Frontier AI does not require a new operational resilience framework; it tests whether existing frameworks can remain effective as disruption becomes faster, more interconnected and less predictable.

Over the past few months, frontier artificial intelligence (AI) – the most advanced general-purpose AI models – has moved from an innovation topic to a board-level risk consideration. Regulators globally have responded with warnings and policy statements on the risks posed by these technologies. Most notably, the European Systemic Risk Board (ESRB) has warned that frontier AI could strain cyber resilience across the financial system, while European Central Bank (ECB) Banking Supervision’s Dear CEO letter requires significant institutions to assess AI-enabled cyber threats and submit action plans by 31 October 2026. Together, these developments reinforce the view that frontier AI is becoming a material risk consideration for financial institutions.

While recent interventions have begun to acknowledge the broader operational resilience implications of frontier AI, most of the focus has remained anchored in cybersecurity. The focus on cybersecurity is well-founded, but frontier AI raises a broader operational resilience challenge across decision-making, third-party dependencies, operations and customer outcomes.

A changing operating environment 

Operational resilience frameworks have evolved significantly over the past decade.

From the Basel Committee’s Principles for Operational Resilience to the EU’s Digital Operational Resilience Act (DORA), firms have invested heavily in identifying critical services, mapping dependencies, testing severe scenarios and improving recovery capabilities.

Those investments have strengthened resilience across the sector.

The issue is not that current frameworks are wrong. The issue is that many of the assumptions underpinning them are now being tested.

Traditional assumptionEmerging reality
Disruptions occur as discrete events, affecting one service at a time.A single upstream failure, such as a model update or shared dependency, can degrade multiple services simultaneously.
Adversaries are constrained by skill, cost and time.Capability is rapidly commoditising: attacks are cheaper, faster and increasingly automated.
Scenario libraries can be refreshed periodically.Threat capability evolves quickly; yesterday’s tail risk can become today’s baseline.
Dependencies, once mapped, remain relatively stable.Frontier technologies introduce more dynamic and multi-layered dependencies across providers, models, platforms and ecosystems.
Disruption unfolds at human timescales, allowing time to respond.Events increasingly unfold at machine speed; response windows may be compressed from days to minutes.

Table 1: Embedded Assumptions vs Emerging Realities

Each of these shifts places new pressure on resilience frameworks that were developed in a different era.

Why frontier AI models are different

Every major technology wave introduces new challenges. Frontier AI stands apart for three reasons.

1. Speed and scale.

Frontier AI compresses the time between intent and execution, enabling both attackers and defenders to operate at unprecedented speed and scale.

Research suggests that the latest models are increasingly capable of identifying vulnerabilities and connecting seemingly unrelated weaknesses into exploitable attack paths. As a result, advanced capabilities are becoming more accessible and easier to scale.

2. Generality and agency.

Unlike traditional technology solutions designed for specific, well-defined purposes, frontier models are inherently general-purpose.

They can be deployed across a wide range of business functions and are increasingly capable of operating with varying degrees of autonomy. The same technology can serve as a productivity enabler, critical dependency and threat vector within the same organisation.

3. Ubiquity.

Many firms are already using frontier AI without fully realising the extent of their exposure. These capabilities are increasingly being embedded across customer, technology, cyber and compliance functions, often through third parties or employee-led adoption (“shadow AI”).

The result is that organisations may have less visibility over their AI dependencies than they assume.

Regulatory frameworks remain but expectations have shifted

A defining feature of the current regulatory response is that it does not create an entirely new resilience framework for frontier AI. In Europe, supervisory expectations are increasingly being applied through existing frameworks, including DORA, rather than through a separate AI-specific resilience regime.

This distinction is important. The challenge for financial institutions is not to design new frameworks, but to demonstrate that existing resilience capabilities remain effective.

While the EU AI Act focuses on AI governance and accountability, DORA focuses on operational resilience and ICT risk. Together, they reinforce a shift in supervisory focus: from AI adoption itself to the resilience of the services and processes that increasingly depend upon it.

Operational resilience in an AI-enabled world

Existing frameworks remain relevant, but they must now operate at a different pace and across a wider set of dependencies.

Six areas require particular attention.

Governance and accountability – Boards cannot oversee risks they do not understand, and frontier AI cannot default to a purely technology or security concern.

Firms should establish explicit executive ownership, board-level visibility, and risk appetite statements and management information that reflect the scale, speed and dependency risks associated with frontier AI.

Impact tolerances and scenarios – Impact tolerances calibrated for single-service, human-paced disruption require revalidation.

Disruptions are increasingly simultaneous, interdependent and machine-driven. What constitutes “severe but plausible” has shifted materially. Last year’s tail risk can quickly become this year’s planning assumption. Scenario design must evolve beyond annual refresh cycles and reflect a more dynamic threat.

