5 Sources
[1]
Top banking watchdogs issue stark warning over AI-driven cyber attacks
Europe's top banking watchdogs have warned that frontier AI models such as Anthropic's Mythos pose "systemic risks to the financial system" as they gave lenders a tight four-month deadline to prepare for cyber security threats. The Eurozone's chief banking supervisor Claudia Buch on Tuesday sent a letter to 110 lenders giving them until the end of October to come up with a "comprehensive action plan" to combat the cyber risks posed by state of the art AI models. These should include "concrete measures to strengthen relevant controls, allocating the necessary resources, assigning clear roles and responsibilities, and defining timelines for implementation", said Buch, who is chair of the European Central Bank's supervisory board. In a separate warning issued on Tuesday, the European Systemic Risk Board said modern AI models can undermine financial stability across the Eurozone. The ESRB, which is responsible for monitoring and preventing dangers to the region's financial system, said the latest technology can discover and exploit bugs "at a speed, scale and level of accuracy far exceeding previous AI models". They represent "a paradigm shift for cyber security" as IT weaknesses could now be "weaponised" in a "matter of minutes or hours", it said. The watchdogs did not name Mythos in their warnings but referred to "frontier artificial intelligence models" in general. As a consequence, the bodies are urging banks to rapidly beef up their IT security capabilities. Over the short term, lenders need to be in a position to detect and fend off large-scale attacks quickly and to ensure that their third-party IT service providers are also able to do so, Buch stressed in her letter. Over the medium term, lenders also need to improve their "cyber hygiene", she added. In an attempt to compensate for the tight timeline, the ECB is postponing the deadline for its annual IT risk questionnaire, which banks now have until February to file rather than September. "Potential adjustments to other supervisory activities, such as on-site inspections or deep dives, will be considered on a case-by-case basis," Buch said in her letter.
[2]
ECB tells banks to draw up plans against AI attacks amid disruption fears
FRANKFURT, July 7 (Reuters) - The European Central Bank on Tuesday gave euro zone banks four months to draw up plans to counter AI-enabled cyber threats that could undermine confidence in the financial system and disrupt payments. The move reflects mounting concern among regulators about advanced AI models such as Anthropic's Mythos whose cyber capabilities have become so powerful that access to some of them has been restricted -- a limitation that currently excludes euro zone banks. "These developments have potentially profound implications for the confidentiality, integrity and resilience of banks' information â and communication technology (ICT) systems," the ECB said in a letter to bank chief executives. It told banks to prioritise protecting internet-facing systems and other exposed technology assets, including third-party software and open-source components, while speeding up vulnerability fixes and strengthening monitoring. The euro zone's top banking supervisor also urged lenders to modernise ageing technology, improve cyber hygiene and strengthen crisis-management, recovery and information-sharing arrangements. Banks have until October 31 to submit their plans. To free up resources, the ECB has postponed a â separate IT survey and may adjust inspections and other supervisory work. In a warning published alongside the ECB's letter, the European Systemic Risk Board said large-scale cyber disruptions could erode trust in financial institutions and even trigger runs on companies or countries perceived â as less secure. "The ESRB considers these developments to be a source of systemic risks to the financial system," said the ESRB, a European Union body that issues recommendations â to other authorities. To illustrate the risks, the ESRB outlined scenarios ranging from a gradual loss of confidence in smaller banks to state-backed espionage and coordinated â attacks on payments, clearing and settlement systems, potentially amplified by misinformation campaigns. It said incidents could spread quickly through common technology providers and shared software used across the financial sector. Reporting by Francesco Canepa. Editing by Mark Potter Our Standards: The Thomson Reuters Trust Principles., opens new tab
[3]
ECB tells banks to plan for AI cyber threats
The ECB's top supervisor has ordered euro-area banks to submit plans for the cyber threat from frontier AI by end-October. The trigger is a model like Anthropic's Claude Mythos. Europe's banking regulator has a new fear: an AI model clever enough to break into the financial system. It wants every big bank to have a plan by October. The European Central Bank has a warning for the euro area's largest banks. Frontier AI now poses a serious cyber threat, and lenders must draw up plans to counter it, Politico reports. Claudia Buch, who chairs the ECB's supervisory board, wrote to bank chief executives. She set a deadline of end-October. What the ECB wants Buch asked lenders to patch software faster and harden their AI-enabled cyber defences. She also wants tighter oversight of the outside technology providers they lean on. Over the longer term, banks must modernise ageing infrastructure and sharpen their crisis response. The order carries no fines. Banks that ignore it face no formal sanction. The ECB says it may still use the plans to rank lenders against each other and press the laggards. The Mythos effect One model looms over the letter: Anthropic's Claude Mythos. Anthropic says Mythos can find unknown flaws in IT systems. It claims the model has already spotted thousands of severe vulnerabilities across major operating systems and browsers. The company first limited who could use it, which spread unease across European finance. Buch put the worry plainly. Emerging models can pinpoint software weaknesses and write working exploits "at unprecedented speed," she wrote. That collapses the gap between finding a flaw and firing through it. A systemic risk, not just a bank problem The ECB did not act alone. The same day, the European Systemic Risk Board lifted its assessment of systemic cyber risk to "severe." It said frontier AI should now count as a source of systemic risk in its own right. The board flagged a second worry. Nearly all the leading AI providers sit outside the European Union. That leaves the bloc dependent on foreign firms and exposed to geopolitical pressure. It urged Europe to build up its own AI muscle. Why it matters The move fits a wider European scramble. ECB President Christine Lagarde warned last month that AI could trigger a dangerous financial crisis. The ECB has already run 109 banks through a severe cyber-attack drill. The threat is not hypothetical either, with state-backed attacks climbing and European bodies such as France's statistics office already hit. A market has sprung up around the fear. French startup Mistral has opened talks with European banks to sell a flaw-hunting tool. It is one of several firms racing to offer a home-grown answer to Mythos. For now the regulators sound clear on the danger and vaguer on the fix. Banks have until October to show they are ready.
