AI Governance Institute
← News
Research2026-10-01

ECB Requires Bank AI Cyber Action Plans by October 31, 2026

What happened

Marsh's analysis, Cyber risks and AI: the ECB requires an action plan by 31 October 2026, details a binding supervisory expectation from the European Central Bank. Banks must document how they are managing AI-enabled cyber threats. The deadline is October 31, 2026. The scope covers eight domains: governance, AI asset mapping, vulnerability management, threat detection, incident response, recovery, resilience testing, and oversight of external technology providers. Banks that use AI in their own defenses must also document a formal assessment of the benefits and risks of doing so. Human oversight of AI-assisted security tools is an explicit expectation, not optional. The requirement sits within the EU Digital Operational Resilience Act framework, meaning banks with existing compliance programs must extend them rather than build separate tracks.

Why it matters

  • ·The October 31 deadline is binding and imminent. Banks without a documented AI cyber risk action plan face direct supervisory exposure, not just a gap in best-practice alignment.
  • ·The eight-domain scope forces banks to treat AI as a distinct risk category within their EU Digital Operational Resilience Act programs. Existing information and communications technology risk documentation that does not address AI specifically will not satisfy the expectation.
  • ·The explicit requirement to document human oversight of AI-assisted security tools raises accountability questions that most governance programs have not yet answered. Teams using AI to detect threats or automate responses must now show who reviews those outputs and when.

Governance controls affected

What to do now

  • ☐Confirm whether your institution has a documented AI cyber risk action plan covering all eight ECB domains (governance, asset mapping, vulnerability management, detection, response, recovery, resilience testing, and technology-provider oversight), and identify which domains are missing.
  • ☐Map every AI tool used in your security operations, such as tools that scan for threats or flag suspicious activity, and document which staff review their outputs before action is taken.
  • ☐For each AI-assisted security tool, prepare a written benefit-risk assessment and confirm it has been reviewed and approved by the appropriate governance body before the October 31 deadline.
  • ☐Review contracts with technology providers to confirm they include obligations to notify you of AI-related changes or incidents that could affect your operational resilience posture.
  • ☐Schedule a tabletop exercise before October 31 that simulates an AI-enabled cyberattack, and document the results as evidence of resilience testing for supervisory purposes.

What to watch next

Supervisory follow-up from the ECB is likely in the first quarter of 2027. At that point, inspectors will assess whether submitted action plans reflect genuine program substance rather than documentation only. Banks should also monitor whether the European Banking Authority issues supplementary guidance that defines minimum standards for each of the eight domains, which would tighten the current expectation further. The EU Digital Operational Resilience Act threat-led penetration testing cycle is a natural vehicle for AI-specific resilience evidence, and regulators are likely to ask how the two programs connect.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-26

HUD's AI Grant Monitor Launches September 30 With Oversight Rules Unfinished

The U.S. Department of Housing and Urban Development (HUD) plans to launch an AI-powered grants monitoring system called HUGS on September 30, 2026. Built under a $500,000 contract with Palantir, HUGS will review every vendor payment made by grant recipients. Formal procedures for how the AI's findings will be reviewed, contested, or overturned have not yet been finalized.

Enforcement2026-09-25

Federal AI Prior Authorization Program Fails 53% of Requests, GAO Finds Procedural Breach

The Trump administration's WISeR pilot, launched in January 2026 across six states, uses AI to automate Medicare prior authorization decisions. One participating vendor denied more than 53 percent of requests, and several vendors missed a mandated 72-hour decision window. The Government Accountability Office determined in May 2026 that the Centers for Medicare and Medicaid Services did not follow proper procedure in establishing the program.

Enforcement2026-09-30

SBA's AI Fraud Pilot Never Classified as High-Impact, OIG Finds

The SBA's Office of Inspector General found that a Palantir-powered AI fraud detection pilot for COVID-19 loan programs was never classified as a high-impact use case under OMB guidance. As a result, required safeguards including impact assessments, human oversight mechanisms, and borrower appeals processes were never put in place. The OIG issued six recommendations, including establishing a formal process for identifying and documenting high-impact AI use cases.