Daily · AI Cyber Risks & Banking Access · July 7, 2026

AI and Systemic Cyber Risks

Regulators are increasingly concerned that advanced "frontier" AI models are creating new vulnerabilities for the financial sector. European supervisory authorities, including ESMA and the EBA, have backed a warning that these tools can identify and exploit high-severity IT flaws at a speed and scale that could undermine the operational resilience of financial firms. For business leaders, this signals an urgent need to review cybersecurity frameworks beyond standard compliance with the AI Act and DORA. Similarly, the Financial Stability Board is now pushing for a more responsible adoption of AI across the global financial system to mitigate these systemic risks.

In the UK, AI regulation is moving into the commercial arena with new restrictions on the marketing of automated vehicles. The government has established a list of restricted terms that can only be used to promote vehicles that have been officially authorised as automated. Companies selling or promoting vehicle technology must audit their marketing materials to avoid committing an offence under the Automated Vehicles Act 2024.

Banking Entry and Operational Rules

Market entry and operational compliance are shifting in Europe and the UK. The EBA has issued final guidelines on the authorisation of third-country branches, which will directly affect non-EU financial firms seeking to expand their footprint within the bloc. In Switzerland, FINMA is formalising its requirements by converting its circular on bank and securities firm liquidity into a formal ordinance, ensuring the rules meet statutory format requirements.

Meanwhile, the UK’s FCA is intensifying its focus on financial inclusion. Following a "mystery shopping" exercise that revealed poor practices, nine major banks have committed to improving access to basic bank accounts—specifically for vulnerable customers without fixed addresses or standard identification. Firms in the retail banking space should expect stricter oversight and accountability regarding their onboarding journeys.

Consumer Protection and Market Enforcement

The US Securities and Exchange Commission is ramping up its fight against scams with the creation of a new Retail Fraud Working Group. This dedicated unit within the Division of Enforcement will focus specifically on fraud targeting everyday investors, suggesting a more aggressive stance toward firms offering retail investment products. On a more neutral note, the SEC announced that there will be no inflation adjustment for civil monetary penalties in 2026, meaning the maximum fines for violations of the Securities and Exchange Acts remain at 2025 levels.

Hong Kong regulators have also issued alerts regarding fraudulent websites, highlighting the ongoing need for firms to monitor brand impersonation.

This overview is informational, not legal or compliance advice. Consult your lawyer or compliance specialist on specific decisions.

Sources

This overview is based on official regulator publications for the period: