ECB Orders Banks to File AI Cybersecurity Plans by Oct. 31
The European Central Bank has told major banks to submit action plans to its Joint Supervisory Team by 31 October detailing measures, resources and timelines to counter AI-driven cyber threats.
The European Central Bank has given major banks until 31 October to submit action plans to its Joint Supervisory Team explaining how they will protect against artificial intelligence-driven cyber threats. The plans must specify concrete measures, allocated resources and implementation timelines.
Claudia Buch, chair of the ECB supervisory board, wrote to bank leaders asking them to assess the impact of the evolving threat landscape without delay and to set out how they will close unresolved security gaps that AI tools can now find and exploit more quickly. The letter asks firms to assign clear roles, secure funding and define dates for changes.
The ECB set out priority areas banks must address in their submissions. Banks should speed up vulnerability and patch management at scale, strengthen monitoring and detection systems, develop AI-enabled defensive capabilities and ensure third-party risk management arrangements are effective.
Buch emphasised that boards and senior management remain responsible for strategic ICT decisions and may need to revisit investment and resource allocations to meet the new requirements.
The request follows testing in April of Anthropic’s Mythos model, which reportedly revealed thousands of vulnerabilities across operating systems and web browsers after being opened to several organisations, including major cloud providers and some financial firms. Anthropic’s European head, Pip White, reported that the tool found severe weaknesses in every major operating system and web browser it tested.
Jonathan Frost, director of global advisory for EMEA at cybersecurity firm BioCatch, warned that agentic AI will make fraud cheaper to run and easier to scale, enabling attackers to automate fraud processes that adapt in real time. He noted that banks relying on fixed, rule-based systems risk being outpaced by such techniques.
To give firms more time to prepare their responses, the ECB extended the deadline for its annual Risk Questionnaire from September 2026 to February 2027. Buch also flagged the development of quantum computing as a longer-term challenge, saying the adoption of post-quantum cryptography will require sustained, strategic investment and that the ECB will address encryption risks in a separate letter.
Supervisors asked banks to file their action plans with the Joint Supervisory Team by 31 October. The ECB signalled it will conduct follow-up reviews and may set further supervisory expectations as new threats emerge.








