ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
ECB AI Cyber Action Plan Countdown: Big Banks Must File by October 31

ECB AI Cyber Action Plan Countdown: Big Banks Must File by October 31

AI compliance • Admin • • 6 views

The AI cyber action plan the European Central Bank requires from large euro area banks is due on 31 October 2026, four weeks from now. On 7 July 2026, Claudia Buch, Chair of the ECB Supervisory Board, wrote to the chief executives of all significant institutions directly supervised by the ECB under the Single Supervisory Mechanism (SSM). The letter, titled "Addressing AI-enabled cybersecurity threats", arrived on the same day the European Systemic Risk Board (ESRB) issued Warning ESRB/2026/3, raising the systemic cyber risk stemming from frontier AI models from "elevated" to "severe". This is not a new law. Within the framework of the EU Digital Operational Resilience Act (DORA), it turns supervisory expectations into a deliverable with a deadline: frontier AI can find vulnerabilities and generate working exploits within minutes, sharply compressing the window between discovery and attack, and banks' existing patching cycles can no longer keep up.

Six areas every plan must cover

The ECB prescribes capabilities, not products. In the short term, each action plan must address: mapping and shrinking the attack surface, with every ICT asset inventoried, including third-party software and open-source components, and internet-facing systems prioritised; accelerating vulnerability scanning and patch management to frequent, high-volume cycles, with change processes that support rapid, risk-based remediation and contractual notification and fix deadlines for ICT providers; stronger monitoring and detection across application logs, access records, network traffic and cloud repositories, where AI-based defensive tools are allowed only after a proper risk assessment and with human oversight in place; and governance, with management bodies reviewing whether ICT budgets, staffing and tooling are sufficient, training matched to the evolving threat, and full accountability retained for outsourced ICT risk. Medium-term work adds defence-in-depth through segmentation and zero trust, replacement of unsupported legacy systems, and tested incident response, backup, failover and recovery arrangements, including exercises for high-speed, high-volume attacks and cloud disruption. Every plan must name concrete measures, resources, owners and implementation dates, and goes to the bank's Joint Supervisory Team (JST). Open ICT findings from earlier on-site inspections, targeted reviews and the 2024 cyber resilience stress test must be closed without delay, the letter states explicitly.

Scope: euro area significant institutions only, no more and no less

The letter binds only significant institutions under direct ECB supervision, roughly 110 banks, mostly in the euro area. Less significant institutions supervised by national authorities such as Germany's BaFin are outside its direct scope, but BaFin has visibly stepped up cyber supervision this year and law firms broadly expect comparable requirements to follow through national regulators, so treating the letter as irrelevant is risky for LSIs. Banks outside the euro area, and groups with no supervised subsidiary inside it, are not directly bound; international groups with a significant institution in the euro area must file through that entity. The test is not where headquarters sit, but whether the legal entity is on the SSM significant institution list.

Filing is not the finish line: plans will be benchmarked

Submission is not the end. JSTs will discuss each plan and monitor progress, and the ECB will run a horizontal analysis across all submissions and feed the conclusions back to the industry, so a vague plan will stand out next to its peers. To free up capacity, the ECB pushed the annual IT Risk Questionnaire collection from September 2026 to February 2027, and other supervisory activities can be rescheduled case by case. In other words, the supervisor has already cleared time: a bank that cannot produce a credible plan with owners, budget and dates by 31 October will struggle to blame a lack of time. A second, underestimated risk sits in defensive AI itself: AI tools used for scanning and detection still have to pass data protection and model governance checks, and an AI defence with no documented risk assessment and no human review arrangement can become a new supervisory finding in its own right. The letter also flags that post-quantum cryptography migration planning must start now, with a separate letter to follow, so budgets for this round are better set with that work included.

Recommended Tools

More