Tech & Cyber Resilience in the Age of Frontier AI: Key Insights from the CSSF's 2025 Annual Report
September 6, 2026

“I’m sorry, Dave. I’m afraid I can’t do that.”
Introduction
If a regulator’s annual report opens with Stanley Kubrick’s 2001: A Space Odyssey, you want to know why. The CSSF’s 2025 annual report does exactly that: Director General Claude Marx’s preface begins with HAL 9000, the computer that “begins to take decisions that conflict with the humans” and, deciding that their actions threaten its mission, draws a straight line from that scene to today’s discussions about AI alignment, autonomous agents and the loss of human control.
The framing is itself a signal. In previous editions, artificial intelligence was a chapter among many. In 2025, it is the central theme: the preface, the financial innovation chapter, the supervision of information systems chapter, and the CSSF’s own digital transformation all turn on AI. And it arrives in a year when DORA entered its first full year of application, with real data to measure it, and when Luxembourg’s TIBER-LU programme became the vehicle for the country’s first threat-led penetration tests.
For technology and cyber risk professionals, the report is, as ever, more than a summary: it is a strategic guide. Three messages stand out:
- Frontier AI models are a systemic cyber challenge. In the Director General’s words, they will be “the biggest challenge faced by the Luxembourg and EU finance industry in the coming months and years”.
- DORA’s first year, by the numbers: 260 ICT incident notifications, up about 20% year on year, with 81% of them non-malicious.
- The same IT inspection weaknesses were found, year after year: the same checklist, now compounding.
This article unpacks each of them, along with the regulatory developments that frame them.
1. Frontier AI as a systemic challenge
The preface’s passage on cyber risk deserves quoting at length. Claude Marx writes:
Claude Marx, Director General of the CSSFAs also described in a report by the ESRB, frontier AI models are a paradigm shift for cybersecurity. Whilst these models are capable of strengthening cyber resilience, they will undoubtedly also be exploited by cybercriminals, including rogue states, enabling them to discover vulnerabilities and execute cyberattacks with increased speed, scale and sophistication. Current vulnerability management frameworks are ill-suited to handling sophisticated attacks and large numbers of high and critical severity vulnerabilities. Cyber incidents could spread across the broader financial system through payment systems, clearing and settlement. We may thus face potential systemic risks for the finance sector. (…) This will in my view be the biggest challenge faced by the Luxembourg and EU finance industry in the coming months and years.
Four elements deserve attention:
- The vector. The threat is not a new category of attack; it is a change in the economics of attacking, in speed, scale and sophistication, that renders current vulnerability management frameworks inadequate. This is the same analysis as the coordinated ESRB/ECB/CSSF communications of 7 July 2026 on the systemic cyber risks created by frontier AI models, which we dissected in our July article The End of the Remediation Window. The preface and those communications are two sides of the same coin: the timing assumptions underlying cyber defence are eroding.
- The propagation channel. Incidents could spread “through payment systems, clearing and settlement”. Systemic risk here is not hypothetical; it is built into the payment and settlement infrastructure itself.
- The concentration. “Today, the European Union largely depends on a limited number of third-party providers” of AI, largely outside the EU, creating concentration and third-party risk, strategic dependency and geopolitical risk. Expect your DORA third-party registers to grow accordingly.
- The posture. “No national competent authority will be able to tackle [this] on its own.” The CSSF has started creating awareness amongst supervised entities and will cooperate closely with its EU and international counterparts. Expect convergence work, and expect this topic to become a standing supervisory conversation.
What is new in the report is a compact taxonomy of AI risks in finance that maps well to a board-level risk register: model and data risks (bias, opacity, hallucinations, data quality failures); operational risks (resilience failures, third-party concentrations, vendor lock-in); cybersecurity and financial crime (attacks, deepfakes, market manipulation); systemic and financial stability risks (herding behaviour, feedback loops, AI infrastructure concentration); consumer and investor protection and conduct risks; and governance and accountability risks.
Two further notes from the preface. First, the mismatch between the planning horizon of financial institutions, “two, three or five years at best”, and “technology that changes almost overnight”. Second, the sober reminder that we are “entering the age of quantum computing”, with accelerating investments and advances.
