ECB orders banks to file AI cyber-security action plans

The ECB has ordered major banks to submit AI-focused cyber-security action plans to its Joint Supervisory Team by Oct. 31 detailing controls, resources, roles and timelines.

The European Central Bank has ordered major banks it supervises to submit action plans by Oct. 31 explaining how they will defend against AI-enabled cyber attacks.

The letter, signed by Claudia Buch, chair of the ECB’s supervisory board, requires firms to assess the evolving threat landscape and provide an action plan outlining specific measures, resources, roles and implementation timelines.

Buch asked banks to accelerate vulnerability and patch management at scale, enhance monitoring and detection, develop AI-enabled defensive capabilities and confirm that third-party risk management is adequate.

The plans must document measurable changes to controls and how firms will monitor AI-enabled attacks, speed up patching of known vulnerabilities and manage risks from external suppliers. The requirement covers all institutions supervised directly by the ECB.

Banks will submit plans to the Joint Supervisory Team, which will review the responses and the proposed actions and may require further remediation or escalate where plans are judged insufficient.

The ECB set a four-month deadline for compliance. To allow banks extra time, it extended the deadline for its annual Risk Questionnaire from September 2026 to February 2027.

The letter follows incidents in April in which Anthropic’s Mythos model identified thousands of security flaws. Pip White, Anthropic’s European head, said the company had made Mythos available to Microsoft, Amazon Web Services and some financial firms and that the model found vulnerabilities across operating systems and web browsers.

Buch noted the ECB will address risks from advances in quantum computing separately and said the adoption of post-quantum cryptography ‘may involve a longer time frame, but must start now and necessitates sustained, strategic investment over time.’

UK regulators have increased scrutiny of AI risks in finance. The Financial Conduct Authority published a review describing AI as a ‘defining force’ that could amplify risks to consumers and markets.

Jonathan Frost, director of global advisory for EMEA at cyber security firm BioCatch, warned that agentic AI could make fraud cheaper to run and easier to scale and that firms relying on fixed rules risk being overwhelmed as attackers automate adaptive fraud pipelines.

The supervisory board emphasized that management is responsible for delivering the plans and may need to review ICT-related strategic decisions, including investment and staffing.

Articles by this author