Merci de désactiver le bloqueurs de pub pour visualiser cette vidéo.
Cyber resilience: the AMF calls on financial market participants to strengthen their cybersecurity arrangements in response to rapidly evolving threats associated with artificial intelligence

Cyber resilience: the AMF calls on financial market participants to strengthen their cybersecurity arrangements in response to rapidly evolving threats associated with artificial intelligence

The operational resilience of regulated financial entities, and in particular their resilience to cyber risk, is a strategic priority for the Autorité des marchés financiers (AMF). In its 2026 action priorities, the AMF identified the anticipation of new risks and the operational resilience of regulated firms as priority areas for action.

This priority takes on particular importance in the context of rapidly evolving digital risks. Recent advances in certain artificial intelligence models, whether specialised or usable for cybersecurity or cyberattack purposes, are likely to accelerate the identification of vulnerabilities, facilitate their exploitation and, more generally, contribute to the industrialisation of malicious campaigns. While artificial intelligence can also enhance capabilities for detecting, analysing and responding to incidents, its rapid development requires financial institutions to adapt their risk management arrangements. In response to these challenges, the AMF is and will remain proactive across all its areas of activity, from contributing to international work to informing, supporting and supervising financial entities within its remit at the domestic level.

European and international initiatives

The AMF actively contributes to the work of the various bodies that bring together financial sector regulators in order to anticipate emerging risks, promote the sharing of analyses and help ensure a coordinated response from the authorities. It is notably involved in the work of IOSCO, in particular within its Financial Stability Engagement Group, co-chaired by the AMF Chair and the Chief Executive of the UK Financial Conduct Authority, as well as in the European Systemic Risk Board, the Financial Stability Board and the G7 Cyber Expert Group.

Awareness-raising and supervisory initiatives, inspections

The AMF monitors compliance by entities within its remit, namely portfolio management companies, crypto-asset service providers, crowdfunding service providers and market infrastructures, with Regulation (EU) 2022/2554, known as the Digital Operational Resilience Act (DORA), which has applied since 17 January 2025. This regulation imposes a number of obligations on financial sector participants. In particular, they must identify their entity’s critical or important processes and systems, implement cybersecurity risk mitigation strategies, establish a robust framework for managing cyber incidents, conduct digital operational resilience testing and manage third-party risk, particularly in relation to information technology and digital service providers.

The European Supervisory Authorities will shortly publish a report on the major incidents reported to national competent authorities under this regulation. Subsequently, the AMF will publish an initial assessment of the implementation of the regulation, focusing on French financial entities under its supervision. For educational and awareness-raising purposes, this publication will share the key lessons learned from the notifications received, the types of incidents observed and the main points requiring attention for all stakeholders.

In addition, in line with its 2026 action priorities, the AMF will conduct various awareness-raising initiatives in the second half of 2026 for portfolio management companies, crowdfunding service providers and crypto-asset service providers, notably through an educational webinar aimed at professionals scheduled for 1 July. From July onwards, it will also survey these participants on the measures taken or planned to address risks specifically related to AI models, in order to assess the extent to which these risks are integrated into their cyber risk management arrangements and into their processes for identifying, detecting and remediating vulnerabilities. The Authority will ensure that its expectations remain proportionate and will adopt a risk-based approach. It will publish the results of this survey in the autumn and, where appropriate, draw the relevant conclusions for its supervisory practices.

The AMF will also continue to carry out inspections of the cybersecurity arrangements of regulated entities within its remit. These inspections will assess the protection of client data, the quality of arrangements for preventing, detecting, managing and remediating cyber incidents and, more specifically, the measures implemented to address the evolving threat posed by the capabilities of artificial intelligence.

Recommendations from the Authority

The AMF reiterates that cybersecurity is a major issue for investor protection, the continuity of financial services and, more broadly, confidence in the proper functioning of financial markets. The senior management of regulated entities must therefore ensure that cyber risks are identified, monitored at the appropriate level, tested regularly and integrated into internal control and risk management arrangements. The Authority invites the entities under its supervision to refer to recognised best practices, in particular those issued by ANSSI on cybersecurity hygiene, as well as to the requirements of the DORA framework and the technical standards, guidelines and publications issued by the European Supervisory Authorities. These best practices include, in particular:

  • maintaining a robust inventory of critical systems, data and service providers, and ensuring that access is appropriately controlled;
  • protecting data confidentiality, in particular through cryptographic mechanisms adapted to the current threat landscape;
  • applying security patches within considerably shorter timeframes, in line with evolving threats;
  • frequently backing up systems and data and testing the proper functioning of recovery procedures;
  • training staff on common threats;
  • deploying mechanisms to detect cybersecurity events;
  • regularly testing incident response procedures;
  • conducting, or arranging for the conduct of, technical security audits of critical resources, where appropriate by PASSI-certified auditors, including, where relevant, through so-called ‘red teaming’ exercises;
  • incorporating AI-related risks into cybersecurity scenarios;
  • conducting cyber crisis management exercises.