In June 2026, the body responsible for watching systemic risk to the European financial system raised its assessment of systemic cyber risk to severe, up from elevated three months earlier. In July it made the reason public. The European Systemic Risk Board called frontier AI models “a paradigm shift for cybersecurity,” warning that in the short to medium term they hand attackers the ability to find flaws and execute attacks with “increased speed, scale and sophistication.” The European supervisory authorities endorsed the warning the same day. The European Central Bank's supervisory arm wrote to the largest banks it oversees, asking for concrete action plans by the end of October.
This matters because of who said it. Not a vendor. Not an analyst. The financial-stability apparatus of the European Union, raising a formal flag and asking supervisors to reflect the risk in how they oversee the system. When that machinery moves — and moves from “elevated” to “severe” — the question stops being whether the risk is real and becomes how anyone will evidence it when it materialises.
The warning identifies the exposure. It does not resolve the harder question underneath it: when an AI-enabled incident occurs on a regulated firm's surface — conduct the firm did not author and cannot fully see — what will stand as the account of what happened?
Today, that account is assembled after the fact, by the party with the most at stake in how it reads. A firm reconstructs its own incident. A provider documents its own system. Each is doing its best; each is also interested. And interest is precisely the problem a supervisor, a court, or a counterparty has to price when the reconstruction is challenged.
The instinct is to assume the EU AI Act already closes this. It largely does not, and the detail matters.
For most high-risk AI systems, the Act's conformity route is internal control — the provider assesses its own system, without an independent notified body. Independent third-party assessment is the exception, reserved mainly for biometric and certain product-embedded systems, not the rule. Post-market monitoring, likewise, runs on a plan the provider draws up and maintains for its own system.
In other words, the dominant model the Act relies on is the system, and its operator, attesting to themselves. This is not a loophole — it is a deliberate design choice. But it is a design choice with a known weakness: there is documented scepticism about whether self-assessment and self-certification, without an independent party, are sufficient. That scepticism existed before a supervisor called the underlying risk severe. It is sharper now — and the supervisors themselves have said so. In endorsing the warning, the European supervisory authorities noted that while the existing framework, including DORA and the AI Act, is a solid foundation, “the speed and scale of these tools raise concerns that AI-enabled cyber-attacks could undermine the operational resilience of financial entities.” A solid foundation, in the regulators' own words, that the pace of the threat may outrun.
Set the two facts side by side. A supervisor has raised systemic cyber risk from frontier AI to severe. And the compliance framework beneath it leans, for most systems, on the operator's own account of its own behaviour.
Between those two facts sits a gap that no amount of better self-documentation can close, because the gap is structural, not procedural. A record produced by a party with an interest in the outcome is not neutral evidence — not because the party is dishonest, but because interest and neutrality cannot reside in the same author. “We monitored ourselves and it looked fine” is not a defence that survives a determined challenge, whether from a regulator or across a claims dispute. The point is old and well settled in evidence law: the account that carries weight is the one made contemporaneously, by something with no stake in how it is later read.
The Act names the notified body, the post-market plan, the conformity route. The warning names the risk. Neither names the witness — the independent observer, sitting outside the trust boundary of the system being observed, whose record can be checked by anyone without trusting the observer.
That witness has specific properties, and they are not rhetorical:
Outside the trust boundary. It observes the conduct from the receiving surface, not from inside the observed system or from logs the system itself emits. What it records is not the operator's self-report; it is the act as it reached the surface.
Contemporaneous. The record is made as the conduct happens, not reconstructed afterward when the outcome — and the incentive — is already known.
Self-verifying. Its integrity does not rest on trusting the party that produced it. The record can be independently verified — if it were altered, that is detectable — so trust in the operator is replaced by verification of the evidence.
None of this concludes that any party has breached any regulation; that is not a determination this note makes or that an evidence layer should make. It characterises conduct and leaves adjudication to those whose role it is. What it offers the supervisor, the underwriter, the claims handler and the board is the one thing the current arrangement structurally lacks: an account of what happened that the interested parties did not author.
The sequence is the argument. The risk has been called severe by the body whose job is to call it. The framework beneath it rests, for most systems, on self-attestation whose sufficiency is already doubted. And the exposure increasingly arrives as the conduct of third-party automated agents on a firm's surface — behaviour no one deployed, that bypasses the checks built for a slower adversary.
A framework can require an operator to watch itself. It cannot make that operator a neutral witness to its own conduct. That witness has to come from outside — and the market that is about to need it has not yet named it.
For the firm carrying the risk, the exposure is concrete: the incident will happen on a surface you don't fully control, the account of it will be assembled by the party with the most at stake, and the moment it matters — a claim, a dispute, a supervisory review — “we monitored ourselves and it looked fine” is what you will have to defend with. The time to have an independent record is before that moment, not after it.
BotConduct is a receiver-side observatory: a neutral, contemporaneous, cryptographically verifiable record of how automated agents behave on a surface. Not a defence tool, not an adjudicator — a witness. The methodology behind the classification is proprietary and available for independent integrity audit under NDA; the verification itself uses standard, public cryptography, so any third party can confirm a record without relying on us.