
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.
AI Analysis
On 2026-07-31, the European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement calling for a cross-sectoral, risk-based and consistent supervisory approach to address ICT and cyber risks arising from frontier AI models in the EU financial sector. The statement does not introduce new binding rules but signals how supervisors expect existing frameworks, particularly under DORA and related ICT risk regulations, to be applied to frontier AI use cases.
Key dates
2026-07-31
Joint ESA statement on ICT risks from frontier AI models in the EU financial sector published
Suggested considerations
Compliance teams may wish to map existing and planned uses of frontier AI models (including large language models and other advanced generative or predictive systems) to current ICT risk and cyber resilience frameworks under Regulation (EU) 2022/2554 (DORA) to demonstrate that these models are covered by documented risk assessments, controls and monitoring.
Firms should consider reviewing governance arrangements for frontier AI, including board and senior management oversight, clear accountability, and integration of AI-related ICT risks into the firm’s risk appetite, risk taxonomy and operational risk frameworks, with specific escalation and reporting lines.
Risk and technology functions may wish to update ICT and cyber risk management policies to explicitly address frontier AI threats (e.g. prompt injection, model poisoning, data leakage, adversarial attacks) and to align detection, logging and incident response capabilities with the ESAs’ emphasis on prevention, detection and management of AI-related cyber risks.
Operational resilience teams should consider conducting scenario analysis and testing around frontier AI incidents (such as compromised AI-enabled customer interaction tools or automated decision engines) to evidence the ability to maintain critical services in line with DORA requirements on ICT-related incident management and business continuity.
Compliance and procurement teams may wish to review contracts and due diligence for critical ICT third‑party providers that supply or host frontier AI models, assessing how provider controls, service levels and incident processes meet DORA expectations and the ESAs’ focus on frontier AI risks.
Supervisory engagement teams should consider preparing to discuss the firm’s frontier AI strategy, risk management and governance with competent authorities, using the ESA statement as a reference point for how existing supervisory expectations on ICT risk and cyber resilience are applied to AI use cases.
Internal audit and second‑line control functions may wish to plan thematic reviews of frontier AI deployments to assess coverage of AI-specific ICT risks within existing control frameworks, including documentation quality, model oversight, and alignment with DORA and sectoral guidance.
Firms should consider monitoring forthcoming ESA and national competent authority publications on frontier AI and DORA oversight activities, as the statement signals that supervisory practices and expectations in this area are evolving and may be further operationalised.
What changed
The publication introduces a consolidated supervisory expectation that frontier AI models be treated explicitly as a source of ICT and cyber risk within existing EU operational resilience and ICT risk management frameworks, rather than as a separate technology domain. It emphasises the need for robust governance, risk management, and controls around the prevention, detection and management of cyber risks stemming from frontier AI, including model governance, validation, monitoring and incident handling.
Compliance impact
The impact is primarily supervisory and interpretative rather than creating new binding obligations, but it raises expectations that frontier AI deployments will be demonstrably integrated into existing ICT risk, cyber security and DORA compliance frameworks. Firms that cannot evidence robust governance and risk management for frontier AI may face heightened supervisory scrutiny and potential findings in ICT risk or operational resilience reviews.
The Data Point Model Alliance, a joint initiative of the EBA, ECB and EIOPA, is committed to making financial sector statistical and supervisory reporting across the EU simpler, smarter and more proportionate. To facilitate the integration of reporting, they launched today a public consultation on enhancements to…
AI Analysis
The EBA-ECB-EIOPA Data Point Model (DPM) Alliance has launched a two‑month public consultation on DPM 2.1, a new version of the common metadata model and associated naming conventions intended to support integrated statistical and supervisory reporting in the EU. This is a standard-setting initiative that will shape how prudential, resolution and statistical data are modelled, named and reported across banking, insurance and pensions sectors.
