MFSA Frontier AI Circular: What Financial Firms Need to Reassess Now
The MFSA frontier AI circular, issued on 5 August 2026, puts one question to licence holders: are your existing controls still effective if the threat environment moves faster? This third edition of A2CO’s Digital Risk Briefing sets out what that means in practice across vulnerability management, agentic AI, identity and access, security testing, third-party risk and operational resilience.

What the MFSA frontier AI circular means in practice
The circular does not create a new control framework. It asks firms to re-test an assumption buried inside the frameworks they already have: that defenders have time. Frontier AI models are narrowing the gap between a vulnerability being discovered and a working exploit existing, and the same capabilities are now being embedded in agents that act inside enterprise systems rather than simply generating text.
For a supervised firm, the practical consequence is a review rather than a rebuild. Five things are worth reassessing: how vulnerabilities are prioritised, how identity and delegated authority are governed for non-human actors, how security testing reflects realistic attack chains, how deeply third-party dependencies are understood, and what monitoring exists while systems are running rather than only before they are approved.
Why the response window is shrinking
The development of frontier artificial intelligence is beginning to challenge an important assumption underpinning many cybersecurity and ICT risk management frameworks: how much time defenders have to respond.
The issue is not simply that AI may enable more sophisticated cyberattacks. It is that AI may accelerate several stages of an attack simultaneously, potentially reducing the time available to detect, assess, contain and respond.
For Boards, risk functions and security teams, the question is therefore becoming increasingly practical: are existing controls capable of operating effectively when the threat environment moves faster?
A changing supervisory focus on AI cyber risk in financial services
On 5 August 2026, the Malta Financial Services Authority (“MFSA”) issued its circular Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape.
The MFSA highlights the potential for frontier AI models to accelerate vulnerability discovery and the development and weaponisation of exploits. This could compress the period between vulnerability discovery and exploitation, placing established vulnerability-management and cyber-defence cycles under increasing pressure.
Importantly, the MFSA does not establish a separate control framework for frontier AI. Rather, it reinforces the need for firms to assess whether existing ICT risk management, cybersecurity and operational-resilience arrangements remain sufficiently effective as the threat environment changes.
That direction is consistent with developments at European level.
The European Systemic Risk Board has warned that frontier AI models may increase the speed, scale and sophistication of cyberattacks and potentially create systemic consequences where financial institutions depend on shared infrastructure and technology providers.
ENISA similarly calls for capabilities that can respond to machine-speed threats, recognising that defensive operating models may need to evolve alongside increasingly automated offensive capabilities.
The European Supervisory Authorities have also emphasised prevention, detection and management measures including asset visibility, vulnerability management, monitoring, least-privilege access, supply-chain controls, resilience testing and management-body accountability.
The supervisory message is therefore increasingly consistent: the fundamentals of ICT risk management remain relevant, but the assumptions around speed, scale and interconnectedness need to be reassessed.
1. Vulnerability management needs to become more risk-driven
AI can reduce the effort required to analyse software, identify weaknesses and generate or adapt exploit techniques.
This means that a vulnerability previously considered manageable within a traditional patching cycle may become materially more urgent if exploitation can be developed more quickly or automated.
Accurate asset inventories and effective exposure management therefore become even more important. But speed alone is not enough. Organisations also need to improve how vulnerabilities are prioritised.
A purely severity-based approach can result in limited resources being directed towards high-scoring vulnerabilities that present relatively little practical exposure, while more exploitable weaknesses affecting critical systems remain unresolved.
A stronger approach to AI vulnerability management combines:
- vulnerability severity;
- evidence of exploitability;
- external exposure;
- business criticality;
- the sensitivity of affected data or services; and
- the potential operational impact of compromise.

This becomes particularly important as the response window narrows.
AI also has a defensive role
The same capabilities that accelerate offensive activity can support defenders.