Measuring and managing organisational latency – One of the least mature yet increasingly important resilience capabilities is organisational responsiveness – the ability to assess, decide and act at the pace required by the threat environment.

Traditional resilience metrics focus on outcomes such as uptime, incidents and recovery times. Increasingly, firms also need to understand their decision and execution speed, including:

  • Time from vulnerability disclosure to risk assessment
  • Time from risk assessment to approval
  • Time from approval to deployment
  • Time from detection to containment

Supervisors are showing increasing interest in these measures, as they indicate whether a firm can operate at the pace required by AI-enabled threats.

Mapping, outsourcing and concentration – Frontier models enter firms primarily through third-party ecosystems and are often several layers deep.

DORA’s register of information and outsourcing expectations provide the foundation. Firms must extend mapping to understand where frontier AI capabilities sit within critical service chains, and where concentration risk is accumulating.

The key questions are no longer theoretical:

  • Where is the dependency?
  • How concentrated is it?
  • What does credible substitution or exit look like when viable alternatives are limited?

Response and recovery – Response frameworks designed for human-paced disruption require acceleration.

Frontier AI is likely to compress the time available for decision-making and execution across resilience and operational response activities. While increased speed can improve responsiveness, it may also increase the risk of unintended consequences where changes are implemented before their impacts are fully understood. The resilience challenge is therefore not simply operating faster, but ensuring that governance, controls and oversight can keep pace with accelerated execution.

People and cultureHuman judgement is becoming more, not less, important.

A workforce capable of questioning model outputs acts as a control; one that cannot do so introduces material vulnerability. Skills, scepticism and the confidence to challenge automated decisions must be treated as core resilience capabilities, rather than optional enhancements.

The resilience test ahead

Frontier AI does not break operational resilience frameworks; it tests their effectiveness and exposes their limitations. Resilience can no longer be viewed as a one-time, static exercise or a regulatory documentation process. In an environment shaped by faster, more interconnected and AI-enabled disruption, firms will need to approach resilience as an ongoing, adaptive capability.

For boards and executive committees, the test can be distilled into three critical questions:

  • Can you clearly identify which of your important business services depend on frontier AI models, either directly or through third-party providers?
  • Would your established impact tolerances withstand multiple, simultaneous AI-driven disruptions?
  • If you received the next “Dear CEO” letter tomorrow, would you have a well-prepared response plan, or would you be building one under supervisory pressure?

Answering these questions requires more than high-level assurance. The immediate priority for firms is to assess whether existing operational resilience arrangements remain effective in an AI-enabled operating environment. That assessment should examine how frontier AI affects important business services, third-party dependencies, impact tolerances, scenario design, governance and response capability.

Institutions best positioned to navigate this transition will embed these questions into the leadership agenda, continuously stress-test their resilience frameworks against AI-driven conditions and recognise that resilience must evolve at the same pace as the technologies shaping the operating environment.

Bank of England, FCA and HM Treasury, Joint Statement on Frontier AI Models and Cyber Resilience, 15 May 2026.

European Central Bank, F. Elderson, “Strengthening operational resilience for the age of AI,” keynote, Goldman Sachs European Financials Conference, Zurich, 3 June 2026.

New York State Department of Financial Services, Industry Letters on Heightened Cybersecurity Risks Associated with Frontier AI Models, 21 May 2026 (and Cybersecurity Risks Arising from Artificial Intelligence, 16 October 2024).

European Systemic Risk Board, Warning on systemic cyber risks stemming from frontier artificial intelligence models, ESRB/2026/3, 25 June 2026, published 7 July 2026.

European Central Bank Banking Supervision, “Addressing AI-enabled cybersecurity threats,” Dear CEO letter to significant institutions, 7 July 2026.

Central Bank of Ireland, Cross-Industry Guidance on Operational Resilience (revised; effective 14 July 2025); Regulatory & Supervisory Outlook, 26 February 2026.

Regulation (EU) 2022/2554 (DORA); EU Artificial Intelligence Act, Regulation (EU) 2024/1689.

Basel Committee on Banking Supervision, Principles for Operational Resilience, 2021.

Prudential Regulation Authority, SS1/21; Financial Conduct Authority, PS21/3.

UK National Cyber Security Centre, guidance on preparing for a “vulnerability patch wave.”

Monetary Authority of Singapore, Project MindForge AI Risk Management Toolkit and Operationalisation Handbook (2026) and proposed Guidelines on AI Risk Management (consultation, November 2025); Hong Kong Monetary Authority, guidance on generative AI in financial services.

Australian Prudential Regulation Authority, Letter to Industry on Artificial Intelligence, 30 April 2026.