The European Central Bank has highlighted a significant shift in the cybersecurity landscape: artificial intelligence is accelerating how vulnerabilities are identified, exploited, and weaponized. For banks, this means less time to detect and respond to threats, increased exposure across digital assets, and growing supervisory expectations.
The ECB is calling on supervised institutions to assess the impact of AI-enabled cyber threats and submit a comprehensive action plan to their Joint Supervisory Team by 31 October 2026. The expectation goes beyond awareness. Institutions are expected to demonstrate concrete measures, clear accountability, allocated resources, and implementation timelines.
Key areas of supervisory focus include:
For boards and executive management, the message is clear: cyber resilience has become a strategic governance issue.
Download the regulatory watch briefing, where we summarize:
At Deloitte, we help financial institutions assess AI-driven cyber risks, develop supervisory-ready action plans, strengthen control environments, and improve operational resilience.
Partner | Deloitte Central Europe | Strategy, Risk& Transactions | FSI Risk & Regulatory Advisory
Director | Deloitte Central Europe | Technology & Transformation | Cyber
Opens in new window