AI can assist security teams with vulnerability triage, threat correlation, log analysis, incident investigation and prioritisation of remediation activity.
The objective should not, however, be uncontrolled automation. For material security decisions, organisations still need appropriate validation, escalation mechanisms and human judgement.
The relevant question is therefore not simply whether AI is used in cyber defence, but where automation improves response speed without weakening assurance.
2. Agentic AI changes the identity and authorisation problem
Agentic AI introduces a different security challenge.
An AI agent may retrieve data, call APIs, interact with applications, initiate workflows, update records or communicate with other agents. Once an AI system can act rather than simply generate information, identity governance becomes much more important.
Organisations need visibility over:
- which agents and other non-human identities exist;
- who owns them;
- which user or process they are acting for;
- what authority has been delegated to them;
- what tools and systems they can access; and
- how long those permissions remain valid.

This is where Zero Trust and least privilege become particularly relevant.
Agents should not automatically inherit the broad permissions of the user or application initiating them. Access should be appropriately scoped to the task, time-limited where practical and withdrawn when no longer required.
Sensitive or irreversible actions should also be subject to additional safeguards, including human approval where appropriate.
OWASP’s work on agentic applications reflects this wider shift, identifying agentic AI security risks around agent identity, privilege, tool use and the broader environment in which autonomous systems operate. Its Top 10 for Agentic Applications is a useful reference point.
The security boundary is therefore no longer the model alone. It extends across the agent, identity, tool, data and system chain.
3. Prompt injection should be considered as part of an attack path
Prompt injection remains one of the most discussed AI security risks, but treating it as an isolated model issue can obscure the real risk.
In an agentic environment, malicious instructions could be contained in webpages, emails, documents, retrieved data or tool outputs. If an agent processes those instructions while also holding access to enterprise systems, the more important question becomes:
If the agent is manipulated, what can it actually do next?
Potential consequences may include:
- accessing sensitive information;
- misusing credentials;
- invoking unauthorised tools;
- altering persistent memory or context;
- bypassing intended workflows;
- escalating privileges; or
- triggering sensitive actions.
This is why testing should move beyond isolated prompt-response exercises and consider realistic end-to-end attack paths.
That does not mean testing every conceivable scenario.
A proportionate programme should identify representative attack chains based on the system architecture, available permissions, critical processes and credible impact.
4. Security testing needs both automation and evidence
The emergence of agentic security-testing tools adds another dimension.
Adaptive AI-driven testing may be useful where security weaknesses depend on context, such as business-logic flaws, complex authorisation relationships or multi-step attack chains. However, this does not make established deterministic testing obsolete.
A practical approach is to distinguish between repeatable automated testing for known vulnerability classes and agentic testing for scenarios requiring greater contextual reasoning.
It is also important to recognise that an AI-generated hypothesis is not the same as a validated vulnerability. Findings should still be supported by runtime evidence and reproducible testing.
For firms, the practical implication is a hybrid testing model:
- use deterministic techniques for repeatable and scalable coverage;
- use adaptive or agentic approaches where reasoning adds value;
- validate findings before treating them as established risk;
- set clear testing boundaries around credentials, scope and destructive actions; and
- retain human oversight for material findings and remediation decisions.
The same principle applies to AI security more broadly: greater automation should increase the need for evidence, not reduce it.
5. Third-party and concentration risk become more dynamic
AI adoption is heavily dependent on interconnected external ecosystems: cloud providers, foundation-model providers, software vendors, data providers, APIs and increasingly agentic platforms.
The MFSA specifically highlights common cloud, technology, software, AI-model and data providers as possible sources of shared vulnerabilities and single points of failure.
This is familiar territory for ICT third-party risk management, but AI can deepen the dependency chain.
A firm may contract with one SaaS provider while depending indirectly on a cloud host, foundation model, external dataset and several software libraries. Understanding the immediate vendor alone may therefore provide an incomplete picture.
