ARTICLE

August 2026 Global Regulatory Brief: E-delivery, cyber concentration and frontier AI risks

Bloomberg Professional Services

As technology continues to reshape financial services, regulators and policy setters are embarking on a range of digital-finance initiatives to manage risks and set appropriate standards. The following digital finance policy developments represent a sample of wider regulatory and policy coverage available to Bloomberg Terminal customers. Run REGS <GO> to find out more or contact your Bloomberg representative to learn more:

  • US: SEC proposes Regulation E-Delivery
  • Hong Kong: Regulators flag third-party cyber concentration risks
  • Korea: Ministries announce financial and digital asset reform
  • EU: ESAs call for supervisory approach to frontier AI risks

Explore the latest regulatory insights with our outlooks, webinars, research and analysis.

Sign up

SEC proposes Regulation E-Delivery

The U.S. Securities and Exchange Commission (SEC) has proposed Regulation E-Delivery to make electronic delivery the default method by which market participants satisfy information delivery requirements under federal securities laws.

Overview:
Regulation E-Delivery is intended to make information more readily accessible while preserving the ability to receive delivery in paper format on request. According to the SEC, the proposal is intended to reduce paper, printing and postage costs for issuers, market intermediaries and investors. 

Technological context:
SEC Chair Paul Atkins cited developments in artificial intelligence and blockchain technology as part of the rationale for reconsidering paper as the default delivery method. 

  • The SEC stated that electronic delivery could support more personalized, interactive and timely access to disclosures. 
  • The SEC also identified potential accessibility and information retention benefits. 

In-scope documents:
The range of information deliverable electronically under the proposed rule would be broad, including prospectuses for funds and other issuers, fund annual and semi-annual shareholder reports, proxy statements, trade confirmations, disclosures pursuant to Form CRS, and Form ADV Part 2 brochures.

Next steps:
The public comment period will remain open for 60 days following publication of the proposing release in the Federal Register.

Hong Kong regulators flag third-party cyber concentration risks

A joint cross-sector mapping exercise by Hong Kong financial regulators identified no new systemic cyber risks and highlighted third-party technology concentration as an area for supervisory monitoring. 

Context:
The Hong Kong Monetary Authority (HKMA), Securities and Futures Commission (SFC), Insurance Authority (IA), and Mandatory Provident Fund Schemes Authority (MPFA) released a joint circular summarizing their first cross-sector Cyber Mapping initiative completed in March 2026. Prompted by Financial Sector Assessment Program recommendations, the exercise mapped roughly 2,900 operational dependencies across more than 50 financial entities spanning banking, securities, insurance, wealth management, and pensions.

Key takeaways: 

  • No new systemic threats: The assessment confirmed that systemic cyber risk remains concentrated among major financial entities, market infrastructures, and large-scale technology providers already subject to supervisory monitoring.
  • Third-party concentration: The mapping identified shared dependencies across firms on specific specialized vendors. Concentration was particularly evident in network hardware appliances, cybersecurity tools for access management and event monitoring, and specialist vendors for payments and communications.
  • Enhanced supervisory monitoring: Authorities emphasized that vendor concentration does not imply existing vulnerability, but warrants continued supervisory monitoring to manage systemic interdependencies.

Next steps:
Regulators intend to make cyber mapping a permanent supervisory tool, with the next exercise expected in 2027/2028. Authorities will use the current dataset to inform daily oversight, thematic reviews, cross-sectoral disaster drills, and joint contingency planning, while evaluating potential options to share interactive mapping tools directly with financial institutions in the future.

Korea announces financial and digital asset reform strategy

The government’s second-half 2026 economic plan outlines proposed reforms covering digital assets, capital markets and state-backed investment. 

Context:
The Ministry of Finance and Economy released its policy strategy for the second half of 2026, outlining institutional and regulatory changes across financial markets. The strategy includes measures relating to digital assets, capital markets, foreign exchange and investment infrastructure, alongside efforts related to Korea’s potential inclusion in the MSCI Developed Market Index. 