Key dates
2026-07-31
Launch of the public consultation on DPM 2.1 and publication of naming conventions for metadata used in reporting
2026-09-30 Deadline
Deadline for submitting comments to the DPM 2.1 public consultation
2023-06-01
Publication month of DPM Standard 2.0 by EBA and EIOPA, establishing the current baseline data dictionary standard
2024-03-01
Establishment of the DPM Alliance joint governance framework by EBA, EIOPA and ECB to extend DPM to ECB statistical reporting
Suggested considerations
Compliance teams may wish to review the DPM 2.1 factsheet and the published naming conventions to understand proposed changes in metadata versioning, logical data model support and naming structures, and how these could impact existing COREP, FINREP, resolution and insurance reporting implementations.
Regulatory reporting and technology teams should consider mapping current data dictionaries and reporting taxonomies (including those used for CRR/CRD prudential reports, BRRD/SRB resolution reports and EIOPA insurance and pensions reports) against the DPM 2.1 metamodel to assess the scale of future migration effort and potential system changes.
Firms should consider engaging in the consultation process, either directly or via industry bodies, to provide feedback on the practicality of the proposed metamodel and naming conventions, particularly where they affect multi-framework reporting or large-scale data integration projects.
Compliance and regulatory change functions may wish to flag DPM 2.1 internally as a strategic development in EU reporting architecture and ensure it is reflected in medium-term reporting transformation programmes, including planning for alignment with the ESCB Integrated Reporting Framework (IReF).
Reporting vendors and in-house IT teams should consider evaluating whether their current regulatory reporting tools and data models can support DPM 2.1’s enhanced versioning and logical data model capabilities, and identify potential design changes needed to remain aligned with future EBA, EIOPA and ECB requirements.
Supervisory liaison and public policy teams may wish to monitor subsequent EBA, EIOPA, ECB and SRB communications following the close of the consultation for indications of timelines when DPM 2.1 and the naming conventions will become expected or mandatory for specific reporting frameworks.
What changed
The DPM Alliance is consulting on DPM 2.1, an updated version of the DPM metadata model that introduces enhanced metadata versioning and extends the metamodel to host logical data models, with the explicit objective of supporting integrated European reporting across all regulatory frameworks in the financial sphere. The consultation also covers newly published naming conventions that set out a common approach for naming metadata used in reporting, designed to ensure consistent use of the common data dictionary across regulatory reporting frameworks.
Compliance impact
The immediate compliance impact is moderate because this is a consultation rather than a binding rule, but it foreshadows significant medium-term changes to how EU prudential, resolution and statistical reports are modelled and integrated. The alliance emphasises reduced complexity, improved data quality and lower reporting costs, indicating that supervisors expect firms to adapt systems and data governance to a more unified, DPM-based reporting architecture.
Interview with ECB Supervisory Board member discussing banking supervision priorities including geopolitical risks, stress testing, AI governance, cyber resilience, and banking union completion.
New Q&As available 10 July 2026 Digital Finance and Innovation Sustainable finance Trading The European Securities and Markets Authority (ESMA), the EU's securities markets regulator, has published the following question and answer: EU ESG Ratings Regulation (ESGRR) Consulting activities to investors or undertakings…
AI Analysis
Key dates
10 July 2026
- ESMA publishes the new Q&As on ESGRR, MiCA, and MiFIR secondary market topics
Suggested considerations
Review ESG ratings policies to ensure consulting, notification, issuer feedback, and factual error review procedures align with ESMA’s latest ESGRR Q&As.
Update internal case-handling workflows so notifications are screened for the designated contact issue and the two-working-day notification period is calculated consistently.
Document how your firm distinguishes internal-use ESG ratings or in-house financial services from externally provided ESG ratings activity.
Reassess whether any second-party opinion business can rely on the ESGRR exemption and record the legal basis for that conclusion.
Re-map MiCA permissions for custody, administration, transfer, and lending services to confirm the firm is not performing activities outside its authorisation scope.
What changed
- ESMA added a Q&A clarifying consulting activities to investors or undertakings under the EU ESG Ratings Regulation (ESGRR), which is relevant where a ratings provider’s advisory services may...
