Written by a human
How can Nordics firms stay ahead of frontier AI risk?
AI is accelerating cyber threats to the financial sector. Learn what Finanstilsynet, the ESRB, and EU regulators expect firms to do, and how to prepare.
In brief:
- Finanstilsynet (Danish FSA) has warned that advanced frontier AI models are helping bad actors find and exploit IT vulnerabilities faster and at greater scale
- The warning comes after a joint European Systemic Risk Board/ European Supervisory Authorities (ESRB/ESA) alert issued in July 2026 on systemic cyber risk from frontier AI
- The regulator has laid out seven expectations across firm’s board-level accountability, monitoring, and incident-response readiness
On August 21, 2026, Denmark’s financial services regulator, Finanstilsynet, issued a risk outlook report, noting that AI has not invented a new category of cyberthreat, but has dramatically accelerated an existing one. The warning lands as part of an increase in regulatory attention across Europe on frontier AI risk. For compliance teams across the Nordic region and the wider EU/EEA, the message is clear: the rules of cyber-defense and operational resilience are shifting, and regulators expect firms to shift with them.
“Raising the tempo” – Why regulators are sounding the alarm
At the heart of Finanstilsynet’s warning is a straightforward but sobering finding: frontier AI models are enabling cyber attackers to identify and exploit vulnerabilities “faster and at greater scale than before.” Mette Tams Kitaj, Deputy Director, Finanstilsynet stated, “AI increases the tempo of the cyberthreat” facing the financial sector, meaning both firms and regulators are having to move with urgency.
Finanstilsynet is not sounding this alarm in isolation. On July 7, 2026, the ESRB issued its own warning that frontier AI models are enabling bad actors to increase the speed, scale, and complexity of cyberattacks. The EU’s financial supervisory authorities (ESA) followed with a statement urging the sector to strengthen cyber and operational resilience in the face of these emerging risks.
“No Standard Fix” – Building governance that keeps pace
Finanstilsynet has conceded that there is no one size fits all there is no one-size-fits-all solution for organizations across the financial sector. Instead, the regulator has laid out a series of expectations for firms grouped into four practical pillars:
- Visibility: Firms must map how AI, including frontier models, is used internally and what risks this may create.
- Ownership: Clear board and executive-level accountability for AI risk must sit within existing governance and IT risk frameworks. Regulators want named responsibility, not diffused committee oversight. As Felix Abu, Director of Corporate & Advisory at Robinhood, outlined, risk does not sit in one department alone, and neither should accountability.
- Vigilance: Effective processes for vulnerability monitoring and security patching are non-negotiable and must account for the accelerated pace at which AI-assisted attackers can move.
- Preparedness: Incident response and recovery plans must be updated to reflect AI-driven attack scenarios, and plans must be tested, not merely documented.
The emphasis on testing is deliberate. Finanstilsynet expects leadership to have a “clear picture of vulnerabilities” and proof that response plans have been assessed under realistic conditions. This connects directly to the Digital Operational Resilience Act’s (DORA’s) existing ICT risk-management and testing obligations, and Finanstilsynet explicitly ties its expectations here to its DORA supervisory role, making clear that AI-driven cyber risk is not a separate workstream but one that flows through the architectures firms are already building.
Expertise, knowledge-sharing, and the supply chain behind AI risk
Finanstilsynet has advised firms to build up necessary cybersecurity expertise, whether internal or sourced externally, and to actively share knowledge and experience with other organizations across the sector. Frontier AI presents risk at sector-wide scale, making knowledge sharing and collaboration vital.
Financial firms rely on third-party partners and vendors for a wide range of services, and increasingly this includes third-party provided AI models and outsourced IT services.
If the expectation is that firms maintain expertise and vigilance over AI-related vulnerabilities, then vendor oversight and supply-chain due diligence become a practical necessity, not a nice-to-have. Firms must look to work with vendors that prioritize security and resilience, as their incident-response plans are only as strong as the weakest link in their vendor chain.
Finanstilsynet has also signaled that it will spend the second half of 2026 specifically analyzing the sector’s AI use and associated risks — a clear indication that more scrutiny is coming, and likely more questions about third-party and vendor relationships with it.
Key takeaways and actions for firms
Can we have a little lead in paragraph here please “blah blah blah key takeaways firms can take to increase resilience include …”
- Regulatory & risk mitigation: Map frontier-AI use and exposure now, before Finanstilsynet’s sector-wide AI review lands later in 2026.
- Governance: Assign explicit board and executive ownership of AI-driven cyber risk, as regulators want named accountability, not shared responsibility.
- Operational resilience: Treat AI-accelerated attacks as a distinct scenario in DORA-aligned incident response and recovery testing, not a subset of generic cyber risk.
- Third-party / supply chain: Extend vulnerability monitoring and expertise requirements to AI vendors, model providers, and outsourced IT partners, working with trusted security-first vendors, as a firm’s resilience is only as strong as theirs.
- Culture: Build internal and sector-level knowledge-sharing on AI threats into regular practice, and be prepared to work collaboratively with other organizations to stay ahead of evolving threats.
Working with security-first partners and vendors is essential to minimizing potential weak links in your compliance chain. Every third-party integration, AI-enabled tool, and outsourced service that touches your firm’s communications introduces a new node of risk — and resilience and recovery require a firm foundation of complete data across your business so that you can monitor for potential issues and trust that should you need to recover, you’ll have all the data you need. When Finanstilsynet calls for visibility into AI use and vigilance over vulnerabilities, the reality is that much of that exposure flows through the communication channels your firm already archives, such as: email, chat, voice, and other regulated interactions where AI-assisted tools, vendor integrations, and outsourced services leave a footprint.
Global Relay’s Archive and Surveillance solutions help compliance teams turn that into actionable oversight. Comprehensive archiving across communication channels gives firms a defensible record of what was said, by whom, and through which platforms, including those used by third-party vendors and AI-enabled platforms. Together, these solutions provide the kind of documented, testable visibility that regulators like Finanstilsynet increasingly expect, not just as a compliance checkbox, but as evidence that leadership genuinely understands where its vulnerabilities lie.
See how Global Relay’s Archive and Surveillance solutions give you that visibility.