European Central Bank gives banks four months to counter AI cyber threats as regulators warn of systemic risks

5 Sources

Share

The European Central Bank has ordered 110 major eurozone banks to submit comprehensive action plans by end-October to combat AI-driven cyber attacks. Banking regulators warn that frontier AI models like Anthropic's Mythos can exploit vulnerabilities at unprecedented speed, posing systemic risks to the financial system and potentially triggering widespread disruption.

European Central Bank Issues Urgent Directive on AI Cyber Threats

The European Central Bank has given eurozone's 110 largest lenders a tight four-month deadline to develop comprehensive action plans addressing AI cyber threats that regulators now classify as systemic risks to the financial system

1

2

. Claudia Buch, chair of the ECB's supervisory board, sent letters to bank chief executives on Tuesday demanding plans by October 31 that include "concrete measures to strengthen relevant controls, allocating the necessary resources, assigning clear roles and responsibilities, and defining timelines for implementation"

1

. The move reflects mounting concern among banking regulators about advanced AI models such as Anthropic's Mythos, whose cyber capabilities have become so powerful that access to some versions has been restricted

2

.

Source: PYMNTS

Source: PYMNTS

Banking Regulators Elevate Threat Assessment to Severe

In a coordinated warning issued the same day, the European Systemic Risk Board raised its assessment of systemic cyber risk to "severe" from "elevated" in March, declaring that frontier AI models represent "a paradigm shift for cybersecurity"

4

. The ESRB warned that modern AI models can discover and exploit bugs "at a speed, scale and level of accuracy far exceeding previous AI models," with IT weaknesses now capable of being "weaponised" in "a matter of minutes or hours"

1

. The watchdog outlined scenarios ranging from gradual loss of confidence in smaller banks to state-backed espionage and coordinated attacks on payments, clearing and settlement systems, potentially amplified by misinformation campaigns

2

. The Bank of England issued a parallel warning in its half-year financial stability report, noting that while frontier AI will offer opportunities to improve cyber defence, it will also increase the sophistication and impact of AI-driven cyber attacks on financial institutions

5

.

Source: FT

Source: FT

ECB Tells Banks to Prioritize Critical Infrastructure Protection

The cybersecurity risks posed by frontier AI demand immediate action across multiple fronts. Banks must prioritize protecting internet-facing systems and other exposed technology assets, including third-party software and open-source components, while speeding up vulnerability management and strengthening monitoring capabilities

2

. The ECB emphasized that plans should prioritize faster vulnerability and software patch management, stronger AI-enabled monitoring and detection systems, and closer scrutiny of third-party risk management and supply-chain risks

4

. Major lenders including Deutsche Bank, BNP Paribas and Santander must direct these efforts from the highest levels of their institutions

4

.

Source: Reuters

Source: Reuters

Short-Term Defense and Long-Term Modernization Required

Over the short term, lenders need to be in a position to detect and fend off large-scale attacks quickly and ensure their third-party IT service providers can do the same, Buch stressed in her letter

1

. Over the medium term, banks must also improve their cyber hygiene, modernise ageing technology infrastructure, and strengthen crisis-management, recovery and information-sharing arrangements

2

. To compensate for the tight timeline, the ECB is postponing the deadline for its annual IT risk questionnaire from September to February, and may adjust other supervisory activities such as on-site inspections or deep dives on a case-by-case basis

1

4

.

AI-Powered Cyber Threats Could Trigger Financial Instability

The ESRB warned that large-scale cyber disruptions could erode trust in financial institutions and even trigger runs on companies or countries perceived as less secure

2

. Incidents could spread quickly through common technology providers and shared software used across the financial sector, amplifying operational risks

2

. The board also flagged that nearly all leading AI providers sit outside the European Union, leaving the bloc dependent on foreign firms and exposed to geopolitical pressure, and urged Europe to build up its own AI capacity

3

. While the ECB's order carries no formal fines, regulators may use the plans to rank lenders against each other and press laggards to improve

3

. A market has already sprung up around these concerns, with French startup Mistral opening talks with European banks to sell flaw-hunting tools as firms race to offer home-grown answers to models like Mythos

3

.

Today's Top Stories

Š 2026 TheOutpost.AI All rights reserved