adesso Blog

The more powerful AI systems become, the more crucial it is for AI governance to understand the extent to which these systems are capable of carrying out cyberattacks autonomously [1]. Whilst it remains unclear how rapidly these capabilities will develop, it is already becoming clear that the associated security risks are no longer merely hypothetical scenarios [1]. For instance, in 2025, Anthropic documented a cyber-espionage campaign in which, according to the company, an AI system had already carried out 80 to 90 per cent of the operational steps involved in the attack.

This development is of direct relevance to insurers: if, for example, a customer portal goes down, or an information and communication technology (ICT) service provider fails to respond to an attack in good time, cyber security immediately becomes a business issue for insurers. Frontier AI models can further exacerbate this situation because they can alter the pace of attacks, detection and response. Under DORA, it is therefore not enough simply to document controls. Rather, the required management of ICT risks, third-party risks and digital operational resilience must keep pace with this increased attack dynamics.

The ESRB warning and its relevance for insurers

On 7 July 2026, the European Systemic Risk Board (ESRB) issued a warning regarding systemic cyber risks posed by frontier AI models. The ESRB describes frontier AI models as advanced AI models that can also have a material impact on offensive or defensive cyber operations. In the short to medium term, they could help attackers identify vulnerabilities more quickly and carry out cyberattacks with greater speed, scale and sophistication. In the long term, however, the ESRB also sees opportunities for stronger cyber defences.

This assessment is deliberately worded cautiously. It does not describe a single insurance event or a wave of losses already measured as a result of frontier AI. However, it highlights a plausible risk driver for the EU financial sector. The European Supervisory Authorities (ESAs) – namely the EBA, EIOPA and ESMA – explicitly endorsed this warning on the same day, linking it to DORA, ICT risk management, critical third-party ICT service providers and supervisory expectations.

For insurers, this is the crucial point:

A technological development is becoming an issue for operational resilience.


Those affected include Security Operations Centres, executive boards, IT risk functions, architecture, compliance and specialist departments such as claims, portfolio management and customer service.

The pace of attacks meets complex insurance landscapes

Frontier AI refers to powerful models capable of supporting tasks in software development, analysis and automation. However, these same capabilities can reach a level that poses risks to public safety [2]. As a result, an attacker no longer needs to understand the entire technical infrastructure and organisation of their target in detail to carry out an effective attack. The ESAs state that recent advances have significantly improved the ability of frontier AI models to identify and exploit highly critical vulnerabilities in IT systems within very short timeframes. Insurers present a particularly large attack surface in this regard: mature core systems, numerous interfaces, intermediary and partner portals, cloud services, and automated processes.

DORA makes speed a key management issue

The Digital Operational Resilience Act (DORA) provides the European financial sector with a harmonised framework for digital operational resilience. The ESAs emphasise that DORA and the AI Act create a solid foundation for managing cyber and AI-related risks. However, a regulatory framework is no substitute for robust operational governance when attack capabilities are evolving faster than control processes.

The first DORA overview of serious ICT-related incidents highlights this operational dimension. On 3 June 2026, the ESAs reported 3,383 reported serious ICT-related incidents in the EU financial sector. Around a third had cross-border implications; according to the report, the immediate impact on customers and transactions was generally limited. System failures and external events were key drivers. Only ten per cent of the reported incidents were related to cyber security; at the same time, the ESAs emphasise the importance of high cyber security standards precisely because of the capabilities of powerful AI tools.

For insurers, this implies a prioritisation approach: not every ICT incident is a cyberattack, and not every cyberattack is AI-enabled. The crucial factor is whether critical insurance processes remain manageable even if an attack is prepared, adapted or scaled more quickly than previously assumed.

Attacks are getting faster. Insurers must keep pace.


Four areas to examine for the initial resilience check

A sensible response does not begin with the purchase of yet another AI tool, but with the question of where an accelerated attack would cause genuine business disruption. Four areas of assessment help to focus the discussion.

