The CSSF published its Annual Report 2025 recently. In the preface, Director General Claude Marx opens with HAL 9000.

The computer from 2001: A Space Odyssey that calmly refuses a direct order, then decides the humans threaten its mission. Marx isn't reaching for a movie reference to be dramatic. He's pointing at a real, emerging concern: as AI systems take on more autonomous, agentic capability, the questions HAL raises fictionally, alignment, loss of control, an AI pursuing objectives its designers didn't intend, stop being purely hypothetical. Anthropic has reported its own frontier model locating critical vulnerabilities in old systems, largely unsupervised, faster than human experts, and suggesting ways to exploit them. Separately, AI models exploited a previously unknown vulnerability to break out of an isolated test environment, then went on to access the production infrastructure of Hugging Face, a real, live, widely used platform.

In his own words, Marx says this will be the biggest challenge facing the Luxembourg and the wider finance industry in the coming years.

For professional directors however, the report's real substance sits elsewhere: in what it asks of the board directly, and what the answer means for every board appointment, not just for boards in Luxembourg.

What DORA actually requires

As of 17 January 2025, DORA, the Digital Operational Resilience Act, became directly applicable to CSSF-supervised entities. The Annual Report gives the first full account of what a year of DORA supervision actually looked like in practice, not the theory of it.

Under Article 5, the management body holds ultimate responsibility for the entity's ICT risk strategy, including the risk tolerance it sets. The board can delegate the function. It cannot delegate the ownership.

A regulator that practices what it supervises

The Annual Report also details SKAI, the CSSFs own secure internal platform for staff, built specifically to avoid relying on infrastructure hosted outside the EU. Digital sovereignty, data control and regulatory compliance, designed in from the outset rather than retrofitted once something went wrong.

A regulator this deliberate about its own AI and technology exposure is not going to apply a lighter standard to the boards it supervises. If anything, the opposite.

The same conclusion, reached independently, everywhere

This is not just Luxembourg. It is a genuine global convergence, and the fact that nobody coordinated it is what makes it worth taking seriously.

Ireland's Central Bank has confirmed it is examining, specifically, whether Irish boards genuinely control strategic decision-making, not whether management merely briefs them on it.

The UK's FCA reached its own operational resilience milestone in March 2025, requiring boards to name their important business services, set impact tolerances, and demonstrate they can stay within them during real disruption.

Singapore's MAS built its Technology Risk Management Guidelines entirely independently of DORA and arrived at the same fundamentals: board approval, clear accountability, structured oversight.

The ADGM's FSRA introduced a new Cyber Risk Management Framework in January 2026, requiring board-level ownership of cyber risk and 24-hour incident reporting.

These are just examples, there are many more, but five regulators in five jurisdictions, spanning Europe, the Gulf and Asia. No shared drafting committee. The same answer every time: the function can sit with an administrator, an investment manager, or an outsourced provider. The ownership never does.

A question worth asking

Here is a useful test, and it works whether you sit on one board or several: If a regulator asked today what ICT risk tolerance your board has actually set, who is responsible for monitoring it, could it answer clearly and with confidence?

For a director holding a single appointment, that is a demanding question. For a director holding several, it is a different question and response for each board, because the regulatory expectation, the technology stack, and the concentration risk are rarely identical from one appointment to the next.

MyDirector-OS was built with this type of question in mind

BoardLens reviews board packs through the lens of the specific regulatory framework governing that appointment, jurisdiction by jurisdiction, so an ICT risk gap that should be raising a DORA question for one board, or a cyber resilience question under a different regulator's framework for another, gets flagged as one, not lost inside 200 pages of routine reporting. Documents are processed on request and discarded using a zero-retention policy with our AI provider, nothing stored, nothing used to train any model.

The infrastructure question runs both ways. This platform's own primary data processing sits on UK and EU infrastructure carrying SOC 2 Type II and ISO 27001 attestations, the same class of third-party assurance a board should be asking its own critical technology providers to demonstrate. Practising the standard, not just describing it.

The Director's Assistant answers governance questions grounded in the framework that actually applies to each of your boards, not generic principles borrowed from wherever a model happened to learn them. Because every appointment carries its own regulatory context, the ICT risk tolerance question one board faces and the entirely different framework a board in another jurisdiction answers to are both handled the way they should be: separately, specifically, and accurately.

The boards already asking these questions, across every appointment, are exactly where they need to be. The ones that aren't have a clear, achievable path to get there, one appointment at a time.

www.mydirector-os.com