ESMA's new supervisory priority from 2027: AI and tokenisation under the spotlight
European Securities and Markets Authority (ESMA)AnnouncementIssued
By the ExamPass CY editorial teamPublished
- MiFID II
- Investor protection
- MiCA and crypto-assets
Short answer
On 23 September 2026 ESMA announced a new Union Strategic Supervisory Priority (USSP) on digital innovation, due to start in 2027. National supervisors such as CySEC will first look at how firms use artificial intelligence (AI) and tokenisation, especially in processes and products that affect client outcomes, and will run initial checks on a subset of the most affected firms. No new rules apply: the MiFID II duties that ESMA says already govern AI use stay as they are, but firms should be ready for supervisory questions.
At a glance
- What changes
- No new rules. ESMA has set a new EU-wide supervisory priority on digital innovation from 2027, starting with how supervised firms use AI and tokenisation.
- Who is affected
- Firms supervised by CySEC and other national supervisors that use AI or tokenisation in processes and products affecting clients, and their compliance teams.
- Cyprus investment firms (CIFs) using AI tools in advice, portfolio management, onboarding, marketing or client communications
- Firms offering tokenised instruments or crypto-asset services
- UCITS management companies and AIFMs that use new technologies in client-facing activities
- Compliance, risk, IT and data teams
- What to do
- Take stock of client-facing AI and tokenisation uses, and check governance, testing, data quality, bias controls and client information against MiFID II.
- By when
- During 2027 — supervisory work starts; no filing deadline
What has ESMA announced?
On 23 September 2026 ESMA said it will launch a new Union Strategic Supervisory Priority (USSP) on digital innovation. The aim is to make sure supervisors have the expertise and capacity to oversee the use of new technologies. Working with national competent authorities, ESMA will start with how supervised entities use AI and tokenisation, and will stay flexible enough to cover other technologies as they emerge. In its factsheet ESMA describes the new priority as innovation with investor safeguards, due to start in 2027.
ESMA's 2027 annual work programme (ESMA22-50751485-1673, dated 28 September 2026) places the new USSP in the retail investor space: it is meant to support innovation and the better investor outcomes that new technologies may bring, while keeping investor protection adequate.
The new priority runs alongside the USSP on cyber and operational resilience, in place since 2025; 2027 will be the third year of that priority and of the application of DORA. The USSP on ESG disclosures, launched in 2023, closes in 2026.
How do USSPs reach firms in Cyprus?
USSPs are priorities that ESMA sets at EU level to direct supervisors' resources towards high-risk areas that need EU-wide attention. Every three years ESMA identifies up to two of them. National competent authorities, and ESMA where it supervises directly, apply them: each year every authority works on the USSP topic, within areas of focus and parameters set with ESMA, and ESMA takes stock of the work once a year.
CySEC, as a national competent authority, applies ESMA's USSPs, so the new priority will feed into its supervisory work from 2027 alongside the cyber and operational resilience priority.
What will supervisors look at in 2027?
According to ESMA's factsheet, in 2027 authorities will focus on areas where AI, tokenisation and other emerging technologies may be used by supervised entities to deliver core activities. The work is organised around three outcomes: supporting innovation; supervisory readiness; and governance, quality and client interests.
In the first year supervisors are to engage with the market on potential benefits, explore the information firms give investors and share examples of innovation that improved investor outcomes; identify where technologies such as tokenisation are emerging in practice and build up their own capacity; and map how firms use, or plan to use, AI and tokenisation in processes and products that directly affect client outcomes, beyond back-office tasks, and run initial checks on a subset of the most affected firms.
The risks ESMA lists are fairness (AI outputs may be biased, unclear or misleading), investor protection (new products may be hard to understand or create new risks), over-reliance (dependence on a small number of third-party providers) and supervisory readiness. The outcome sought from firms is robust governance and client-aligned outcomes when they develop and deploy new technologies, supported by testing, data-quality checks, bias mitigation and reliable outputs. ESMA's work programme adds that it will identify AI use cases through periodic national surveys, which ESMA aggregates.
What should firms prepare?
Nothing new applies yet, and existing rules already cover AI. In a public statement of 30 May 2024 ESMA said it expects firms using AI to provide investment services to retail clients to comply with MiFID II, in particular its organisational requirements, conduct of business rules and the duty to act in the client's best interest. It named algorithmic bias and data quality, opaque decision-making, over-reliance on AI, and privacy and security as the main risks.
Firms can get ahead of the mapping exercise by keeping an inventory of AI tools and tokenised products that touch clients, for example in investment advice, portfolio management, onboarding and suitability, client communications and marketing, with a named owner for each. For each use, compliance should be able to show who approved it, how it was tested, how data quality and bias are checked, what clients are told and how staff can override the output. For the MiFID II basics, see our study note on organisational requirements.
Under the cyber and operational resilience priority, supervisors will also look at the impact of AI on digital operational resilience and at the quality of DORA registers of information, so reliance on outside AI providers should be visible there. In July 2026 the European Supervisory Authorities also asked financial entities to have robust governance and risk management for cyber risks linked to frontier AI models. Firms offering tokenised instruments should be ready to explain how each asset is classified: ESMA will keep monitoring the consistent classification of DLT-based assets under MiFID II, MiCA and the DLT Pilot Regime.
In the official wording
“In collaboration with National Competent Authorities, our initial focus will be on how supervised entities use artificial intelligence and tokenisation.”
When does it apply?
Applies now
- MiFID II organisational, conduct of business and best-interest rules apply when firms use AI in investment services (ESMA public statement, 30 May 2024).
- DORA rules on ICT risk and ICT third-party risk, supervised under the existing cyber and operational resilience USSP.
- Nothing new applies yet: the digital innovation USSP creates no new obligations for firms, and ESMA says only that it starts in 2027, without an exact date.
Applies later
No later dates announced.
What to do
- Build or update an inventory of AI tools and tokenised products used in client-facing processes, with an owner for each.No fixed deadline
- Document governance, testing, data-quality and bias controls for each client-facing AI use, and how staff can override its output.No fixed deadline
- Check client information and marketing for AI-supported services and tokenised products against MiFID II and, where relevant, MiCA.No fixed deadline
- Make sure reliance on outside AI providers is captured in the DORA register of information and ICT risk assessments.No fixed deadline
- Prepare to answer supervisory surveys or information requests on AI and tokenisation during 2027.No fixed deadline
In the exam
In the CySEC Advanced and Basic exams this links to the MiFID II organisational requirements, conduct of business rules and the duty to act in the client's best interest, which ESMA expects firms to respect when they use AI.
Related study notes
Preparing for an exam?
Practise the topics behind this update
Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.
- CySEC AdvancedSee the CySEC Advanced packsTry the free demo
- CySEC BasicSee the CySEC Basic packsTry the free demo
Sources
- ESMA sets new supervisory priority on digital innovation from 2027 (opens in a new tab)
ESMAOfficial text
- Union strategic supervisory priorities (USSPs) – factsheet (opens in a new tab)
ESMAOfficial text
- 2027 Annual Work Programme (ESMA22-50751485-1673) (opens in a new tab)
ESMAOfficial text
- ESMA provides guidance to firms using artificial intelligence in investment services (opens in a new tab)
ESMAOfficial text
- EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector (opens in a new tab)
ESMAOfficial text
Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.
This document has been drafted using material downloaded from ESMA's website. ESMA does not endorse this publication and in no way is liable for copyright or other intellectual property rights infringements nor for any damages caused to third parties through this publication.