Point-in-time vendor questionnaires are also increasingly difficult to rely on where technology stacks, integrations and exposures change continuously.
A stronger approach involves ongoing visibility over critical dependencies, material subcontractors, changes in architecture and concentration exposures.
For firms within scope of DORA, these developments reinforce the importance of ICT third-party risk management, contractual safeguards, concentration assessments, resilience testing and viable exit arrangements. Our DORA compliance service covers each of these.
Runtime controls and monitoring become increasingly important
Traditional AI governance often concentrates heavily on approval before deployment: assess the use case, approve it, define permissions and review periodically.
Those controls remain necessary.
However, systems capable of autonomous action also require controls that operate while the system is running.
Depending on the use case, these may include:
- restrictions on tool and API access;
- limits on delegated authority;
- transaction or action thresholds;
- human approval for sensitive actions;
- behavioural monitoring;
- real-time logging;
- rollback mechanisms; and
- tested kill switches.
Monitoring also needs to extend beyond whether the model is technically available or producing plausible outputs.
NIST’s 2026 report Challenges to the Monitoring of Deployed AI Systems highlights the importance of post-deployment monitoring to validate real-world operation, identify unexpected outputs and drift, and detect consequences arising from changing deployment contexts.
For agentic systems, organisations should therefore consider monitoring tool calls, identities, permissions, data access, actions, exceptions and overrides, rather than model outputs alone.
The MFSA AI self-assessment is more than an inventory exercise
The MFSA’s Dear CEO Letter of 4 June 2026 on AI Governance, Risk and Prudential Expectations provides an important practical link between AI governance and the wider ICT risk framework.
The MFSA expects licence holders to treat AI as a prudentially relevant risk area and to undertake a structured internal assessment of AI use, governance, dependencies and controls.
Its AI-Enabled Process & Vendor Mapping Self-Assessment should not be treated simply as an AI inventory.
The exercise requires firms to consider matters including:
- end-to-end processes and tools;
- vendor and fourth-party dependencies;
- embedded AI capabilities;
- AI autonomy and materiality;
- governance and Board oversight;
- customer and market impact;
- concentration and systemic dependencies;
- contractual protections; and
- manual overrides, rollback and kill-switch arrangements.
This makes the Annex a useful starting point for connecting AI governance, ICT risk management, cybersecurity, third-party risk and operational resilience.
For Boards and senior management, the value of the exercise lies not in completing the questionnaire, but in identifying where AI changes the organisation’s risk profile and whether existing controls remain appropriate.
What should financial firms prioritise?
Four areas deserve particular attention.
End-to-end identity and delegated authority, including non-human identities. Firms should be able to determine what is acting, on whose authority and with which permissions.
Zero Trust, least privilege, blast-radius limits and human approval for sensitive actions. A manipulated agent should not be able to convert one compromised instruction into unrestricted enterprise access.
AI-enabled detection, risk-based prioritisation and containment. Defensive capability should evolve alongside offensive capability while retaining validation and human judgement at critical points.
End-to-end attack-path testing and continuous runtime monitoring. Testing should reflect realistic chains of compromise, while monitoring should provide visibility into the behaviour of deployed agents and their interactions with enterprise systems.
From AI governance to digital risk management
Frontier AI does not make established cybersecurity principles obsolete.
It changes the speed, scale and operating assumptions under which those principles must work.
Boards and senior management should therefore be asking whether vulnerability-management processes, identity controls, security operations, third-party oversight and resilience arrangements remain effective as both internal AI adoption and external AI-enabled threats accelerate.
At A2CO, we support organisations across digital risk, including ICT risk management, DORA and operational resilience, AI governance, AI risk management, AI security advisory for AI systems, AI assurance and MFSA AI self-assessment support.
As AI security, ICT risk management and operational resilience become increasingly interconnected, organisations that manage them as components of the same digital-risk framework will be better positioned both to adopt AI safely and to remain resilient to the threats developing around it.