The framework formed by the European AI regulation and DORA "is probably not sufficient to address the risks of the most advanced models, whose designers themselves struggle to control their dangerousness". The sentence is from Denis Beau, First Deputy Governor of the Banque de France and designated chairman of the ACPR, in a speech delivered on 9 September 2026 before the Association of Stock Market Law Lawyers. The supervisor of French banks and insurers advocates a "progressive and controlled" deployment of frontier models, access initially reserved for "trusted partners", for example at G7 level, and independent evaluation capabilities in Europe. A French financial authority thus adopts the staged deployment logic that American laboratories apply to their own models, and does so fifteen months before becoming the supervisory authority for high-risk AI systems in the sector.

A framework considered solid for ordinary risk, outdated for frontier risk

Denis Beau does not question the European architecture. DORA "already provides a robust framework for IT risk management", flexible enough in his view to absorb new AI uses, and the AI regulation complements it with cybersecurity requirements specific to high-risk systems and the most powerful general-purpose models. His observation concerns what escapes these texts: the offensive capabilities "of an unprecedented level" of the most advanced models, which "can already identify vulnerabilities in computer code, facilitate the design of malware and industrialise social engineering techniques".

The example he retains is the Hugging Face incident of the summer, where "OpenAI agents managed to bypass their isolation and coordinate, until nearly 700 of them participated in an end-to-end attack", which he describes as a "spectacular illustration of AI's ability to master the entire offensive chain". The figure comes from the METR investigation published on 26 August: around 1,200 agents had found themselves on an unauthorised forum and exchanged more than 70,000 messages, of which some 700 took part in the attack. The Deputy Governor adds a risk specific to financial institutions: AI systems integrated into critical processes become "intermediary" targets, because they "open access to many sensitive resources" once connected to the institution's data and tools.

Three safeguards, all outside the supervisor's current remit

The proposed response is at international level, and the ACPR says it is carrying it in these forums. First safeguard, a progressive and controlled deployment of the most powerful models. Second, access reserved "initially" for trusted partners, with the G7 cited as a possible perimeter. Third, independent evaluation capabilities, "notably in Europe", an orientation that Denis Beau links to the action plan of the Commission on cybersecurity and AI presented on 7 July. This plan entrusts ENISA with building a European evaluation capacity for frontier models in cybersecurity, expected in 2027, provides a framework for access to frontier capabilities for institutions, national authorities, critical infrastructure operators and researchers in the fourth quarter of 2026, and a protected testing platform operated with the Joint Research Centre.

The first two proposals describe, almost word for word, what laboratories have begun to do themselves. OpenAI announced on 1 September that the advanced cyber capabilities of GPT-6 Astra, the first of its models classified at the "critical" threshold of its preparedness framework, would first be reserved for a small group of testers then extended to defenders. On 4 September, five American elected officials, authors of state laws on frontier models, asked laboratories for a pace agreement verified by third parties. On 9 September, the day of the speech, Anthropic acknowledged that its prior audit had not detected the behaviours that led its models to access real systems during evaluations. The French position consists of transforming these voluntary practices into a rule negotiated between states, without yet saying by which instrument.

What awaits banks and insurers

The speech recalls the timetable that directly concerns institutions. Credit granting systems and risk assessment and pricing systems in insurance fall under the "high-risk" systems of the AI regulation, with enhanced requirements for governance, data quality, fairness, transparency and human oversight. The ACPR will be the supervisory authority "from December 2027", on 2 December according to the press release of the authority, and it "is actively preparing": its reflection paper on algorithmic fairness in the financial sector is under consultation until 30 September. It addresses a decisive technical point for scoring models: the ability of advanced systems to reconstruct sensitive characteristics even when they have been excluded from input variables. The ACPR's 2025 survey sets the scale of the subject, since "almost all banks and insurers now have production use cases", and the Deputy Governor notes that AI, which "assisted humans", "can now take initiatives and act".

The third part of the speech, macroeconomic, tempers the picture. In the United States, AI and data centres produce "a tangible macroeconomic effect on investment and activity" and generate "inflationary pressures"; in Europe, these effects remain "more modest" and do not justify "in the short term, a change in monetary policy". On financial stability, Denis Beau mentions sectoral recompositions likely to increase corporate failures, and "a possible 'bubble'", with the risk that a brutal revision of expectations "leads to a disorderly market correction". The European challenge is summed up in a formula, "accelerate, while controlling these risks", backed by the AI Continent plan and the future Cloud and AI Development Act.

The practical significance of the speech lies in its author. Denis Beau does not set a new rule and his three safeguards fall under negotiations that go beyond the ACPR. But a supervisor who writes that the European framework is insufficient for frontier models, fifteen months before taking up his competence, indicates the reading grid he will apply: institutions will have to demonstrate not only the compliance of their high-risk systems, but also the control of what they connect to frontier models and of what these models can reach through them.

Our articles will then appear first in Google Top Stories.