ECB tells eurozone banks to file AI cyber-defence plans
The European Central Bank has given eurozone banks four months to submit cybersecurity action plans to address AI-enabled threats by Oct. 31.
The European Central Bank has ordered eurozone banks to produce and submit cybersecurity action plans within four months to address AI-enabled cyber threats, with a firm deadline of Oct. 31. The directive was sent in a letter to bank chief executives and focuses on protecting payment networks and maintaining confidence in the financial system.
The ECB instructed banks to prioritise protection of internet-facing systems and other technology assets that are most exposed to cyber risk. Lenders were told to strengthen the security of third-party software and open-source components, accelerate remediation of known vulnerabilities, and improve continuous monitoring capabilities. The central bank also asked institutions to modernise ageing technology infrastructure and raise basic cyber hygiene standards across operations.
Supervisors asked banks to bolster crisis-management arrangements, recovery plans and information-sharing mechanisms to improve readiness for potential incidents. To help banks focus on these requirements, the ECB has postponed a separate information technology survey and said it may adjust planned inspections and other supervisory activities to free up resources for the new initiatives.
The letter notes that advances in artificial intelligence have reached a level where some models are now subject to access restrictions, and that those restrictions currently do not include eurozone banks. The ECB wrote in the letter: “These developments have potentially profound implications for the confidentiality, integrity and resilience of banks’ information and communication technology systems.”
Alongside the ECB directive, the European Systemic Risk Board published a warning about broader financial stability risks from large-scale cyber incidents. The ESRB outlined scenarios in which AI-enabled attacks could erode confidence in smaller banks, be used in state-backed espionage campaigns, or be coordinated to disrupt payment, clearing and settlement systems. The board also highlighted the risk that misinformation could amplify uncertainty and that incidents could spread rapidly through widely used software and shared technology providers.
Banks must submit action plans to the ECB by Oct. 31. The plans should assess vulnerabilities, set priorities for protections and present concrete measures for strengthening cyber resilience in response to the increased capabilities of AI tools.








