The European Banking Authority, European Insurance and Occupational Pensions Authority, and European Securities and Markets Authority have issued a joint statement calling for a consistent, cross-sectoral supervisory approach to information and communication technology risks arising from frontier artificial intelligence models. Financial entities should adapt their cyber risk controls under the Digital Operational Resilience Act in proportion to their size, risk profile and operational complexity, focusing on prevention, detection and management of AI-enabled threats. Entities should establish governance and accountability for frontier AI risks without delay, review risk appetite metrics and tolerance thresholds, and strengthen asset inventories, secure system design, patching, continuous monitoring, incident response, resilience testing, backups and supply chain controls. Management bodies should oversee these risks continuously, support timely response plans and allocate sufficient resources. The illustrative measures do not create additional requirements. The authorities have also begun targeted engagement with relevant critical information and communication technology third-party providers. The findings have informed priorities for the 2027 oversight plan, while AI-related risks are being incorporated into the oversight examination methodology and are expected to feature in examinations and other oversight activities during 2027.