Skip to main content

Article

Cyber risks and AI: the ECB requires an action plan by 31 October 2026

ECB calls on banks to deliver an Oct 31, 2026 action plan to strengthen DORA-based resilience against AI-enabled cyber threats and supply-chain risk.

In line with the warning adopted on 25 June 2026 by the European Systemic Risk Board (ESRB) on cyber risks related to frontier AI models (FAIM), the ECB is calling on significant banking institutions to take immediate and proactive measures.

The ESRB defines frontier models as general-purpose models capable of affecting offensive and defensive cyber operations. They can notably accelerate vulnerability discovery, exploit generation, and the automation of complex attacks. While not necessarily creating new risks, these models are likely to profoundly alter their speed, scale, and impact.

This trend is already observable. According to METR, an independent organisation specializing in evaluating the autonomous capabilities of AI models, frontier models could in 2020 only accomplish tasks corresponding to a few seconds of human work. The most recent models today succeed one time out of two in carrying out certain software tasks whose execution would take nearly sixteen hours for a human expert.

The ESRB considers that in the short and medium term, this development could benefit attackers and increase the risk of spillover across institutions, market infrastructures, and their critical service providers. In addition to this operational threat, there is a strategic issue: the concentration of the main providers of these models outside the EU exposes the European financial system to risks of technological dependence, sovereignty, and geopolitical tensions.

Main ECB expectations

In a letter addressed on 7 July 2026, to the leaders, the ECB asks them to assess without delay the impact of these threats and to submit no later than 31 October 2026, a comprehensive action plan aimed at strengthening their resilience to AI-enabled cyber threats.

This plan must specify the concrete measures, the resources mobilized, the responsibilities, and the implementation schedule.

The letter emphasizes in particular the following priorities:

What is changing: the increase in the number of vulnerabilities,dynamic attack vectors and the reduction in the time between their discovery and exploitation are gradually making the traditional remediation cycle obsolete. Banks therefore must not only remediate more quickly, but also sustainably absorb a higher volume of vulnerabilities, without increasing the risks of error, unavailability, or disruptions linked to changes that are too rapid or insufficiently tested.

Main expected actions:

  • Map the most exposed ICT assets: systems accessible from the Internet, remote access, cloud environments, connections with providers, third-party software, and open-source components;
  • Minimise and continuously monitor assets, then prioritise vulnerabilities according to their criticality, exploitability, and potential impact on critical or important functions;
  • Strengthen and automate, where appropriate, scanning and prioritization, including with the support of AI tools; 
  • Plan for emergency procedures and increase the capacity to deploy patches on a large scale;
  • Adapt change management to accelerate remediation without compromising operational stability.

Contracts and service levels with ICT service providers must also enable the rapid reporting of vulnerabilities, the communication of mitigation measures, and the provision of patches within appropriate timeframes. Nevertheless, it is up to the bank to preserve its own capabilities for monitoring, detection, and effective tracking of patches.

What is changing: the acceleration and automation of attacks are reducing the time available to detect a compromise and contain it. The ECB considers that a prudent security posture must now incorporate the assumption that perimeter defenses may be breached.

The challenge is therefore no longer merely to prevent intrusion, but also to quickly detect a compromise, limit its spread, and maintain critical or important functions.

Main expected actions:

  • Strengthen the analysis of logs, network traffic, and indicators of compromise, particularly on exposed applications, cloud environments, and critical systems;
  • Segment or even micro-segment networks to contain an attack;
  • Apply zero trust principles, with continuous access verification, secure configuration,, multi-factor authentication, and least privilege;
  • Keep asset inventories up to date; 
  • Isolate, upgrade, or replace legacy, unsupported, or end-of-life systems;
  • Integrate security from the design stage of software development.

The ECB invites banks to develop AI-assisted defensive capabilities. However, their deployment must be preceded by an assessment of the benefits and risks and remain governed by clear governance, appropriate controls, and human oversight.

What is changing: shared dependencies can turn an individual technical incident into a systemic risk.

