Skip to content
Braincap
← All articles

The ECB tells banks to file an action plan against AI-enabled attacks by 31 October 2026

by Claudiu Hulea · IT Management Consultant

Illustration: a bank supervised by the ECB files an action plan against AI-enabled attacks, deadline 31 October 2026

On 7 July 2026, ECB Banking Supervision sent a letter to the CEO of every significant institution — SSM-2026-0301, signed by Claudia Buch, Chair of the Supervisory Board — with a firm deadline: by 31 October 2026, banks must submit an action plan against AI-enabled cyber threats. Below are the facts, taken straight from the official letter, with no interpretation.

What the ECB actually says

The rationale is stated plainly: AI models can identify vulnerabilities and generate functioning exploits at unprecedented speed, compressing the time between the discovery of a flaw and its exploitation. The ECB stresses that these are not entirely new risks, but a major amplification of the speed and scale at which they materialise — a long-term shift in the threat landscape, not a passing wave tied to any single tool. The letter is aligned with, and references, the European Systemic Risk Board (ESRB) warning on “systemic cyber risks stemming from frontier artificial intelligence models”.

The action plan

Responsibility lies primarily with the bank’s management bodies — ICT investment decisions, resource allocation and the risk-tolerance framework may need revisiting, and governance and control systems strengthened where necessary. The ECB asks for a comprehensive action plan, with concrete measures, allocated resources, clear roles and implementation timelines, built on top of the bank’s existing cyber-risk strategy. The plan is submitted to the Joint Supervisory Team (JST) by 31 October 2026.

It is not a new law: the letter operationalises DORA (Regulation (EU) 2022/2554) in the face of the new threat, and it is outcome-based, not a prescriptive checklist of technologies.

The focus areas, as the letter lists them

Short term:

  • accelerate vulnerability and patch management at scale;
  • strengthen monitoring, detection and AI-enabled defensive capabilities;
  • verify that third-party risk management is fit for purpose — ICT service providers are critical links in the supply chain;
  • prioritise protecting the perimeter and internet-facing assets, including third-party software and open-source components.

Structural (longer term):

  • defence-in-depth and cyber hygiene, plus modernising infrastructure by replacing legacy, unsupported or end-of-life technologies;
  • operational resilience through response and recovery mechanisms, including crisis management and information-sharing arrangements.

In addition, the ECB asks banks to resolve open supervisory findings without delay (on-site inspections, targeted reviews, the 2024 cyber-resilience stress test) and separately flags post-quantum cryptography — its adoption “must start now”, with a dedicated letter to follow.

Note what is not front and centre: the letter does not elevate any specific authentication technology to a requirement. Identity controls sit, naturally, within “defence-in-depth” — but the mandate is about patch speed, detection, third parties and the exposed surface, not about any particular product.

Supervision, and a relaxed deadline in return

The JST will discuss the plan with each bank and monitor its progress. The ECB will run a horizontal analysis of all submitted plans to identify trends and share the conclusions with the sector. In return for the effort, the ECB is extending the annual IT Risk Questionnaire collection from September 2026 to February 2027, and will adjust other supervisory activities case by case.

What it means for banks in Romania

The letter is addressed to the significant institutions supervised directly by the ECB (banks in the euro area and in close-cooperation countries). Banks in Romania are supervised primarily by the national central bank (BNR), so they are not the letter’s direct addressees. But the practical conclusion is the same, for three reasons:

  • DORA has applied directly in Romania since 17 January 2025 — the same digital operational resilience requirements the ECB letter operationalises are already mandatory for Romanian financial entities.
  • Subsidiaries of euro-area groups are covered through the parent bank’s group plan.
  • The threat does not respect borders. The AI-driven “vulnerability → exploit” compression hits the same way, whoever supervises you.

In other words, the ECB letter is the clearest template of supervisory expectation in the EU on this subject — the direction the whole sector is heading.


Translated into practice — a plan that survives a review — the hard points are exactly the ones in the letter: how fast you patch exposed assets, whether you can see an attack in progress, and how well you know your third parties. A security audit and a test of your exposed surface show where you stand now, before someone else finds out.

The facts come from the official ECB Banking Supervision letter, “Addressing AI-enabled cybersecurity threats” (SSM-2026-0301, 7 July 2026), and from the ESRB warning it references. This article reports what the letter says, with no commercial interpretation.

Frequently asked questions

What exactly does the ECB letter require?

That every significant institution supervised by the ECB submit, by 31 October 2026, to its Joint Supervisory Team (JST), a comprehensive action plan against AI-enabled cyber threats — with concrete measures, allocated resources, clear roles and implementation timelines. It is not a new law, but a supervisory action that operationalises DORA requirements in the face of the new threat.

Does it apply to banks in Romania?

The direct addressees are the significant institutions supervised directly by the ECB (the euro area and close-cooperation countries). Banks in Romania are supervised primarily by the national central bank (BNR), so they are not the letter's direct addressees. But DORA has applied directly in Romania since 17 January 2025 — the same requirements are already mandatory — and subsidiaries of euro-area groups are covered through the parent bank's plan.

What are the required focus areas?

Short term: accelerate vulnerability and patch management at scale; strengthen monitoring, detection and AI-enabled defensive capabilities; verify third-party risk management; protect the perimeter and internet-facing assets. Structural: defence-in-depth and cyber hygiene, modernising legacy technology, response and recovery mechanisms. In addition: resolving open supervisory findings and preparing post-quantum cryptography.

Why now? What changed?

According to the ECB, AI models can identify vulnerabilities and generate functioning exploits at unprecedented speed, compressing the time between discovery and exploitation. These are not entirely new risks, but a major amplification of their speed and scale — a long-term shift in the threat landscape. The letter references the ESRB warning on systemic cyber risks stemming from frontier AI models.

Related articles