Regulation

ECB gives euro-area banks four months to submit AI-focused cybersecurity plans

The European Central Bank has ordered banks in the euro area to produce action plans within four months to fend off cyberattacks that could exploit advanced AI capabilities, with submissions due by October 31.

ECB gives euro-area banks four months to submit AI-focused cybersecurity plans

The European Central Bank (ECB) on Tuesday instructed banks across the euro area to prepare action plans within four months to address cyber threats that exploit advanced artificial intelligence (AI). According to the ECB, the plans must be submitted by October 31.

Why the step was taken

In a letter to bank executives, the ECB warned that the spread of advanced AI models could have serious implications for the confidentiality, integrity and resilience of banks' information and communication technology (ICT) systems. The regulator noted that access to certain sophisticated models—for example, the Anthropic Mythos model—has been restricted, and that such advanced systems are currently not available to euro-area banks.

What the ECB asks banks to do

The ECB sets out a number of concrete expectations for institutions:

  • strengthen the protection of systems exposed to public networks and other vulnerable technology components;
  • review and secure software supplied by third parties and open-source components;
  • speed up remediation of security vulnerabilities and enhance continuous monitoring;
  • modernise outdated technology stacks and improve cyber hygiene;
  • reinforce crisis management, recovery and information-sharing arrangements.

To free up the necessary supervisory resources, the ECB has postponed a separate IT survey and said it may adjust the timing of inspections and other supervisory activities if needed.

Parallel warning from the ESRB

At the same time, the European Systemic Risk Board (ESRB) issued a warning that large-scale cyber disruptions could undermine public trust in financial institutions and trigger panic-driven capital outflows from perceivedly more vulnerable firms or countries. The ESRB treats these developments as a systemic risk.

The ESRB outlined several scenarios ranging from a gradual loss of confidence in smaller banks and risks of state-sponsored espionage to coordinated attacks against payment, clearing and settlement systems. It also cautioned that the impact could be amplified by disinformation campaigns and that incidents can quickly spread across the financial sector via shared technology providers and common software solutions.

Next steps for banks

Banks must assess the AI-related threats to their own systems, third-party components and open-source elements and then prepare and submit the required action plans by October 31. The combined signals from the ECB and the ESRB indicate that regulators may intensify supervision of how the financial sector manages AI-driven cyber risks going forward.

The measures underline the regulators' intent to reduce the potential for rapidly spreading and severe cyber risks to the financial system.

Key facts

  • The ECB has given banks four months; plans are due by October 31.
  • Access to certain advanced AI models, including Anthropic Mythos, has been restricted and is not currently available to euro-area banks.
  • The ECB has postponed a separate IT survey to allocate supervisory resources to this effort.

(Source: Reuters.)