Main expected actions:

  • Integrate and monitor external applications and services integrated with the bank's systems;
  • Verify providers’ readiness for accelerated vulnerability disclosure and higher patch volumes;
  • Review subcontracting chains, concentrations, cloud dependencies, and exit strategies;
  • Review contracts and service-level agreements to adapt providers’ obligations to the increasing speed and scale of these cyber threats.

Please note that as of 11 September 2026, manufacturers subject to the Cyber Resilience Act will be required to inform their customers of actively exploited vulnerabilities or serious incidents affecting their digital products. They will also need to communicate, where necessary, the corrective or mitigating measures to be applied.

What is changing: faster, more automated attacks, likely to affect multiple systems or providers simultaneously, significantly reduce the time available to contain the incident and restore operations.

Main actions expected:

  • Adapt and regularly test incident response, backup, failover, restoration, and crisis management measures;
  • Integrate large-scale scenarios: exploitation of zero-day vulnerabilities, destructive attacks, ransomware, compromise of a service provider, interruption of a cloud service;
  • Plan for degraded operating modes that make it possible to maintain essential services; 
  • Strengthen secure mechanisms for sharing information on vulnerabilities, threats, defensive strategies, and remediations.

What is changing: the acceleration of cyberthreats may render insufficient the budgets, staffing, tools, and levels of risk tolerance defined up to now.

Main expected actions: The management body must reassess the digital operational resilience strategy, including the ICT risk appetite framework as well as responsibilities, ICT investments, the adequacy of human resources and training, and change capabilities. It must ensure that the resources allocated are proportionate to the risks and that any identified weaknesses are corrected promptly. To this end, the management body must have a sufficient understanding of the risks related to frontier AI models in order to set strategic directions and oversee their implementation.

DORA remains the main regulatory foundation

The ECB explicitly states that the requirements of the DORA regulation remain fully relevant. The expected plan must therefore build on the existing digital operational resilience framework: governance, asset mapping, vulnerability management, detection, response, and recovery, resilience testing, and oversight of ICT service providers.

The banks must demonstrate how they are concretely adapting their DORA framework to these more specific supervisory expectations in response to AI-enabled cyber threats.

A looming threat: the quantum risk

The ECB letter does not stop at AI. It indicates that progress toward operational quantum computing could also transform the cyber landscape and weaken traditional encryption methods.

The transition to post-quantum cryptography will take several years, but the ECB therefore estimates that preparation must begin now and be supported by sustained strategic investments. It also indicates that a separate letter will be sent to institutions on this subject at a later date.

Next steps

The respective JST will engage with each bank to discuss its action plan and monitor progress. The ECB will also conduct a horizontal analysis of the submitted plans.

Beyond the ECB's letter, national supervisory authorities across Europe are actively translating these expectations into jurisdiction-specific requirements. This reinforces the urgency of the ECB's call and provides concrete operational detail on what regulators expect in practice.

A leading example is Banca d'Italia, which has issued a detailed market communication addressed to all supervised Italian financial intermediaries, fully aligned with the ECB's six focus areas and the DORA framework. Its approach illustrates the level of operational granularity that national supervisors are beginning to require and offers a useful benchmark for institutions across the EU.

In the United Kingdom, the authorities are also taking action. In its July 2026 financial stability report, the Bank of England estimates that the rapid progress of leading-edge AI models is increasing cyber and operational risks for the financial sector. A joint statement by the Bank of England, the FCA and the Treasury calls on institutions to strengthen their governance, vulnerability management, as well as their protection, response and recovery capabilities.

At international level, the Financial Stability Board (FSB) published a consultation on 10 June 2026 proposing 12 sound practices for the responsible adoption of AI by financial institutions. These cover governance, risk management throughout the lifecycle of AI systems, as well as cyber, ICT, and third-party risks. The FSB encourages governing bodies to rely on these practices in their decisions on strategy, technology investment, and risk management. The final report is scheduled for October 2026.

For banks, the challenge is twofold: adapting their resilience to cyber threats amplified by AI and managing the new risks related to their own use of AI. This requires accelerating the detection and remediation of vulnerabilities, strengthening business continuity and third-party risk management, while governing the use of AI systems within an appropriate framework of governance and controls.

Contact us to discuss your preparedness and identify priority actions.

Related insights