The French financial regulator AMF has placed AI-driven cyber threats at the centre of its 2026 action plan, warning that artificial intelligence is accelerating system vulnerability discovery and enabling more efficient cyberattacks across retail financial services. The regulator is now enforcing the Digital Operational Resilience Act, which took effect in January 2025, setting mandatory requirements for cyber risk management, incident reporting, and third-party oversight.
The AMF will launch expanded monitoring this year, including a July webinar and a survey measuring how firms manage AI-related cyber risks, with results expected in autumn. The regulator is conducting cybersecurity inspections focused on AI-driven threats and urging senior management to align with DORA requirements and European guidance. Recommended measures include critical system inventories, stronger encryption, accelerated patching, and AI scenario integration into crisis planning.
Separately, European Supervisory Authorities reported 3,383 major ICT incidents under DORA’s first reporting period, with approximately one-third showing cross-border impact.
**
FXnCO Insight
** Retail brokers and fintech firms should immediately audit AI exposure points and accelerate DORA compliance efforts ahead of intensified AMF inspections throughout 2026.
Source: Finance Magnates