GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
ECB tells banks to draw up plans against AI attacks amid disruption fears - Finance news and analysis from Global Banking & Finance Review
Finance

ECB tells banks to draw up plans against AI attacks amid disruption fears

Published by Global Banking & Finance Review

Posted on July 7, 2026

3 min read

· Last updated: July 7, 2026

Add as preferred source on Google

ECB tells banks to bolster AI cyber defences as peers take lighter approach

Central Banks Respond to AI-Enabled Cyber Threats

By Francesco Canepa

FRANKFURT, July 7 (Reuters) - The European Central Bank on Tuesday gave euro zone banks four months to draw up plans to counter AI-enabled cyber threats, taking a more prescriptive approach than other major central banks to risks posed by advanced AI models.

The U.S. Federal Reserves and Bank of England struck softer tones in separate comments on Tuesday as central banks look to tackle risks posed by Anthropic's Mythos and the latest generation of large-language models.

The cyber capabilities of some of these systems are considered so powerful that access has been restricted, with euro zone banks currently excluded from Mythos.

ECB's Directive to Euro Zone Banks

"These developments have potentially profound implications for the confidentiality, integrity and resilience of banks’ information and communication technology (ICT) systems," the ECB's chief supervisor Claudia Buch said in a letter to bank chief executives.

Key Areas of Focus for Banks

She told banks to prioritise protecting internet-facing systems and other exposed technology assets, including third-party software and open-source components, while speeding up vulnerability fixes and strengthening monitoring.

The euro zone's top banking supervisor also urged lenders to modernise ageing technology, improve cyber hygiene and strengthen crisis-management, recovery and information-sharing arrangements.

Timeline and Next Steps

Banks have until October 31 to submit their plans. To free up resources, the ECB has postponed a separate IT survey and may adjust inspections and other supervisory work.

The ECB, which met banks in the spring to hear their views, will then share its findings to help identify challenges and areas for improvement.

Contrasting Approaches from BOE and Federal Reserve

BOE Not Issuing 'Edicts'

BOE NOT ISSUING 'EDICTS', FED FAVOURS LIGHTER TOUCH

Speaking in London later on Tuesday, Bank of England Governor Andrew Bailey said the ECB's warning was "sensible" but that the BoE would take a less prescriptive approach.

"It's not about issuing edicts," he told reporters, presenting the BoE's half-yearly Financial Stability Report. "It's about getting in a room and saying ... how are we going to share our understandings of the vulnerabilities that we find in this system?"

The BoE has long given firm advice to British banks to bolster their cyber defences but has not gone as far as to set public deadlines.

Federal Reserve's Lighter Regulatory Touch

In a separate speech, Federal Reserve vice chair for supervision Michelle Bowman stressed responsible AI adoption, proportionality and "a lighter supervisory and regulatory touch" for lower-risk uses.

Like her European colleagues, she emphasised governance, controls and risk management, but focused on enabling innovation rather than responding to systemic cyber threats.

EU Watchdog Highlights Systemic Risks

Potential Disruptions and Systemic Risks

EU WATCHDOG WARNS OF DISRUPTIONS

In a warning published alongside the ECB's letter, the European Systemic Risk Board said large-scale cyber disruptions could erode trust in financial institutions and even trigger runs on companies or countries perceived as less secure.

"The ESRB considers these developments to be a source of systemic risks to the financial system," said the ESRB, a European Union body that issues recommendations to other authorities.

Scenarios and Sector-Wide Implications

To illustrate the risks, the ESRB outlined scenarios ranging from a gradual loss of confidence in smaller banks to state-backed espionage and coordinated attacks on payments, clearing and settlement systems, potentially amplified by misinformation campaigns.

It said incidents could spread quickly through common technology providers and shared software used across the financial sector.

(Additional reporting by Phoebe Seers and David Milliken in London. Editing by Mark Potter)

Key Takeaways

  • ECB demands that banks develop and submit detailed plans by October 31 to defend against AI‑enabled cyberattacks targeting ICT systems.
  • Regulators stress modernising legacy tech, improving cyber hygiene, and accelerating patching, while prioritising internet‑facing and third‑party components.
  • The ESRB warns that AI‑driven cyber disruptions may pose systemic risks—potentially triggering runs or large‑scale payment system disruptions.

Frequently Asked Questions

Why has the ECB given banks a four-month deadline?
The ECB wants euro zone banks to counter AI-enabled cyber threats and submit plans by October 31 to safeguard the financial system.
What specific areas are banks told to prioritize?
Banks should focus on protecting internet-facing systems, exposed tech assets, speeding up vulnerability fixes, and enhancing monitoring.
What risks does the ESRB highlight regarding AI cyber threats?
The ESRB warns that large-scale cyber disruptions could erode trust, trigger bank runs, and pose systemic risks across the financial sector.
How could AI cyber incidents spread in the financial sector?
Incidents could rapidly affect institutions through common technology providers and shared software used across the sector.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category