Finally, a forward-looking hook: a third comprehensive survey on AI use among supervised entities will be launched in Q4 2026, with its results to be published in Q1 2027. We will return to it in next year’s review: based on the first two surveys, it will likely be the best available snapshot of how Luxembourg finance actually deploys AI.
2. The third pillar: talent and people
After technology and regulation, the preface comes to what Claude Marx calls “the most challenging” pillar: people.
Claude Marx, Director General of the CSSFThis is not about teaching staff the basics of AI or prompting, which most organisations do. It is about supercharging senior and middle management layers as broad as possible on the tech evolution, as they will drive the transformation in supervised entities.
This is not a new message from the report; we flagged the need for management body upskilling in our 2023 review as well, but it is now framed by the Director General as a structural pain point, in Luxembourg and globally. The report’s financial innovation chapter corroborates it: from its dialogues with the Innovation Hub, the CSSF observes that while staff are offered more training, “there still is an increased need for new talents and specific competences, right up to the level of the decision-making bodies of the authorised entities.”
Practically, “supercharging” is not a training line item. It means AI competence reaching the layers that will drive the transformation, the management body and, as widely as possible, middle management, with succession planning for key technology and security roles on the table. The report also points to national enablers, the AI Advisory Board steered by the Minister of Finance and the AI Experience Centre launched by LHoFT, as avenues for institutions to build this capability without duplicating existing efforts.
3. DORA in practice: year one, by the numbers
2025 was the first full year of DORA, applicable since 17 January 2025. Chapter XVI, on the supervision of information systems, provides the first annual dataset on the regime; a parliamentary Q&A on DORA notifications answered in July 2026 adds further insight on year one.
Incidents. The CSSF received 260 ICT-related incident notifications under DORA and Circular CSSF 24/847, up about 20% on 2024, a year that itself recorded 220 notifications, about 90% more than 2023, a rise the 2024 report attributed to the circular’s entry into force and to the global CrowdStrike outage of the third quarter. The report attributes the 2025 growth partly to DORA’s extended scope and typology, and partly to a few incidents at service providers that generated multiple notifications by client entities. The more important observation: 81% of the incidents notified in 2025 were not related to malicious acts, against roughly three-quarters in 2024. The most common causes, failures by third-party providers, change management issues and human errors, are the same as the year before; DDoS attacks and successful phishing campaigns accounted for the malicious share.
In other words, DORA’s first year confirms at regulatory scale the old resilience truth: what takes your systems down is more often a failed change or a failing third party than a nation-state actor. And the report’s own emphasis on successful phishing campaigns underlines that, within even a small malicious share, it is the attacks that get through that matter.
In the meantime, a parliamentary Q&A on DORA notifications — a question of 1 June 2026, answered by the Minister of Finance on 3 July 2026 — extended the dataset through 8 June 2026: 326 major ICT incident notifications, of which 40% came from credit institutions and 19% from investment fund managers, and only one voluntary notification of a significant cyber threat. The typology of incidents was reported to have remained broadly unchanged from the previous CSSF 24/847 regime, a quarter of the incidents involved ICT third-party providers, and no missed notifications or sanction proceedings for notification failures were reported. On the mechanics, the eDesk “IT Incident Notifier” role went from 54% of in-scope entities in January 2025 to 85% by mid-2026.
For payments specifically, the CSSF analysed 91 notifications of major operational or security incidents related to payments under Article 23 of DORA, shared with the ESAs and the BCL, alongside the annual ICT and security risk assessments and SCA self-assessments submitted by credit institutions acting as PSPs.
The institutional machinery. The year was also one of governance transition. The ESAs’ Joint Committee Sub-Committee on DORA completed its activities in June 2025; the CSSF now assists the ESAs within the Oversight Forum established under Article 32 of DORA. The EU-SCICF, the pan-European systemic cyber incident coordination framework, has been active since 17 January 2025 and spent 2025 building and testing its alert and communication protocols. At national level, a working group of the Luxembourg Systemic Risk Committee has been in place since September 2025 to identify activation procedures for systemic incidents and threats. And the CSSF has started a series of targeted workshops with selected entities to assess their DORA readiness.
