EBA Supervisory Direction on AI and Governance

Created: 2026-05-17 Updated: 2026-06-08 Source count: 4 (with supplementary captures)

Updated 2026-06-08 based on S-2026-04-29-eba-connected-clients — EBA Decision and consolidated Guidelines on connected clients (29 April 2026) added; the EBA partially deleted its 2017 connected-clients guidance now that directly-applicable RTS (Commission Delegated Regulation (EU) 2024/1728) govern when institutions must identify groups of connected clients. Reinforces the EBA’s “single-rulebook simplification / move from guidance to binding RTS” direction on the data-identification substrate (large exposures), not AI-specific. Added as a Key Point, a Detail subsection and an Open Question. Updated 2026-05-29 based on S-2026-04-10-eba-supervisory-reporting-simplification — EBA major simplification of supervisory reporting added (data-architecture substrate for AI controls). Updated 2026-05-28 based on S-2026-05-25-eba-esma-suitability-cp — EBA/CP/2026/03 suitability consultation closure date back-filled with proper citation.

TL;DR

The European Banking Authority’s position on AI in EU banking and payments, articulated through its AI Act mapping exercise (Chair letter to Berrigan and Viola, November 2025), is that existing CRR / CRD governance and risk-management requirements are technology-neutral and can be leveraged for AI supervision. Firms should map AI controls into existing model risk, operational risk, ICT and outsourcing frameworks rather than build parallel AI governance structures. EBA also reports that 2LoD and 3LoD AI oversight is inadequate at most firms.

Key Points

  • EBA confirms CRR / CRD already provide a comprehensive, technology-neutral governance and risk-management framework that supervisors will leverage to oversee AI use in banks [S-2025-11-eba-ai-act-mapping].
  • EBA’s 2026 Work Programme prioritises AI Act mapping and DORA oversight, with a 2026–2027 supervisory convergence programme rather than immediate new guidelines [S-2025-11-eba-ai-act-mapping].
  • Only about half of EU banks have introduced dedicated policies or committees to oversee AI, and 2LoD / 3LoD AI oversight is inadequate at most firms [S-2025-11-eba-ai-act-mapping].
  • EBA published a consultation on revised Guidelines on Internal Governance under the Capital Requirements Directive, reflecting CRD framework changes and DORA — tightening board oversight, ICT / third-party risk and internal governance expectations.
  • Joint EBA/CP/2026/03 consultation on revised Guidelines on the assessment of the suitability of members of the management body and key function holders extends to heads of control functions and CFOs; consultation closed 25 May 2026 with a public hearing held 15 April 2026 [S-2026-05-25-eba-esma-suitability-cp].
  • EBA Final Report on Guidelines on Supervisory Independence issued 29 April 2026.
  • EBA staff paper Systematic backtesting of probability of default models with regulatory data (29 April 2026) sets benchmark approach for PD model backtesting using regulatory data.
  • EBA consultation paper on revised Guidelines on limits on exposures to shadow banking entities under CRR — shifts limit basis from eligible capital to Tier 1 capital; responses due 9 July 2026.
  • EBA published final Guidelines on the Management of ESG Risks, effective for Significant Institutions from 11 January 2026, with ECB applying strictly from 1 April 2026 and a 10-year horizon.
  • EBA consultation on major simplification of supervisory reporting (10 April 2026) — revised ITS would cut harmonised reporting data points by ~50% net of additions for IFRS 18, ESG and FRTB; integrate stress-test and benchmarking collections into regular reporting; strengthen SNCI proportionality via a “core plus supplement” approach; apply from September 2027; built on DPM 2.0 and JBRC integrated reporting [S-2026-04-10-eba-supervisory-reporting-simplification].
  • EBA streamlines its Guidelines on connected clients (Decision + consolidated Guidelines, 29 April 2026) — partially deletes provisions of EBA/GL/2017/15 because directly-applicable RTS in Commission Delegated Regulation (EU) 2024/1728 now set out when institutions must identify groups of connected clients (control relationships, economic dependency); a “move from guidance to binding RTS” simplification on the large-exposures data-identification substrate, not AI-specific [S-2026-04-29-eba-connected-clients].

Detail

The AI Act mapping exercise

The EBA Chair letter to Commission addressees Berrigan and Viola, published November 2025, communicates the outcome of the EBA’s AI Act mapping work and crystallises the headline supervisory message: existing prudential governance and risk-management frameworks are sufficient hosting for AI controls. This stance shapes the EBA 2026 Work Programme — no immediate AI-specific guidelines, but a 2026–2027 supervisory convergence programme to surface concrete control expectations. As of last capture, “concrete control expectations beyond the November 2025 factsheet still pending” [S-2025-11-eba-ai-act-mapping][S-2026-05-06-paul-ai-data-pathway].