[4]
ECB tells banks to prepare for AI-powered cyber threats
The European Central Bank has given the eurozone's largest lenders until the end of October to explain how they will strengthen their cyber defences against increasingly capable AI systems. The eurozone's top banking supervisor, the ECB, on Tuesday told major European banks to draw up action plans to address cybersecurity risks posed by increasingly powerful artificial intelligence systems. The emergence of AI models such as Anthropic's Mythos, which is particularly effective at identifying weaknesses in computer systems, has raised concerns among European governments and policymakers. The ECB's supervisory board sent a letter to the 110 banks it directly supervises, arguing that the latest AI models represent a "long-term shift in the threat landscape rather than a temporary phenomenon". "While these developments do not introduce entirely new risks, they significantly amplify the speed and scale at which such risks materialise," wrote Claudia Buch, chair of the ECB's Supervisory Board. The ECB is asking major lenders, including Deutsche Bank, BNP Paribas and Santander, to submit by 31 October a plan detailing the immediate and longer-term measures they intend to take to strengthen their resilience against cyberattacks. It said the plans should prioritise faster vulnerability and software patch management, stronger AI-enabled monitoring and detection systems, and closer scrutiny of third-party technology providers and supply-chain risks. These efforts must be directed from the highest levels of these institutions, the ECB stressed. To give banks more time to focus on the new threat, the ECB said it would postpone its annual IT Risk Questionnaire from September 2026 to February 2027 and would consider adjusting other supervisory activities on a case-by-case basis. Following the deadline, the ECB will analyse every bank's plan, discuss it with each institution, and conduct a horizontal analysis to identify common weaknesses and best practices across the banking sector. The letter also mentioned other emerging technologies, including quantum computing, which it said: "will have a significant impact on the cybersecurity landscape". The ECB said it would address the risks posed by quantum computing in a separate letter "in due course". Systemic cyber risk becomes 'severe' The supervisory board's move comes alongside a warning from the European Systemic Risk Board (ESRB), the EU body responsible for monitoring systemic financial risks. The ESRB on Tuesday warned about "systemic cyber risks stemming from frontier artificial intelligence models". The warning follows the ESRB General Board's decision in June to raise its assessment of systemic cyber risk to "severe" from "elevated" in March. The watchdog said frontier AI models represent a "paradigm shift" in cybersecurity and have become a source of systemic risk to the EU financial system. According to the watchdog, "AI is already being used by malicious actors to enhance cyber-attacks". The ESRB warned that AI could dramatically reduce the time available for banks to identify and patch software vulnerabilities before they are exploited, increasing the risk of simultaneous cyber incidents across the financial sector. The ESRB also warned that the concentration of leading frontier AI developers outside the European Union exposes the bloc to strategic dependency and geopolitical risks. Anthropic, one of the world's leading AI developers, have been creating increasingly capable frontier AI models. The company initially withheld the full version of Mythos over concerns that it could be misused to identify software vulnerabilities and assist hackers before releasing a public version with built-in safety safeguards last month.