Key takeaways: 

  • Digital asset framework: Introducing a digital asset basic act to formally segment the industry and regulate stablecoins, while amending the Capital Markets Act to allow spot crypto ETFs.
  • Capital market internationalization: Expanding won-denominated investment assets for foreign entities, transitioning the forex market to 24-hour trading, and relaxing borrowing limits for foreign financial institutions.
  • Trading infrastructure: The strategy proposes shortening the equity settlement cycle from T+2 to T+1. 
  • Sovereign wealth fund restructuring: Creating a separate strategic investment account within the Korea Investment Corporation to deploy long-term equity into critical national mega-projects.
  • Blockchain integration: Deploying a government bond tokenization pilot project tied directly into the Bank of Korea’s institutional CBDC framework while reviewing network interoperability.
  • Risk and oversight: Forming a high-level macro-prudential soundness council across top regulators and introducing a regulatory sandbox integrated management act covering technology commercialization.

Next steps:
The 24-hour foreign exchange trading framework and a new global core investor council are set to launch in July 2026. The government will publish its detailed T+1 stock settlement roadmap by October 2026, followed by the operation of the offshore won settlement system in January 2027. The central bank’s bond tokenization pilot project is slated to begin in 2027.

ESAs call for supervisory approach to frontier AI risks

Overview:
The European Supervisory Authorities have issued a Joint Committee statement on a consistent and risk-based approach to ICT risks from frontier AI models. The statement highlights that frontier AI capabilities may increase cyber risks by enabling rapid vulnerability discovery and exploitation and increasing risks associated with shared infrastructure and single points of failure across financial entities. The ESAs call for financial entities to address these risks proactively, with measures applied proportionately according to their size, risk profile and the nature, scale and complexity of their activities.

Context:
The statement follows the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, the ESRB warning on systemic cyber risks from frontier AI models, and ENISA recommendations on cybersecurity in the frontier AI era. It also refers to supervisory attention already being given to these risks, including the ECB’s request for significant institutions to address open ICT and security findings without delay.

Key takeaways:

  • Existing framework remains relevant: The ESAs identify DORA and the AI Act as the main EU regulatory foundations. DORA remains relevant through ICT risk management, testing, incident and recovery management, and ICT third-party risk management. The AI Act provides a framework for general-purpose AI models with systemic risk, including additional obligations on providers.
  • Three mitigation strategies: The ESAs identify three areas for financial entities to consider when adjusting ICT risk management processes, procedures and controls: prevention, detection and management. Prevention includes updated IT asset inventories, secure-by-design principles, proactive patching and dependency assessment. Detection includes scaling up vulnerability discovery, continuous monitoring and enhanced SOC and red-teaming capabilities. Management includes operational resilience testing, disaster recovery, data backups, governance updates and cyber maturity.
  • Governance and risk appetite: The ESAs state that competent authorities should ensure that financial entities’ management bodies are engaged in mitigating frontier AI-related cyber risks. The statement also indicates that risk appetite frameworks should be reviewed to update metrics, tolerance thresholds and controls reflecting both the internal use of frontier AI models and indirect exposure to them. 
  • Proportionate approach: The ESAs state that a one-size-fits-all approach would not be proportionate or efficient. Financial entities should take into account their size, overall risk profile, interconnectedness, and the nature, scale and complexity of their services, activities and operations, consistent with DORA Article 4.
  • Annex of illustrative actions: The annex provides examples of possible actions, including automated security controls, security and resilience by design, source-code confidentiality, attack-surface reduction, proactive patching, supply-chain cybersecurity standards, continuous vulnerability monitoring, behavioral logging, updated business continuity processes, AI-enhanced resilience testing and automated escalation procedures. The annex states that it does not establish additional requirements and should not be treated as a comprehensive checklist.
  • Critical third-party providers: The ESAs, acting as Lead Overseers, have started targeted engagement with relevant critical ICT third-party providers to understand how they identify, assess and manage frontier-AI-related challenges. The insights have informed the annual risk assessment cycle and the prioritization of activities under the 2027 Oversight Plan.

Next steps:

  • The ESAs will continue working with competent authorities to maintain a proportionate, risk-based and forward-looking approach to risks from advanced AI models with cyber capabilities.
  • AI-related risks are being embedded into the ESAs’ Oversight Examination Methodology and will be incorporated into oversight examinations and other oversight activities in 2027, particularly for assessing the preparedness and resilience of critical ICT third-party providers.

Related Content

Get insights delivered to your inbox

Sign up for Bloomberg Professional Services newsletter