European Central Bank Banking Supervision has instructed significant institutions to assess without delay how AI-enabled cybersecurity threats affect their risk profile and to develop comprehensive action plans. The ECB warned that AI is accelerating vulnerability discovery and exploitation, amplifying the speed and scale of existing risks. Management bodies should review ICT investment, staffing, risk tolerance and governance, while promptly addressing unresolved findings from previous supervisory work. The plans should specify controls, resources, responsibilities and implementation timelines. Immediate priorities include protecting exposed ICT assets, accelerating vulnerability and patch management, enhancing monitoring and AI-enabled defenses, and ensuring third-party risk management remains fit for purpose. Longer-term measures should strengthen defense-in-depth, modernize legacy infrastructure and improve incident response, recovery, crisis management and information sharing, in line with the Digital Operational Resilience Act. Institutions must submit their plans to their Joint Supervisory Teams by October 31, 2026. The teams will monitor implementation, while the ECB will conduct and share a horizontal analysis of the plans. To allow banks to prioritize this work, the ECB has moved the annual IT Risk Questionnaire deadline from September 2026 to February 2027 and plans a separate letter on quantum computing risks.
European Central Bank - Banking Supervision2026-07-07
European Central Bank Banking Supervision directs significant institutions to submit AI cyber-risk action plans by October 31
European Central Bank Banking Supervision has directed significant institutions to assess AI-enabled cyber threats and submit action plans by October 31, 2026. Plans must address accelerated patching, exposed assets, monitoring, third-party risk and longer-term operational resilience. The ECB has extended the annual IT Risk Questionnaire deadline to February 2027 to support this work.