The European Securities and Markets Authority has begun directly auditing the cyber defenses of firms it oversees, and the accelerant is artificial intelligence.
The warning from Paris
Verena Ross, ESMA chair, told markets this week that cyberattacks are growing in both frequency and speed. The core problem is time. AI enables attacks to move faster than human incident response teams can track them. What previously took hours now takes minutes.
Anthropic’s Mythos model, announced April 7 and released only to a controlled group of roughly 40 organizations under Project Glasswing, demonstrated an 83 percent success rate in autonomous exploit creation on the first attempt, and can chain those exploits together.
The UK’s AI Security Institute independently confirmed the model can execute multi-stage attacks autonomously at speed. That is the capability jump ESMA is designing against. Anthropic built it for defense. The same tooling, in the wrong hands, inverts entirely.
Systemic Risk, Not Just Operational Risk
ESMA’s March 2026 risk monitor identified three stress amplifiers: geopolitical instability, stretched equity valuations, and cyber and hybrid threats. The combination is what makes this moment structurally dangerous. A cyberattack targeting market infrastructure during a period of record-high valuations and elevated volatility does not stay contained. It becomes a market event. Ross acknowledged that global equity markets remain near all-time highs and that a triggering incident could rapidly reverse investor sentiment.
That is the scenario regulators are designing against.
A Tool That Cuts Both Ways
AI in cybersecurity is not a solved deployment. Institutions are integrating models they do not fully understand into infrastructure they cannot afford to break.
The attack surface does not shrink when you add AI, it shifts. Adversarial inputs can manipulate detection models. AI systems trained on historical threat data miss novel attack patterns by design. And the confidence that comes with automation creates its own risk: faster decisions are not always better ones when the model is wrong.
The deeper problem is procurement outpacing comprehension. Security teams are adopting AI tooling under pressure; from leadership, from vendors, from regulators signaling that AI readiness is now an audit criterion. That pressure produces integration without understanding.
IBM’s 2025 Cost of a Data Breach Report found that one in five organizations suffered a breach tied to shadow AI, unsanctioned models running inside infrastructure that security teams could not see. Organizations with high shadow AI exposure paid $670,000 more per breach on average.
ESMA is right to watch AI adoption inside the firms it oversees. The risk is not only that attackers have AI. It is that defenders have it too, and are not sure what it is doing.
Regulatory Infrastructure Catching Up
ESMA and two other EU regulators designated 19 technology companies as critical third-party providers under DORA in November, but none of them are AI model providers.
That gap is now the problem. DORA was designed for cloud infrastructure and legacy software dependencies. It was not designed for a world where a single model can autonomously chain exploits across every major operating system.
Ross declined to say whether Mythos-class providers would be added to the designation. The non-answer is its own answer: the framework does not yet have a category for what Mythos represents.
MiCA tells the same story from a different angle. Crypto firms must secure licenses by end of June or exit EU markets entirely, a hard perimeter being enforced precisely because AI-enabled actors have made that space a primary target.
The regulation exists. The enforcement is real. But MiCA addresses who can operate, not what the operating environment now looks like. Tightening the perimeter means nothing if the wall was built before the threat changed shape.
What Changes Now
ESMA is not waiting for self-reported audits. Direct firm outreach signals that cyber risk has been reclassified, from operational nuisance to systemic threat requiring the same oversight architecture as capital adequacy or liquidity risk.
The practical problem is that the framework is still catching up to the capability. DORA has no category for autonomous exploit chaining. MiCA tightens who operates, not what they face. And Ross declining to answer whether Mythos-class providers fall under critical third-party designation is not caution, it is a live gap in enforcement authority.
The next stress test for European financial infrastructure may not come from a rate decision or a sovereign debt event. It will come from an incident that moves faster than any human response chain, inside systems regulators approved but cannot fully audit. Europe is building oversight architecture for a threat that has already changed shape. That lag is the risk.