ESMA added Q&As on the application and scope of the two working day notification period under ESGRR, indicating that firms must apply the notification clock consistently and in line with ESMA’s...
ESMA clarified access to the dataset for factual error review under ESGRR, which affects how rated entities or issuers can review underlying data used in ESG ratings processes.
ESMA added a Q&A on notifications without a designated contact under ESGRR, which is relevant for governance and outreach workflows when a notification lacks an identified recipient.
ESMA clarified the obligation to consider issuer feedback under ESGRR, reinforcing that issuer comments cannot be ignored and must be handled through a documented review process.
Compliance impact
Non-compliance risk is high because these Q&As affect how firms interpret regulatory scope, notification timing, and operational controls across sustainability, crypto, and market structure regimes. Firms that ignore the guidance may face supervisory challenge, remediation costs, and potential findings that their current procedures, permissions, or disclosures are misaligned with ESMA’s expectations.
ESMA launches Common Supervisory Action on CASPs’ digital operational resilience for custody 08 July 2026 Digital Finance and Innovation The European Securities and Markets Authority (ESMA), the EU regulator and supervisor, is launching a Common Supervisory Action (CSA) focusing on the digital operational resilience…
Why this matters
ESMA's Common Supervisory Action targets CASPs' digital operational resilience frameworks for custody activities, focusing on DLT-specific risks. This is informational guidance on a supervisory exercise running 2026-2027, not an urgent regulatory change.
The ESAs support ESRB warning on systemic cyber risks from frontier AI models 07 July 2026 Digital Finance and Innovation Joint Committee Press Releases The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support today’s warning from European Systemic Risk Board (ESRB) on the systemic…
Why this matters
ESAs issue joint warning on systemic cyber risks from frontier AI models threatening financial sector operational resilience. Applies across all financial entities under DORA framework.
This is an informational speech by ECB Supervisory Board Chair to European Parliament outlining regulatory reform agenda. Key focus areas include capital framework simplification, cyber/AI resilience requirements, banking union completion, and supervisory methodology updates.
Interview with ECB Supervisory Board member discussing banking supervision priorities including geopolitical risk stress testing, digital transformation, AI strategies, SREP reforms, capital requirements (P2R), operational resilience including cyber threats and third-party outsourcing, and Basel III implementation.
This is a fireside chat speech by ECB Executive Board member Frank Elderson discussing regulatory simplification, capital requirements, banking competitiveness, cyber resilience with frontier AI models, and the digital euro project.
ESMA 2025 Annual Report: focus on stronger supervision, regulatory simplification, and innovation 17 June 2026 About ESMA Board of Supervisors Management Board Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published its Annual Report…
Why this matters
ESMA's annual report highlights 2025 regulatory achievements across multiple domains: MiCA and crypto-asset implementation, consolidated tape providers under MiFIR, T+1 settlement, DORA digital resilience, ESG/Green Bond regulations, and supervisory reporting simplification.
This is a keynote speech by ECB Supervisory Board member Sharon Donnery addressing banking supervision modernization. It discusses capital requirements (Pillar 1/2), operational resilience including cyber threats and third-party dependencies, and the need for risk-based supervisory frameworks.
ESAs publish the first report on DORA major ICT-related incidents 03 June 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism…
AI Analysis
The ESAs (EBA, EIOPA and ESMA) have published their first annual report under Article 22(2) DORA, aggregating 3,383 **major ICT‑related incidents** reported by EU financial entities and highlighting that roughly one third had a cross‑border impact. This is an early supervisory “heat map” of DORA incident reporting and sends a clear signal that competent authorities will focus on cross‑border ICT risk, third‑party/outsourcing failures and the adequacy of firms’ incident classification and reporting frameworks.
Key dates
17 January 2025
– DORA (Regulation (EU) 2022/2554) applies, and financial entities become obliged to report major ICT‑related incidents to their competent authority once classification thresholds are met
Annual (from 2026 onwards) Deadline
– Under Article 22(2) DORA, the ESAs must issue a yearly report covering number, nature, impact, remedial actions and costs of major ICT‑related incidents; the publication in early June 2026 is the first such report and sets the expectation for future annual cycles
Suggested considerations
Review and, where necessary, recalibrate internal incident classification criteria against the DORA definition of “ICT‑related incident” and “major ICT‑related incident”, ensuring consistency with applicable RTS on classification and materiality thresholds.