Enforcement. IT risk has for some time been among the shortcomings for which the CSSF takes enforcement action. In 2025, “weaknesses identified in the requirements regarding IT risks” was among the reasons for the 19 injunctions the CSSF issued, alongside MiFID II, prudential reporting and internal control findings; the CSSF additionally used its powers under the payment services law to order two payment institutions to establish a robust IT risk management framework. Weak ICT governance remains, in other words, a matter for formal enforcement.
4. TIBER-LU grows up: first round done, first TLPT launched
The TIBER-LU programme, launched in 2021 under the joint oversight of the BCL and the CSSF as the national implementation of TIBER-EU, completed its first round of tests during 2025, all conducted on a voluntary basis. By the end of 2024, eight tests had been completed since 2022, including two cross-border exercises, and the programme remains limited to a handful of supervised entities. The findings are consistent with the previous round: the security of the external perimeter was the most robust area, and “the largest room for improvement was found in internal system strengthening and detection capacity”.
The most actionable sentence in the chapter: your perimeter is not where you are losing.
2025 was also the transition year to DORA’s threat-led penetration testing (TLPT) requirement for entities designated by the competent authority. The BCL and the CSSF updated the national implementation through a new implementation guide published on 20 June 2025, which enabled the adoption of TIBER-LU as the means of carrying out TLPTs. The first TLPT was launched in the summer of 2025, while the voluntary framework continues in parallel for entities not identified by a competent authority.
5. The AI Act: phasing in, and slipping
The report provides a clean summary of the AI Act’s 2025 timeline. In February 2025, the rules on prohibited AI practices, along with the definitions and AI-literacy provisions, applied. In August 2025, the obligations for general-purpose AI and the governance rules applied. It then documents the slippage: delays in the appointment of competent authorities in most Member States, and in the publication of guidance, harmonised standards and compliance tools, led the European Commission to publish in November 2025 a proposal to amend the AI Act, the so-called “Digital Omnibus on AI”, aimed at simplifying and postponing the entry into force of certain measures. The report still lists those negotiations as ongoing; the Digital Omnibus on AI was in fact adopted and published in the Official Journal in late July 2026.
The report is equally clear on the state of play in Luxembourg. The joint CSSF/BCL survey published in May 2025, with its scope extended this year to investment firms and authorised investment fund managers, found that the adoption of generative AI “rapidly overtook” that of more traditional machine learning techniques, bringing new use cases (text summarisation, content generation, chatbots, translation, software code generation) and new risk typologies (hallucinations above all). Its harshest finding: “certain financial entities have yet to fully comprehend or implement the risk categorisation introduced by the AI Act.”
In parallel, the CSSF has been active in the European workstreams: participation in working groups on the interpretation of the AI Act for the financial sector, contribution to the EBA’s mapping of the high-risk AI requirements (solvency assessment, credit scoring) against sectoral rules, and to the ECB’s work on the use of AI in banking.
What should supervised entities take from all this? First, that what applies now applies now: AI literacy and the categorisation of your AI systems against the Act’s risk categories do not wait for the high-risk timeline. Second, that the Omnibus moves the timetable, not the direction of travel; the CSSF will keep participating in the working groups clarifying application to the financial sector, and supervisory convergence work on AI is already under way. The final text is likely to become a reference point for supervisory expectations in the coming years.
A short note on the regulator’s own adoption of the technology it supervises: under its CSSF 5.0 strategy, the CSSF deployed in Q1 2026 its own secure AI platform, SKAI, which combines conversational and agentic capabilities and uses sovereign models for confidential data. It was explicitly motivated by the sovereignty and security concerns raised by AI infrastructure hosted outside the EU. The regulator’s experience is a useful reference point for institutions weighing the same trade-offs.
6. On-site inspections: the same themes, sharper expectations
The CSSF’s “IT on-site inspection” division performed five IT-risk on-site inspections in 2025 (six in 2024 and 10 in 2023), at two credit institutions, one electronic money institution, one specialised PFS and one support PFS, in addition to SSM missions for significant institutions. Methodology work continued in parallel with the ECB, in the working group harmonising IT on-site inspection practices under DORA and within the SSM, and in the competence centre on IT risks.
