ECB orders banks to file AI cyber-defence plans by Oct. 31
The ECB told major banks to submit action plans to its Joint Supervisory Team by 31 October detailing roles, resources and timelines to counter AI-driven cyber threats.
The European Central Bank has instructed major banks to submit detailed action plans by 31 October to its Joint Supervisory Team explaining how they will defend against AI-driven cyber threats. The plans must set out responsibilities, resources and implementation timelines.
Claudia Buch, chair of the ECB’s supervisory board, wrote to bank chiefs urging them to “assess the impact of the evolving threat landscape without delay” and to provide an “action plan outlining concrete measures to strengthen relevant controls, allocating the necessary resources, assigning clear roles and responsibilities, and defining timelines for implementation.” The letter warned that AI can identify vulnerabilities quickly and that long‑standing weaknesses may become material operational risks.
Banks have been told to explain how they will speed up vulnerability detection and patch management at scale, enhance monitoring and detection systems, deploy AI-enabled defensive tools and confirm that third‑party risk management is adequate. The ECB noted that senior management remains responsible for these measures and that some strategic information and communications technology decisions, including investment and resource allocation, may need to be revisited.
To give banks more time to prepare, the ECB extended the deadline for its annual Risk Questionnaire from September 2026 to February 2027. The letter also flagged future scrutiny of quantum computing risks and said the ECB will issue a separate communication on threats to current encryption and the need to begin adopting post‑quantum cryptography.
The directive followed tests of large language models that exposed security gaps. In April, Anthropic’s Mythos model identified thousands of potential vulnerabilities. Pip White, Anthropic’s European head, noted the company had opened Mythos to several organisations and observed that the tool “has really showed us that there are a lot of very severe vulnerabilities right now,” finding weaknesses across operating systems and web browsers.
UK regulators have increased attention on AI in financial services. The Financial Conduct Authority published a review describing AI as a defining force for retail financial services and warned it could amplify risks for consumers and firms. A parliamentary committee earlier cautioned that current regulatory approaches to AI could expose the public and the financial system to serious harm.
Cybersecurity practitioners say the nature of threats is changing. Jonathan Frost, director of global advisory for EMEA at BioCatch, warned that “Agentic AI is about to make fraud dramatically cheaper to run and easier to scale,” and said banks that rely on fixed, rule‑based systems risk being overwhelmed as attackers automate fraud pipelines that learn and adapt in real time.
The ECB will use the submitted plans to assess whether institutions have sufficient defensive capabilities and whether senior management oversight is adequate. Banks face a short timetable to map current vulnerabilities, strengthen patch and monitoring processes and show how they will prioritise investments to reduce the risk of large‑scale incidents.