[5]
Banking Regulators Warn That AI Could Threaten Financial System | PYMNTS.com
The European Systemic Risk Board (ESRB) and Bank of England (BOE) both issued reports Tuesday (July 7) on the risks of these artificial intelligence (AI) models to financial institutions' cyber defenses. "Frontier AI models are a paradigm shift for cybersecurity," the ESRB said in a news release accompanying its report. "Eventually, these models are likely to strengthen cyber resilience. In the short to medium term, however, they provide an advantage to threat actors, enabling them to discover vulnerabilities and execute cyberattacks with increased speed, scale and sophistication." The board added that the concentration of the world's top AI companies outside the European Union (EU) exposes the region to "strategic dependency and geopolitical risks," and called on the EU to expand its "capacity, expertise and strategic autonomy" in this area. The report comes weeks after pushback from the U.S. government against a pair of frontier models from Anthropic and OpenAI. While the ERSB mentions both models by name in its report, it says its concerns and recommendations apply to any frontier models. Meanwhile, the Bank of England made a similar argument about frontier AI models in its half-year financial stability report. "Whilst frontier AI will offer opportunities to improve cyber defence, it will also increase the sophistication and impact of cyber-attacks on firms, including financial institutions and market infrastructure," the report said. "Operational risks are also likely to increase as frontier AI accelerates vulnerability discovery and exploitation, requiring firms to identify, patch and mitigate vulnerabilities more quickly and frequently, increasing the risk of disruption if change is not managed effectively." The central bank said these developments underline the importance of forms acting on joint statements from the BOE, Financial Conduct Authority (FCA) and the British Treasury on frontier models and cyber and operational resilience frameworks. The third AI-related warning Tuesday came from Claudia Buch, chair of the European Central Bank's supervisory board. According to a Financial Times report, she wrote to 110 EU banks giving them until the end of October to develop a "comprehensive action plan" to counter the cybersecurity risks from AI models. In related news, PYMNTS spoke last month with Entersekt Chief Information Officer Richard Bailey about the increased urgency for cybersecurity improvements as attackers and defenders deploy the same artificial intelligence technologies. "AI has definitely given some tailwinds ... to fraud," Bailey told PYMNTS. "Fraud actors now have the ability to apply AI to their attacks. They can enrich their attacks and apply multiple attack vectors at any one time."
Share
Copy Link
The European Central Bank has ordered 110 major eurozone banks to submit comprehensive action plans by end-October to combat AI-driven cyber attacks. Banking regulators warn that frontier AI models like Anthropic's Mythos can exploit vulnerabilities at unprecedented speed, posing systemic risks to the financial system and potentially triggering widespread disruption.
The European Central Bank has given eurozone's 110 largest lenders a tight four-month deadline to develop comprehensive action plans addressing AI cyber threats that regulators now classify as systemic risks to the financial system
1
2
. Claudia Buch, chair of the ECB's supervisory board, sent letters to bank chief executives on Tuesday demanding plans by October 31 that include "concrete measures to strengthen relevant controls, allocating the necessary resources, assigning clear roles and responsibilities, and defining timelines for implementation"1
. The move reflects mounting concern among banking regulators about advanced AI models such as Anthropic's Mythos, whose cyber capabilities have become so powerful that access to some versions has been restricted2
.
Source: PYMNTS
In a coordinated warning issued the same day, the European Systemic Risk Board raised its assessment of systemic cyber risk to "severe" from "elevated" in March, declaring that frontier AI models represent "a paradigm shift for cybersecurity"
4
. The ESRB warned that modern AI models can discover and exploit bugs "at a speed, scale and level of accuracy far exceeding previous AI models," with IT weaknesses now capable of being "weaponised" in "a matter of minutes or hours"1
. The watchdog outlined scenarios ranging from gradual loss of confidence in smaller banks to state-backed espionage and coordinated attacks on payments, clearing and settlement systems, potentially amplified by misinformation campaigns2
. The Bank of England issued a parallel warning in its half-year financial stability report, noting that while frontier AI will offer opportunities to improve cyber defence, it will also increase the sophistication and impact of AI-driven cyber attacks on financial institutions5
.
Source: FT
The cybersecurity risks posed by frontier AI demand immediate action across multiple fronts. Banks must prioritize protecting internet-facing systems and other exposed technology assets, including third-party software and open-source components, while speeding up vulnerability management and strengthening monitoring capabilities
2
. The ECB emphasized that plans should prioritize faster vulnerability and software patch management, stronger AI-enabled monitoring and detection systems, and closer scrutiny of third-party risk management and supply-chain risks4
. Major lenders including Deutsche Bank, BNP Paribas and Santander must direct these efforts from the highest levels of their institutions4
.
Source: Reuters
Related Stories
Over the short term, lenders need to be in a position to detect and fend off large-scale attacks quickly and ensure their third-party IT service providers can do the same, Buch stressed in her letter
1
. Over the medium term, banks must also improve their cyber hygiene, modernise ageing technology infrastructure, and strengthen crisis-management, recovery and information-sharing arrangements2
. To compensate for the tight timeline, the ECB is postponing the deadline for its annual IT risk questionnaire from September to February, and may adjust other supervisory activities such as on-site inspections or deep dives on a case-by-case basis1
4
.The ESRB warned that large-scale cyber disruptions could erode trust in financial institutions and even trigger runs on companies or countries perceived as less secure
2
. Incidents could spread quickly through common technology providers and shared software used across the financial sector, amplifying operational risks2
. The board also flagged that nearly all leading AI providers sit outside the European Union, leaving the bloc dependent on foreign firms and exposed to geopolitical pressure, and urged Europe to build up its own AI capacity3
. While the ECB's order carries no formal fines, regulators may use the plans to rank lenders against each other and press laggards to improve3
. A market has already sprung up around these concerns, with French startup Mistral opening talks with European banks to sell flaw-hunting tools as firms race to offer home-grown answers to models like Mythos3
.Summarized by
Navi
[3]
25 May 2026â˘Policy and Regulation

13 May 2026â˘Policy and Regulation
20 Apr 2026â˘Policy and Regulation
