Skip to main content

AI-enabled cyber threats are no longer a future concern

They are a current supervisory priority

The European Central Bank has highlighted a significant shift in the cybersecurity landscape: artificial intelligence is accelerating how vulnerabilities are identified, exploited, and weaponized. For banks, this means less time to detect and respond to threats, increased exposure across digital assets, and growing supervisory expectations.

The ECB is calling on supervised institutions to assess the impact of AI-enabled cyber threats and submit a comprehensive action plan to their Joint Supervisory Team by 31 October 2026. The expectation goes beyond awareness. Institutions are expected to demonstrate concrete measures, clear accountability, allocated resources, and implementation timelines.

Key areas of supervisory focus include:

• Protection of internet-facing and critical ICT assets
• Accelerated vulnerability and patch management
• Enhanced monitoring and AI-assisted cyber defence
• Third-party and supply chain risk management
• Governance, resilience, recovery, and crisis preparedness

For boards and executive management, the message is clear: cyber resilience has become a strategic governance issue.

In the attached regulatory watch briefing, we summarize:
• The ECB's expectations and timeline
• The evolving AI-enabled threat landscape
• The key risk domains requiring management attention
• Practical actions institutions should consider now

At Deloitte, we help financial institutions assess AI-driven cyber risks, develop supervisory-ready action plans, strengthen control environments, and improve operational resilience.

  
The European Central Bank has highlighted a significant shift in the cybersecurity landscape: artificial intelligence is accelerating how vulnerabilities are identified, exploited, and weaponized. For banks, this means less time to detect and respond to threats, increased exposure across digital assets, and growing supervisory expectations.

The ECB is calling on supervised institutions to assess the impact of AI-enabled cyber threats and submit a comprehensive action plan to their Joint Supervisory Team by 31 October 2026. The expectation goes beyond awareness. Institutions are expected to demonstrate concrete measures, clear accountability, allocated resources, and implementation timelines.

Key areas of supervisory focus include:

  • Protection of internet-facing and critical ICT assets
  • Accelerated vulnerability and patch management
  • Enhanced monitoring and AI-assisted cyber defence
  • Third-party and supply chain risk management
  • Governance, resilience, recovery, and crisis preparedness

For boards and executive management, the message is clear: cyber resilience has become a strategic governance issue.

Download the regulatory watch briefing, where we summarize:

  • The ECB's expectations and timeline
  • The evolving AI-enabled threat landscape
  • The key risk domains requiring management attention
  • Practical actions institutions should consider now

At Deloitte, we help financial institutions assess AI-driven cyber risks, develop supervisory-ready action plans, strengthen control environments, and improve operational resilience.

Did you find this useful?

Thanks for your feedback