AI in Cyprus Financial Services: What CySEC and EU Rules Actually Require
Artificial intelligence is moving quickly into trading platforms, portfolio management, fraud detection and client onboarding across Cyprus's large investment-services sector. That has prompted a fair question: how does the Cyprus Securities and Exchange Commission (CySEC) actually govern the technology? The short answer is that there is no single, standalone CySEC "AI rulebook". Instead, firms must read a set of overlapping European rules alongside CySEC's supervisory priorities and circulars.
What CySEC has actually said
CySEC named AI as a thematic supervisory priority for 2025, alongside the online promotion of financial products by so-called "finfluencers". Its supervisory-priorities document signalled thematic reviews of how regulated firms use AI in areas such as client communication, investment advice and risk management, and said the regulator would issue circulars and technical guidance and run workshops to clarify its expectations.
In June 2025, CySEC issued Circular C709, which drew regulated entities' attention to a voluntary survey launched by the European Securities and Markets Authority (ESMA) on AI adoption in the securities sector. The survey examined firms' AI strategies, policies, investment levels and operational use cases; responses were collected on an anonymised, aggregated basis, with a completion deadline of 29 August 2025.
The ESMA guidance underneath it
The substantive expectations for investment firms come largely from ESMA. In a public statement published on 30 May 2024, ESMA set out initial guidance for firms using AI when providing investment services to retail clients. Its central message is that existing MiFID II obligations already apply: firms must act in the best interests of clients and meet organisational and conduct-of-business requirements, regardless of whether a human or an algorithm is involved.
ESMA flagged specific risks that boards and compliance functions are expected to manage:
- Algorithmic bias and poor data quality
- Opaque decision-making by staff who rely on AI
- Over-reliance on AI by both firms and clients
- Privacy and security risks tied to large-scale data processing
ESMA listed customer support, fraud detection, risk management, compliance, investment advice and portfolio management as use cases that fall within MiFID II. It confirmed that it and national regulators, including CySEC, would keep monitoring the area.
Two other rulebooks firms cannot ignore
Two further EU frameworks shape AI governance in practice. The Digital Operational Resilience Act (DORA), which applies from 17 January 2025, imposes a binding information-and-communications-technology risk-management regime on investment firms and other financial entities. That is directly relevant to AI systems and the third-party providers behind them.
The EU AI Act entered into force on 1 August 2024 and applies in phases. Bans on certain practices and AI-literacy duties took effect on 2 February 2025, and obligations for general-purpose AI models from 2 August 2025. Some financial uses, such as AI-based creditworthiness assessment, are classed as "high-risk". The timetable for those high-risk obligations was eased in 2026: under the EU's "Digital Omnibus" simplification package, agreed by the Council and Parliament and given final Council approval on 29 June 2026, the main high-risk requirements for stand-alone systems were deferred to 2 December 2027.
What this means for firms
For Cyprus-based investment firms, the practical takeaway is that AI is being supervised through existing conduct, governance and operational-resilience rules rather than a bespoke Cyprus code. Firms should document their AI use cases, address bias and explainability, keep humans accountable for outcomes, and track both the AI Act timeline and any further CySEC circulars. As a national competent authority within the EU framework, CySEC's job is to apply and supervise these rules locally, and it has said further guidance will follow.