Validate that your firm’s incident management and escalation processes can identify, assess and classify incidents “without undue delay” and trigger major‑incident reporting within the prescribed timelines (initial, intermediate and final reports).
Conduct a gap analysis of cross‑border incident handling, ensuring that governance, communication and coordination arrangements adequately address incidents affecting multiple Member States or shared cross‑border infrastructures.
Strengthen third‑party and outsourcing risk management by mapping critical and important functions to their supporting ICT service providers, and ensuring contracts, SLAs and incident‑response clauses support DORA reporting and cooperation obligations.
Test and, if needed, enhance incident response runbooks to ensure close coordination with ICT service providers during incident containment, remediation and recovery, including clear roles for data provision required for regulatory reporting.
What changed
- The ESAs have operationalised Article 22(2) DORA by issuing the first annual overview of major ICT‑related incidents, confirming that yearly ESA‑level aggregation and analysis of incident data is...
Incident reporting under DORA is now demonstrably harmonised and centralised, with major ICT‑related incidents being notified to all competent authorities involved and then aggregated by the ESAs for...
The report confirms that cross‑border incidents are prevalent (around one third of major incidents), reinforcing that the “borderless and interconnected” nature of ICT risk is a key supervisory...
System failures and external events, rather than pure cyber‑attacks, are identified as the main drivers of major incidents, placing regulatory emphasis on ICT change management, resilience of core...
The ESAs highlight third‑party and outsourcing risk as a core theme, stressing the need for robust oversight of ICT service providers and close coordination with them during incident response and...
Compliance impact
Non‑compliance with DORA incident management and reporting obligations can lead to supervisory findings, administrative sanctions, and heightened intrusive supervision, especially where cross‑border incidents or third‑party failures are not properly reported or managed. Given the ESAs are now publicly benchmarking the sector, firms whose reporting patterns appear inconsistent with peers face increased risk of challenge on classification practices and operational resilience adequacy.
This is an informational keynote speech by ECB Executive Board member Frank Elderson addressing operational resilience and AI-driven cyber threats in banking. While it contains supervisory guidance and expectations (including mention of forthcoming 'dear CEO letter'), it is primarily a speech outlining strategic...
ESMA’s annual data report shows increased quality, wider use and digital progress 29 May 2026 Market data The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its annual report on the quality and use of regulatory data . It shows that improvements…
AI Analysis
ESMA’s latest annual report on the **quality and use of regulatory data** confirms a material step‑up in supervisory reliance on EMIR, SFTR, MiFIR, AIFMD and MMFR datasets, alongside new inclusion of Prospectus and DORA ICT‑incident reporting. For compliance teams this is a clear signal that data quality is now an enforcement‑relevant topic across a broader perimeter, and that ESMA is actively moving toward **streamlined, “report once” cross‑regime reporting** and an integrated funds reporting framework, which will reshape reporting architecture and controls over the next 1–3 years.
Key dates
2025 (exact dates TBD)
– ESMA’s Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR is scheduled, with stakeholders expected to provide input on duplication removal and “report once” options
18 June 2026
– ESMA will host a webinar to present the main findings of the annual report on the quality and use of regulatory data
Suggested considerations
Map all existing regulatory reporting obligations across EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus and DORA ICT‑incident reporting, and document the underlying data sources, systems and ownership for each regime.
Review and enhance data quality controls for EMIR, SFTR and MiFIR reporting, including validation rules, completeness checks, reconciliations, pairing and matching processes, and governance around Unique Transaction Identifiers and counterparty data.
Perform a gap analysis of Prospectus reporting and DORA ICT‑incident reporting processes against ESMA’s emerging cross‑regime data quality expectations and ensure they are covered in the firm’s enterprise data governance framework.
