The Polish Financial Supervision Commission has published recommendations for financial market entities on the cyber security impact of Frontier AI models, warning that more capable artificial intelligence could materially increase the speed and scale of cyberattacks. The guidance calls on firms to reassess the strategic assumptions behind ICT risk management and to adapt their operational resilience frameworks to a threat environment in which vulnerabilities may be identified and exploited more quickly. The recommendations tie this reassessment directly to obligations under the Digital Operational Resilience Act, requiring firms to reflect AI-related threats in ICT risk management, digital resilience testing, third-party ICT risk assessments and incident analysis. In the near term, the authority highlights four priorities: faster vulnerability identification and patch management at scale, stronger monitoring and defensive capabilities supported by evidence that controls work in practice, a review of third-party risk management in critical ICT supply chains, and stronger protection of internet-facing ICT assets, including perimeter technologies, third-party software and open-source components. Over the longer term, firms are expected to build structural resilience through secure-by-design and secure-by-default practices, layered defenses, reduced attack surfaces, tested incident response arrangements and action to limit dependence on single ICT and AI providers. The guidance also calls for risk-based vulnerability management using threat intelligence and information on active exploitation rather than relying only on technical severity scores, controlled use of AI-based defensive tools, closer information-sharing with CSIRT KNF, and stronger management body involvement in assessing the impact of Frontier AI on the firm's risk profile and resource needs. UKNF expects firms to take the necessary actions and says the adequacy and effectiveness of implemented measures will be reviewed through ongoing supervision and inspections.