The European Union’s leading markets regulator will begin direct supervision of artificial intelligence and tokenization applications in financial services. This marks a significant shift from establishing regulations to actively enforcing them. The European Securities and Markets Authority (ESMA) confirmed on Wednesday, 2024-09-18, that these technologies will become a Union Strategic Supervisory Priority (USSP) starting in 2027.
This initiative establishes a coordinated oversight framework across the 27-nation bloc. It empowers ESMA and national regulators to scrutinize how financial firms integrate these rapidly evolving technologies into their core business. The program, dubbed “Innovation with investor safeguards,” aims to balance the benefits of financial technology with robust investor protection.
EU Markets Authority shifts focus to enforcement
The decision reflects a growing recognition within the EU that AI and blockchain are no longer confined to niche crypto markets. Mainstream financial institutions are adopting them to gain a competitive edge. As the industry moves towards the tokenization of traditional assets, regulators are increasingly focusing on practical implementation and its potential risks.
The EU’s regulatory journey has seen a strong emphasis on foundational legislation, including the Markets in Crypto-Assets (MiCA) framework, for which rules have been set. With such frameworks established, ESMA’s announcement ushers in a new phase of supervision. This phase targets enforcement, not just for crypto assets, but for the underlying technologies across the broader securities industry.
Under the new USSP, ESMA and National Competent Authorities (NCAs) will first map the financial sector’s existing and planned use of AI and tokenization. Their focus includes products that directly affect investors, extending beyond back-office functions to encompass core activities and client-facing applications. Following this mapping, supervisors will conduct targeted checks on firms deemed most exposed or at-risk by these new technologies.
A primary goal of this program is to foster a consistent supervisory culture and expertise across the European Union. Through coordinated efforts, ESMA aims to prevent regulatory arbitrage, where firms might exploit differences in oversight between member states. The initiative also commits to sharing best practices and showcasing innovations that genuinely enhance investor outcomes, reduce bias, and deliver reliable results.
Identifying key risks in digital finance innovation
ESMA detailed specific risks it plans to address through this new supervisory priority. For artificial intelligence, the agency is particularly concerned about biased or misleading AI outputs. This is especially critical in areas such as automated financial advice or credit scoring, where accuracy directly impacts consumers.
The complexity and potential opacity of some AI-driven models, often referred to as the “black box” problem, also pose significant challenges for supervisors and investors. For tokenization, ESMA highlighted worries that the intricacy of certain on-chain investment products might surpass the understanding of retail investors, potentially leading to unsound financial decisions.
The agency also pointed to the concentration risk stemming from the industry’s reliance on a limited number of third-party technology providers for crucial infrastructure.
This digital innovation focus will operate alongside an ongoing USSP on cyber and operational resilience, which began in 2025. It also follows the conclusion of a priority on environmental, social, and governance (ESG) disclosures launched in 2023. Additionally, some European supervisory authorities have started assessing other long-term technological risks, such as those posed by quantum computing.
Broader EU institutional alignment on digital finance
ESMA’s actions are part of a larger, coordinated push by European institutions to manage the expanding digital finance sector. The European Central Bank (ECB) has been actively involved, recently announcing plans to invest a small portion of its reserves in tokenized securities. This provides the ECB with direct exposure and experience in blockchain-based markets.
The ECB also launched Pontes, a new wholesale platform designed to bridge digital ledger technology (DLT) infrastructure with the bloc’s traditional payment systems. This further integration aims to connect traditional finance with decentralized finance. Concurrently, the ECB and the 27 member-country central banks have advocated for an expanded ban on crypto platforms offering yields or rewards on stablecoins.
Their argument is that fiat-pegged digital assets function as money, not investment or savings products. This stance carries significant implications for the DeFi lending sector. The European Central Bank has clearly communicated its requests to policymakers, aiming to influence the final implementation of stablecoin rules under MiCA to align with this conservative monetary perspective.
Navigating a complex regulatory timeline
The 2027 commencement date for ESMA’s new priority holds considerable significance, as it aligns with other critical regulatory timelines. Notably, the compliance deadline for specific high-risk AI applications in financial services under the EU AI Act saw a recent extension.
This deadline moved to December 2, 2027, covering AI systems for creditworthiness assessments and risk pricing in life and health insurance, offering firms and regulators additional preparation time.
However, certain provisions of the AI Act are already in effect. Transparency obligations for firms utilizing AI systems that interact with humans or generate content became active on August 2, 2026. This multi-layered regulatory schedule underscores the intricacy of the EU’s supervisory framework.
Other key bodies, including the European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA), are also advancing their work on digital transformation, AI ethics, and operational resilience.
For financial firms operating across the EU, this converging regulatory attention means technology is now a central compliance focus, not merely a business enabler. The era of rapid deployment without prior regulatory consideration is definitively over.
Firms must now demonstrate robust governance, reliable data management, and a clear alignment with customer interests from the outset, all under the vigilant eye of an increasingly digitally-savvy supervisory cohort.