Establish or update a centralised regulatory data governance framework that explicitly covers cross‑regime consistency (for example, trade and position data alignment between EMIR, SFTR and MiFIR) and defines clear accountability at senior management level.
Engage with internal IT and reporting teams to identify where a future “report once” model could be supported technically, including harmonised reference data, common identifiers and golden‑source transaction and position records.
What changed
- ESMA confirms measurable data quality improvements across EMIR, SFTR, MiFIR, AIFMD and MMFR regulatory datasets, indicating that regulators now consider these data sufficiently reliable for...
ESMA highlights extensive and growing supervisory use of regulatory data by ESMA and NCAs for investor protection, financial stability, orderly markets and market integrity, increasing the...
The scope of the annual data quality and use report is expanded to include Prospectus reporting obligations, bringing prospectus‑related data formally into ESMA’s cross‑regime data quality scrutiny.
The report scope is also expanded to include ICT‑related incident reporting under the Digital Operational Resilience Act (DORA), signaling that operational resilience incident data will be monitored...
ESMA has launched a 2025 Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR, including options to remove duplications and apply a “report once” approach, which will likely lead...
Compliance impact
Regulatory data reported under EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus rules and DORA is increasingly used for day‑to‑day supervision, thematic reviews and enforcement, making poor data quality a direct source of regulatory, reputational and potentially financial sanctions risk. As ESMA and NCAs deploy more automated, risk‑based data quality tools, firms with weak controls or inconsistent cross‑regime reporting will be more visible and more likely to face targeted supervisory action.
ESMA advances the simplification of EU reporting frameworks for funds and transactions 04 May 2026 Fund Management Market data Press Releases Securities Financing Transactions Simplification and Burden Reduction The European Securities and Markets Authority (ESMA), the EU financial markets regulator and supervisor…
ESMA launches a call for evidence on the structure of European equity markets 30 April 2026 Trading The European Securities and Markets Authority (ESMA) has published a call for evidence (CfE) presenting a data driven analysis of the evolution of trading in European equity markets between 2022 and 2025, based on MiFIR…
Joint Committee annual report highlights digitalisation, cyber resilience and sustainable finance as key priorities of 2025 24 April 2026 Joint Committee The Joint Committee of the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published its Annual Report for 2025 , setting out the main…
ESMA support ESEF implementation with updated taxonomy 21 April 2026 Electronic reporting The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the 2025 European Single Electronic Format (ESEF) XBRL taxonomy files , together with an updated ESEF…
ESMA releases reporting templates and instructions for the Active Account Requirement 13 April 2026 CCP Market data The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the reporting templates and instructions for the Active Account Requirement (AAR)…
This speech discusses the Savings and Investments Union (SIU), a strategic initiative to deepen financial integration in Europe. It highlights the important role of banks in the success of the SIU, as they can help mobilize savings, diversify risks, and support the real economy.
This regulatory update from the ECB covers topics relevant to the banking and investment management sectors, including prudential requirements, operational resilience, and technology/cyber risks. It has a medium level of urgency as it discusses current challenges and future priorities for European banking supervision.
This regulatory update from the ECB discusses simplifying banking supervision processes while maintaining prudential standards and resilience. It is relevant for banks, asset managers, and wealth managers in the banking and investment management sectors, covering topics around prudential requirements, operational...
This regulatory update discusses harmonization and diversity in banking regulation and supervision within the EU, covering topics such as the Single Rulebook, proportionality, and the ECB's supervisory approach. It is relevant for banks, wealth managers, and the broader financial sector.
This regulatory update from the ECB focuses on upgrading banks' capacity to deal with digital risks, including IT change management, third-party dependencies, and cybersecurity testing. It is relevant for banks and fintechs and covers key operational resilience and technology/cyber topics.
This regulatory update from the ECB covers key topics for the banking and investment management sectors, including prudential requirements, operational resilience, and technology/cyber risks. It is of medium urgency as it provides an overview of the ECB's supervisory priorities and activities.
