ECB Requires Bank AI Cyber Action Plans by October 31, 2026
What happened
Marsh's analysis, Cyber risks and AI: the ECB requires an action plan by 31 October 2026, details a binding supervisory expectation from the European Central Bank. Banks must document how they are managing AI-enabled cyber threats. The deadline is October 31, 2026. The scope covers eight domains: governance, AI asset mapping, vulnerability management, threat detection, incident response, recovery, resilience testing, and oversight of external technology providers. Banks that use AI in their own defenses must also document a formal assessment of the benefits and risks of doing so. Human oversight of AI-assisted security tools is an explicit expectation, not optional. The requirement sits within the EU Digital Operational Resilience Act framework, meaning banks with existing compliance programs must extend them rather than build separate tracks.
Why it matters
- ·The October 31 deadline is binding and imminent. Banks without a documented AI cyber risk action plan face direct supervisory exposure, not just a gap in best-practice alignment.
- ·The eight-domain scope forces banks to treat AI as a distinct risk category within their EU Digital Operational Resilience Act programs. Existing information and communications technology risk documentation that does not address AI specifically will not satisfy the expectation.
- ·The explicit requirement to document human oversight of AI-assisted security tools raises accountability questions that most governance programs have not yet answered. Teams using AI to detect threats or automate responses must now show who reviews those outputs and when.
Governance controls affected
What to do now
- ☐Confirm whether your institution has a documented AI cyber risk action plan covering all eight ECB domains (governance, asset mapping, vulnerability management, detection, response, recovery, resilience testing, and technology-provider oversight), and identify which domains are missing.
- ☐Map every AI tool used in your security operations, such as tools that scan for threats or flag suspicious activity, and document which staff review their outputs before action is taken.
- ☐For each AI-assisted security tool, prepare a written benefit-risk assessment and confirm it has been reviewed and approved by the appropriate governance body before the October 31 deadline.
- ☐Review contracts with technology providers to confirm they include obligations to notify you of AI-related changes or incidents that could affect your operational resilience posture.
- ☐Schedule a tabletop exercise before October 31 that simulates an AI-enabled cyberattack, and document the results as evidence of resilience testing for supervisory purposes.
What to watch next
Supervisory follow-up from the ECB is likely in the first quarter of 2027. At that point, inspectors will assess whether submitted action plans reflect genuine program substance rather than documentation only. Banks should also monitor whether the European Banking Authority issues supplementary guidance that defines minimum standards for each of the eight domains, which would tighten the current expectation further. The EU Digital Operational Resilience Act threat-led penetration testing cycle is a natural vehicle for AI-specific resilience evidence, and regulators are likely to ask how the two programs connect.
Stay ahead of stories like this
Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.
