ECB orders euro‑zone banks to submit AI‑cyber risk plans by October
The European Central Bank (ECB) has written to the CEOs of the 110 largest banks under its supervision, demanding a detailed action plan by 31 October to protect against cyber threats driven by advanced artificial‑intelligence models such as Anthropic’s Mythos. ECB supervisory board chair Claudia Buch warned that “these models represent a structural change in the threat landscape, not a temporary phenomenon.” Plans must address faster vulnerability patching, AI‑enhanced detection and monitoring, stricter oversight of third‑party technology providers, and allocation of resources at senior‑management level. The ECB will review each plan, discuss findings with the institutions and may use the results for future supervisory actions. In parallel, the European Systemic Risk Board (ESRB) has upgraded the systemic cyber‑risk rating to “severe,” highlighting the potential for AI‑driven attacks to accelerate exploitation of software flaws across the financial sector. The ECB also announced it will delay its annual IT‑risk questionnaire to February 2027 and will issue a separate communication on emerging quantum‑computing threats.