EU financial markets enter 2026 amid high-risk environment 11 March 2026 Press Releases Risk monitoring The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its first risk monitoring report of 2026 , outlining the key risks and vulnerabilities in EU…
Why this matters
The regulatory update discusses significant market volatility, cyber and hybrid threats, and operational risks in the EU financial markets, particularly impacting securities, crypto-assets, and financial infrastructures.
This regulatory update from the ECB covers topics relevant to banks, asset managers, and wealth managers, including prudential requirements, operational resilience, and the use of technology and AI models.
This speech discusses the need for deeper financial integration in the EU to address fragmentation and enhance the competitiveness of European banks and financial institutions.
This regulatory update discusses the role of banks in promoting competitiveness and growth, with a focus on the importance of strong regulation and supervision in contributing to bank resilience and competitiveness.
ESMA issues a supervisory briefing on algorithmic trading 26 February 2026 Trading The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, today published a supervisory briefing to support consistent supervision of algorithmic trading across the EU. The briefing…
Why this matters
This regulatory update from ESMA provides guidance and supervisory expectations for firms engaged in algorithmic trading, with a focus on areas such as pre-trade controls, governance, testing, and the use of emerging technologies like AI.
This regulatory update from the ECB discusses the adoption of artificial intelligence (AI) in the banking sector, covering key areas such as governance, risk management, and the impact of generative AI.
ESMA publishes latest edition of its newsletter 13 February 2026 ESMA newsletter The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published today its latest edition of the Spotlight on Markets Newsletter. This edition opens with ESMA’s Digital and Data…
Why this matters
This regulatory update from ESMA covers several key areas including data and digital strategies, post-trade transparency for OTC derivatives, cooperation with other regulators, and various publications on ESG and risk-based supervision.
This regulatory update from the ECB discusses geopolitical risks and their impact on the banking sector, including potential disruptions to financial markets, credit risk, and operational resilience. It is relevant for banks, asset managers, and wealth managers.
Join us for ESMA’s Conference “A new era for EU capital markets” on 21 May 2026 05 February 2026 About ESMA The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, is organising a high‑level conference “A new era for EU capital markets” on 21 May 2026 in Paris…
Why this matters
This is an informational speech from ESMA about upcoming discussions on deepening market integration, strengthening supervision, and improving the investor journey. It is relevant for capital markets participants, investment managers, and banks.
This speech covers the ECB's approach to digital transformation and innovation in the banking sector, with a focus on the opportunities and risks of technologies like AI and tokenization.
The European Supervisory Authorities and UK financial regulators sign Memorandum of Understanding on oversight of critical ICT third-party service providers under DORA 14 January 2026 Digital Finance and Innovation International cooperation The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have…
Why this matters
This regulatory update is relevant for banks, asset managers, and wealth managers as it covers the oversight of critical ICT third-party service providers under the Digital Operational Resilience Act (DORA).
ESMA’s Digital and Data strategies support supervision of EU financial markets 13 January 2026 About ESMA Market data Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has adopted a new Digital Strategy and updated its Data Strategy . They reflect…
Why this matters
This regulatory update from ESMA focuses on the adoption of new digital and data strategies to support the supervision of EU financial markets. It covers topics related to technology, data reporting, and operational resilience, which are relevant across various financial sectors including capital markets, crypto...
This regulatory update from the ECB indicates that they will be assessing banks' stress testing capabilities to capture geopolitical risk. This is relevant for banking, investment management, and wealth management firms, as they will need to ensure their risk management frameworks are robust enough to handle potential...
This speech from the ECB discusses evidence-based supervision and addressing evolving risks to maintain resilience, which is relevant for banking, investment management, and wealth management firms from a prudential, operational, and technology perspective.
This regulatory update is relevant for banks, fintechs, and crypto exchanges as it provides guidance on implementing the TIBER-EU framework for digital operational resilience, which is a key requirement under the DORA regulation.
This regulatory update from the ECB discusses improving banks' resilience to hybrid threats, which is relevant for banking, investment management, and wealth management firms.