The CSSF has just published its Annual Report 2025. EUR 6.731 trillion in fund assets under management. A new AI supervision platform. DORA, the Digital Operational Resilience Act, entering its first full year of enforcement. And a direct statement to every board of a Luxembourg-regulated entity: governance structures must support effective management of frontier AI risk.
The CSSF is not alone. In Ireland the Central Bank confirmed it is monitoring the control that Irish boards exercise over decision-making, explicitly at board level. In the UK the FCA operational resilience framework passed its final implementation milestone in March 2025. In ADGM a new Cyber Risk Management Framework came into force in January 2026. In Singapore the MAS technology risk framework places the same obligations on the board.
Across every jurisdiction where professional directors hold appointments, the same message has arrived. Digital operational resilience is a board obligation.
On Wednesday the MyDirector-OS journal will ask, what that obligation actually means to you, the professional director, and whether your board(s) can answer the questions the regulators are starting to dig into.