  • Critical value streams: Claims reporting, claims settlement decisions, policy issuance, payouts and customer service should be mapped onto the underlying applications, data, interfaces and teams. Only then does it become clear which technical disruptions affect which customers, sales partners or regulatory obligations.
  • Vulnerability management: Patch latency, prioritisation and exception processes must keep pace with the new speed of attack. A monthly review of critical vulnerabilities may be too slow if exploitation and automation are accelerating.
  • Third-party ICT service providers: Cloud, SaaS, IT operations, security service providers and data platforms must be operationally integrated into testing, reporting channels, escalation and recovery planning. In this regard, the Frontier AI debate complements earlier DORA discussions, such as those on the standardisation of third-party service provider information via the third-party service provider portal of GDV Dienstleistungs-GmbH.
  • Software supply chain: In-house development, open source, CI/CD pipelines, APIs, identity services and technical debt must be included in the threat model. The ESRB explicitly mentions software providers, security firms and open-source maintainers as part of a coordinated response.

Key performance indicators must drive decisions

Cyber resilience can only be managed if key performance indicators lead to decisions. The time taken to detect an incident, the time taken to contain it, the time taken to resolve critical vulnerabilities, or the coverage of critical service providers in crisis simulations are all useful metrics. Technical metrics alone are not sufficient from a business perspective. Insurers should also ask:

  • Which claims-handling processes would be disrupted?
  • Which underwriting steps are halted?
  • Which customer groups would be affected?
  • Which manual fallback procedures can realistically cope with the workload?
  • Which reporting deadlines, decision-making powers and communication channels apply under DORA time constraints?

This creates a common language between the Executive Board, information security, IT, compliance, procurement and business units.

A security incident is then assessed based on whether it jeopardises a critical insurance process and what decision ensues as a result.

Defensive AI requires clear guidelines

The ESRB points out that frontier AI models can also strengthen cyber resilience in the long term. The correct conclusion is therefore to deploy AI capabilities in a controlled, traceable manner and with clear accountability. Defensive AI can ease the burden on security teams, detect patterns more quickly and speed up technical analyses.

However, without governance, new risks arise: untested tools, unclear data flows and a lack of traceability. Insurers should therefore define which data is permitted in which tools, when human review remains mandatory and how results are to be documented.

What this means for adesso and insurance projects

For adesso, the technical focus lies at the interface between regulation, the insurance business and software engineering. The ESRB warning does not create a need for yet another isolated security concept. It shows that resilience must be strengthened where business processes, applications, data flows and service providers converge. A pragmatic starting point is a concise resilience assessment across critical business processes:

  • Which processes can only be interrupted for a short time?
  • Which applications, data and service providers support them?
  • Which vulnerabilities or dependencies could become relevant more quickly as a result of AI-enabled attacks?
  • Which reporting, decision-making and escalation channels are effective under DORA time pressures?
  • Which measures can be improved within the next 90 days?

The answers form the basis for a prioritised work plan: updated threat models, shorter remediation cycles, joint exercises with service providers, clearer criteria for critical ICT services, the controlled use of defensive AI tools, and comprehensible reports to the board.

Conclusion: Resilience is determined before an incident occurs

The ESRB warning is no cause for panic, but rather a call to manage cyber resilience under DORA with greater speed, coordination and transparency. Any organisation that only clarifies during an incident which systems are critical, which service providers must respond, and who makes decisions vis-à-vis regulators, sales and customers will be too late. For insurers, the next sensible step is to carry out a detailed assessment that brings together critical processes, technical dependencies, third-party service providers, vulnerabilities, reporting channels and recovery plans. This will form the basis not only for discussing AI-enabled cyber risks, but also for making them operationally manageable.

Picture Garo Karh Bet

Author Garo Karh Bet

Garo Karh Bet has been a working student at adesso in the field of full-stack software development since 2024 and has been contributing to various internal and client projects ever since. He also has extensive experience in the use of modern AI tools, as well as in the design and orchestration of AI agents and workflows. Within his team, he focuses on integrating AI effectively into development processes.