Major Banks Face October Deadline
The European Central Bank has instructed the eurozone’s largest banks to explain how they plan to strengthen their cybersecurity defenses against more advanced artificial intelligence systems. The 110 lenders directly supervised by the ECB must submit their plans by 31 October.
AI Changes the Threat Environment
The ECB’s supervisory board warned that the latest AI models are reshaping the cybersecurity landscape for financial institutions. In a letter to banks, Claudia Buch, chair of the ECB’s Supervisory Board, described these systems as a “long-term shift in the threat landscape rather than a temporary phenomenon”.
Risks Are Faster and Larger in Scale
Buch noted that AI does not necessarily create entirely new cyber risks, but it can make existing ones more dangerous. She wrote: “While these developments do not introduce entirely new risks, they significantly amplify the speed and scale at which such risks materialise.”
Plans Required From Leading Lenders
The ECB is asking major banks, including Deutsche Bank, BNP Paribas and Santander, to outline both immediate and longer-term actions. These plans must show how each institution will improve resilience against cyberattacks in a more advanced AI environment.
What the ECB Wants Banks to Prioritise
The requested plans should focus on faster vulnerability detection, quicker software patch management, stronger AI-enabled monitoring systems and improved cyber threat detection. The ECB also wants banks to examine third-party technology providers and supply-chain risks more closely.
Senior Leadership Must Direct the Response
The ECB stressed that the response cannot be treated as a purely technical matter. The effort must be led from the highest levels of each institution, reflecting the growing importance of cyber resilience as a strategic risk for the banking sector.
Supervisory Calendar Adjusted
To give banks more time to address the issue, the ECB will delay its annual IT Risk Questionnaire from September 2026 to February 2027. It also said it may adjust other supervisory activities on a case-by-case basis.
ECB Will Compare Sector-Wide Responses
After the October deadline, the ECB will review each bank’s action plan and discuss it directly with the institution. It will also conduct a horizontal analysis across the sector to identify common vulnerabilities and examples of stronger practice.
Anthropic Model Raises Concerns
The rise of frontier AI models, including Anthropic’s Mythos, has increased concern among European policymakers. Mythos has been described as particularly effective at identifying weaknesses in computer systems. Anthropic initially withheld the full version because of misuse concerns, before releasing a public version last month with built-in safety safeguards.
Quantum Computing Also on the Radar
The ECB letter also pointed to other emerging technologies, including quantum computing. It said quantum computing “will have a significant impact on the cybersecurity landscape” and added that those risks will be addressed in a separate letter “in due course”.
Systemic Cyber Risk Raised to Severe
The ECB’s move comes as the European Systemic Risk Board, the EU body responsible for monitoring systemic financial risks, issued its own warning about “systemic cyber risks stemming from frontier artificial intelligence models”. In June, the ESRB General Board raised its assessment of systemic cyber risk from “elevated” to “severe”.
AI Seen as a Paradigm Shift
The ESRB said frontier AI models represent a “paradigm shift” in cybersecurity and have become a potential source of systemic risk for the EU financial system. It also warned that “AI is already being used by malicious actors to enhance cyber-attacks”.
Less Time to Respond to Threats
According to the ESRB, more capable AI systems could sharply reduce the time banks have to identify and fix software vulnerabilities before they are exploited. This raises the risk of multiple cyber incidents occurring across the financial sector at the same time.
Europe Faces Strategic Dependence
The ESRB also warned that many leading frontier AI developers are based outside the European Union. This concentration could expose the bloc to strategic dependency and geopolitical risks as AI becomes more important to financial security and operational resilience.