The findings are, at once, reassuring and concerning. Reassuring, because they confirm the supervisory focus has not drifted: the main themes are recognisably the same as in 2023 and 2024:
- IT security: obsolete systems and configurations; proactive and global vulnerability management (identification, assessment, remediation, patching); the adequacy of security testing;
- Logical access: privileged generic accounts; need-to-know and least privilege, including for privileged nominative and remote access; event logging for accountability;
- IT risk management: mapping of information assets and their classification by criticality, as the basis of risk identification;
- IT governance: the involvement and supervision of the management body;
- Outsourcing: criticality assessments, complete contractual provisions (notably with parent companies), operational monitoring of providers;
- Business continuity: scenario governance, and response, recovery and communication plans.
Concerning, because the industry is being read back the same list, year after year.
What changes in 2025 is the level of precision, and that is where readers should look. New or sharpened expectations from this year’s inspections:
- firewall rule re-examination at least every six months where the firewall supports critical activities or systems;
- annual, or even half-yearly, review of access rights for critical systems;
- regular testing of business continuity, response and recovery plans: an untested plan is not, in the report’s framing, a plan;
- asset mapping and classification positioned explicitly as the foundation of the entire IT risk management process.
Elsewhere in the instruments chapter, three operational-risk on-site inspections (including outsourcing) at less significant banks added an emphasis on monitoring outsourced activities through relevant KPIs/KRIs, supported by complete contractual arrangements and the involvement of the management body and the risk function.
7. Support PSFs and ICT third parties: the CTTP list is out
On 18 November 2025, the EBA published the list of 19 designated critical ICT third-party service providers under Chapter V, Section II of DORA, with the full list available in our article Designation of DORA’s critical ICT TPPs. Designation was made at the level of the EU group head; five support PFS are members of designated groups. In practice, this means exposure to the enhanced oversight machinery: a Lead Overseer coordinating monitoring, and joint examination teams (JETs) empowered to conduct comprehensive reviews of the critical provider. The report notes that the ESAs and the CSSF coordinate their activities to avoid redundancy, a welcome detail for the affected entities. That does not change the fact that JET-grade scrutiny is now a realistic prospect for a small number of Luxembourg groups.
For support PSFs outside the designated groups, the same message applies: DORA’s contractual regime is fully applicable as ICT third-party providers to financial sector clients, and designation is a moving target.
On the national front, the NIS2 and CER transposition matured in 2025. The CSSF’s discussions with the High Commission for National Protection and the ILR clarified the approach on registration arrangements, incident notification obligations and the “main establishment” concept, and a coordination and oversight committee (HCNP, ILR, CSSF) was established to ensure consistency of the intersectoral oversight. The CSSF also contributed to the review of the national cybersecurity strategy and of the critical entities resilience strategy.
In conclusion: three priorities for 2026
The CSSF’s 2025 annual report sends a consistent message: the digital risk conversation has moved from preparation to operation. Three priorities stand out for technology and cyber leaders:
- Operate DORA as a standing regime, not a project. The first-year data tells you where the losses are: third-party failures, change management, human error. And the first TLPTs tell you what the testing will look like. Invest in third-party resilience, change discipline and incident response, and keep your ICT risk file audit-ready at any point in the cycle.
- Govern AI now, not when the high-risk obligations apply. AI literacy and risk categorisation are already applicable; the Omnibus will move the timetable, not the direction. Give your management body the scenario challenges it needs to question AI risk, and watch the Q1 2027 survey results as the Luxembourg benchmark.
- Close the internal detection gap. Year after year, the TIBER/TLPT findings and the on-site inspection results point to the same place: internal system hardening, monitoring and detection, and tested continuity plans.
For supervised entities, the report is, once again, a strategic guide: in 2026, being ahead of it will be a function of how fast your organisation adapts, not of how long its policies are.
The sources for this article are the CSSF’s 2025 Annual Report and the Parliamentary Question No. 4160 on DORA notifications to the CSSF (in French).