The cyber threat landscape changed dramatically in April 2026 with the emergence of frontier AI models from OpenAI and Anthropic. Access to these models was initially limited, and the US imposed a de facto export ban, since lifted. This column argues that these models turn the EU’s reliance on foreign-controlled technology into a strategic dependence, widening asymmetries between jurisdictions, between attackers and defenders, and between less and more capable financial institutions. The result could be a self-reinforcing cycle of fragility. Rather than more regulation, the EU must mobilise risk capital, retain talent, and help frontier technologies emerge and scale.
In April 2026, the cyber threat landscape fundamentally changed, as frontier AI models (FAIMs) were introduced by Anthropic and OpenAI. The debate is no longer only about AI and productivity; it becomes more and more a debate about capability and power.
In essence, frontier AI models are the most capable models, able to autonomously execute cyber operations and operate with speed, scale, and sophistication unmatched by humans (Törnqvist et al. 2026).The significance of frontier AI models does not stem solely from their ability to conduct automated attacks. They are also able to reduce timelines that used to span days or weeks to hours or minutes (Xiao et al. 2026). Vulnerabilities would remain theoretical threats until long after security patches were available. Now, time is becoming a scarce resource. Not only do institutions need to have real-time feeds of novel vulnerabilities, but they also need the capacity to absorb the information, prioritise efforts, and ultimately remediate their exposures. This cannot be resolved simply with larger budgets, as large financial institutions’ technology stacks are often built on decades of developing and evolving technology, making real-time mitigations impossible without compromising on operational resilience. The problem itself lies also beyond the sole scope of financial institutions, as much of today’s technology relies heavily on common software packages and open-source libraries, where vulnerabilities must be addressed by the provider rather than the end user (Törnqvist et al. 2026). What emerges is not a larger cyber threat, but a threat to our accustomed ways of running IT infrastructure, making each factor a potential trigger for a systemic event.
A new threat, unequally distributed
Over the medium term, frontier AI models are likely to strengthen cyber resilience, as their defensive applications come into effect. However, the transition will be the perilous part, as offensive capabilities will proliferate faster and more widely than defensive ones can be absorbed or even accessed.
The frontier AI models announced in April 2026 showed unprecedented capabilities to discover vulnerabilities, craft working exploits, and launch complex attacks against institutions. However, access to these models was initially granted only to a selected group of institutions, focusing heavily on the US domestic markets, leaving the vast majority of EU institutions without it. As the matter progressed and access was granted to a widened circle, the US administration applied a de facto export ban, explicitly limiting use of specific frontier AI models to US nationals. The ban has since been lifted, though with an explicit caveat that it may be reinstated, should circumstances change. This uncertain environment highlights the EU’s exposure to strategic dependency and creates geopolitical risk for business.
From productivity tool to systemic risk
Following the work of the European Systemic Risk Board (ESRB) Task Force on AI, the ESRB issued a warning on AI to EU member states on 25 June (ESRB 2026). It identified three structural asymmetries underpinning the risk: between jurisdictions, between attackers and defenders, and between less and more capable financial institutions. Together, these asymmetries turn technological dependence into a financial stability issue, making cyber risk a more significant systemic threat than at any point previously considered by European authorities. This is matched by the ESRB General Board decision to elevate cyber risk to the highest risk level. We have detailed the asymmetries and their consequences in the ESRB note accompanying the warning (Törnqvist et al. 2026). The warning itself also alludes to a larger issue, namely EU dependence on technology under third-country jurisdiction which is necessary for the Union’s strategic autonomy, competitiveness, and operational resilience.
Figure 1 Vulnerability exploitation times


Data source: ZeroDayClock.com
A dependence built over time
This dependency did not appear suddenly but was built over time. Not because the EU lacked capability, talent, or opportunity, but because it greatly benefited from access to third-country technological innovation without fully bearing the risks and costs of developing domestic alternatives. As long as the technology remained a common good, trade remained free, and technological dependence did not compromise operational sovereignty, there was little reason for concern. Frontier AI models change this, and now the Union faces a reality in which open access to the forefront of technology can no longer be assumed, and where the costs of lacking this access directly impact operational resilience.
From technological dependence to strategic dependence
The EU is currently dependent on foreign cloud services and hyperscalers, compute, specialised software, and advanced hardware. Until recently, restricting access to these technologies offered little strategic advantage. Frontier AI models aggravate this dependency, as they are not only providing utility and defensive capabilities, but can be used offensively. This means that when access to frontier AI models is widely distributed, their offensive capabilities will also spread. Access to such technology developed outside of the Union cannot be assumed. Cyber is widely recognised as a domain of warfare, and frontier AI models will likely play a crucial role in its development. If these models were airplanes, they would be closer to fighter jets than commercial planes.