Internal Governance Guidelines revision

EBA’s consultation on revised Internal Governance Guidelines under CRD reflects DORA-introduced changes and tightens expectations on board oversight, ICT / third-party risk, and internal governance arrangements. Firms should map current frameworks against the revised expectations and prepare evidence of compliance.

Suitability framework

EBA/CP/2026/03 extends suitability assessment from management body members and key function holders to heads of control functions and CFOs. This brings second-line and finance leadership explicitly within the suitability regime — consequential for AI governance because second-line AI risk owners (often within Risk or Compliance functions) now fall under formal suitability obligations.

Other supervisory direction

EBA published a Final Report on Guidelines on Supervisory Independence (29 April 2026), shadow banking exposure guidelines, and the PD-backtesting staff paper — all tightening the technical machinery against which AI-influenced credit risk and operational risk models will be supervised.

ESG risk integration

EBA’s final ESG risk guidelines, applicable to Significant Institutions from 11 January 2026, push ESG risk into existing governance and risk frameworks with a 10-year horizon. ECB applies strictly from 1 April 2026.

Supervisory reporting simplification — data-architecture substrate

The EBA’s 10 April 2026 consultation on major simplification of supervisory reporting is the most consequential near-term reshaping of the data-architecture substrate that bank governance and AI controls ride on. The package proposes a ~50% reduction in harmonised data points (net of new IFRS 18, ESG and FRTB additions), integration of the EU-wide stress test and supervisory benchmarking data collections into regular reporting, and strengthened SNCI proportionality via a “core plus supplement” approach — built on Data Point Model (DPM) 2.0 and contributing to JBRC integrated prudential and statistical reporting [S-2026-04-10-eba-supervisory-reporting-simplification]. The press release does not directly address AI; the relevance is inferred — simplified, integrated reporting changes the data-lineage, reconciliation and control-evidence surface that any AI-influenced credit-risk, operational-risk or reporting model will be supervised against. Practitioners should treat the September 2027 application date as the planning horizon for re-architecting lineage and control evidence [S-2026-04-10-eba-supervisory-reporting-simplification].

Connected clients — guidance giving way to binding RTS

On 29 April 2026 the EBA published a Decision and a consolidated version of its 2017 Guidelines on connected clients (EBA/GL/2017/15), partially deleting provisions that are now redundant because Commission Delegated Regulation (EU) 2024/1728 — binding RTS developed by the EBA — sets out directly across the EU the circumstances in which institutions must identify groups of connected clients (control relationships, economic dependency, and combined control/economic dependency) [S-2026-04-29-eba-connected-clients]. The source makes no claim of AI relevance; the wiki relevance is to the data-identification and large-exposures control substrate and to the broader pattern (shared with the supervisory-reporting simplification above) of the EBA shifting material from guidance into directly-applicable single-rulebook instruments. Practitioner inference (not in source): where a firm’s connected-clients identification logic or large-exposures data lineage was built against the 2017 guidance text, it should be re-baselined against the consolidated Guidelines and the Delegated Regulation to ensure the control still traces to live, binding requirements [S-2026-04-29-eba-connected-clients].

Practical Applications

  • Use the EBA stance to anchor AI governance frameworks in existing CRR / CRD obligations rather than parallel structures. This is consistent with BCBS AI Governance Framework and FCA approach to AI — the three regimes converge on the same operating posture.
  • Build 2LoD and 3LoD AI oversight as a deliberate priority. EBA flagged this as inadequate at most firms — practitioner opportunity for Service Line — Independent Governance Assurance [S-2025-11-eba-ai-act-mapping].
  • Bring second-line / control-function leadership into suitability evidence. EBA/CP/2026/03 widens the suitability perimeter to heads of control functions and CFOs [S-2026-05-25-eba-esma-suitability-cp] — see Three Lines of Defence for AI.
  • Use the supervisory-reporting simplification as a forcing function for BCBS 239 lineage hardening. Banks will need to re-evidence end-to-end lineage and control coverage as the ITS package beds in toward September 2027 — practitioner opportunity for Service Line — Regulatory Readiness & Evidence and Service Line — Programme Governance Specialist [S-2026-04-10-eba-supervisory-reporting-simplification].

Open Questions

  • What concrete control expectations EBA will publish during the 2026–2027 supervisory convergence programme.
  • Whether the “technology-neutral” framing holds once high-risk AI systems (Annex III) deployed in banking become subject to AI Act-specific obligations from 2 August 2026.
  • Will the September 2027 application date for the simplified supervisory reporting ITS hold given the breadth of the package? [S-2026-04-10-eba-supervisory-reporting-simplification]
  • How materially will the ~50% data-point reduction reshape BCBS 239 lineage programmes already in flight at G-SIBs? [S-2026-04-10-eba-supervisory-reporting-simplification]
  • Which specific provisions of the 2017 connected-clients Guidelines were deleted, and what connected-clients identification logic / large-exposures data evidence does the shift from guidance to directly-applicable RTS require firms to re-baseline? [S-2026-04-29-eba-connected-clients]

Sources