European Central Bank Banking Supervision has instructed significant institutions to assess without delay how AI-enabled cybersecurity threats affect their risk profile and to develop comprehensive action plans. The ECB warned that AI is accelerating vulnerability discovery and exploitation, amplifying the speed and scale of existing risks. Management bodies should review ICT investment, staffing, risk tolerance and governance, while promptly addressing unresolved findings from previous supervisory work. The plans should specify controls, resources, responsibilities and implementation timelines. Immediate priorities include protecting exposed ICT assets, accelerating vulnerability and patch management, enhancing monitoring and AI-enabled defenses, and ensuring third-party risk management remains fit for purpose. Longer-term measures should strengthen defense-in-depth, modernize legacy infrastructure and improve incident response, recovery, crisis management and information sharing, in line with the Digital Operational Resilience Act. Institutions must submit their plans to their Joint Supervisory Teams by October 31, 2026. The teams will monitor implementation, while the ECB will conduct and share a horizontal analysis of the plans. To allow banks to prioritize this work, the ECB has moved the annual IT Risk Questionnaire deadline from September 2026 to February 2027 and plans a separate letter on quantum computing risks.