The US export control of frontier AI models was predicted by the ESRB as a significant risk already in May 2026, and we further predict that they will be considered dual-use technology moving forward. Like advanced semiconductors, the capabilities of frontier AI models exhibit characteristics closely associated with geopolitical importance, where distribution is generally shaped by national security interests rather than by market forces.
Historically, the EU has been technologically dependent but operationally sovereign (Draghi 2024). Frontier AI models fundamentally change this, as defensive capabilities become under the control of third-country jurisdictions, turning technological dependence into strategic dependency (Farrell and Newman 2019). When faced with advanced threats, capability and access are only part of the solution. When attacks move beyond control, autonomy may ultimately mean the ability to unplug. For institutions that understand the consequences and have prepared accordingly, it serves as the defender’s guarantee that control does not solely rest with either the attacker or externally controlled defensive capabilities.
The stakes extend well beyond the realm of cybersecurity. A structural lack of defensive cyber capabilities would eventually erode global confidence in the EU financial system itself, as EU institutions become increasingly exposed to advanced threats without means to adequately defend themselves.
A self-reinforcing cycle of fragility
The economic consequences would follow sequentially and are potentially profound. Technological debt and limited access to frontier AI models as means of defence would lead to higher risk and less operational resilience. Higher risk means higher funding costs, which in turn reduce margins for investments and reinvestments, slowing and reducing innovation, and widening the technological gap with better-protected jurisdictions. Over time, this would reduce EU financial sector competitiveness, causing business to gradually shift its flow and financial institutions to relocate. What began as a cybersecurity issue could convert into a self-reinforcing cycle of system fragility, eventually leading to declining competitiveness, increasing technological dependence, and a widening productivity gap. In that sense, the cost of technological dependence is ultimately paid in terms of resilience, competitiveness, and growth.
Figure 2 Cycle of fragility


Then the central question becomes not whether frontier AI models will be strategically important, but whether the EU is prepared to accept the consequences of technological dependence in a climate where vulnerabilities form as strategic capabilities become subject to geopolitical considerations (Ribakova and Hilgenstock 2022), and access can no longer be assumed. We believe the consequences are too severe. Strategic autonomy is the fundamental tenet of any sovereign jurisdiction, and something that must be protected.
Not more regulation, but capability and capital
The instinctive response seems often to be additional regulation. Yet the Union is arguably not suffering from lack of it. The frameworks and regulation are already in place: the Digital Operational Resilience Act (DORA) governs operational resilience, the Cyber Resilience Act will extend obligations further towards providers, and the AI Act provides tooling for addressing general-purpose AI models posing systemic risk. These have since been complemented by substantial supervisory action, such as resilience testing and preparedness exercises, as well as by financial institutions’ investments in cyber defence. However, neither additional regulation nor supervision, when confined to EU territory, can overcome the fundamental challenge of securing technological and operational autonomy. Moreover, the EU is not suffering from lack of talent, as evidenced by world-class entrepreneurs, researchers, and innovators emerging from the member states. The issue seems to revolve around the frameworks and structure needed to accept the uncertainty and risk associated with innovation, as well as the risk capital needed to drive and reward it. That is why for decades we preferred to benefit from technological advancements developed elsewhere, without bearing the full costs and risks. And it used to be a rational choice. Now AI might turn it into a costly one.
The cost of not innovating
If we wish to catch up with the rest of the world, the EU must do more than regulate. Consistent with Draghi’s conclusion on Europe’s competitiveness (Draghi 2024), we believe the Union must mobilise risk capital and channel it into large-scale investments, including infrastructure, retain and reward talent, create an environment where frontier technologies can emerge and scale successfully, and ultimately revive a culture of institutional competitiveness.
As former US President Kennedy famously remarked when announcing Apollo, “We choose to go to the Moon in this decade and do the other things, not because they are easy but because they are hard.”
The Union is facing a similar choice today.
It can continue to rely on strategic capabilities developed, financed, and controlled elsewhere, and accept the consequences to both economy and autonomy.
Or it can bear the cost of strategic independence and innovation of its own.
Source : VOXeu








































































