The move follows a warning from the European Systemic Risk Board that frontier AI models could materially increase systemic cyber risk across the EU financial system.

The message is important because it shifts the discussion from “AI in cybersecurity” to AI as a supervisory resilience issue. The ECB is not asking banks to experiment with new tools. It is asking them to reassess whether their existing cyber-risk strategies, governance structures, investment priorities and operational resilience plans remain adequate in a threat environment where vulnerabilities may be found and exploited much faster than before.

The ESRB describes frontier AI models as advanced systems that can affect offensive and defensive cyber operations. Its warning says these models may increase the speed, scale and sophistication of cyberattacks and create new pressures for financial institutions, market infrastructures and authorities. The Board’s General Board had already assessed systemic cyber risk as “severe” in June, up from “elevated” in March.

For bank boards and CISOs, the most significant point is the compression of time. Traditional cyber resilience assumes that organisations have some defensive buffer between vulnerability discovery, vendor patching, testing, deployment and possible exploitation. The ESRB warns that frontier AI may reduce that buffer by accelerating vulnerability discovery and exploit development. In practical terms, the bottleneck may no longer be finding the problem. It may be deciding how fast the institution can safely fix it without creating outages in critical services.

The ECB’s required action plans must cover both immediate priorities and longer-term strategic measures. In the short term, banks are expected to accelerate vulnerability and patch management at scale, improve monitoring and detection, strengthen AI-enabled defensive capabilities, and verify whether third-party ICT risk management remains fit for purpose. The ECB also highlights perimeter technologies, internet-facing systems, externally exposed ICT assets, third-party software and open-source components as areas requiring particular attention.

Longer-term expectations are equally important. The ECB points to defence-in-depth, cyber hygiene, replacement or updating of legacy and end-of-life technologies, response and recovery mechanisms, crisis management and information sharing. This is a clear sign that supervisors see AI-enabled cyber risk not as a narrow security-control topic, but as a broader operational resilience question involving technology architecture, governance, funding and executive accountability.

The link with DORA is direct. The ECB states that the Digital Operational Resilience Act remains highly relevant in the changing cybersecurity landscape. That matters because DORA already requires financial entities to manage ICT risk, third-party dependency, incident response, resilience testing and governance in a more structured way. The new ECB letter effectively raises the urgency: banks should not treat DORA implementation as a static compliance project if the threat environment itself is accelerating.

The ESRB’s analysis also introduces a strategic dependency dimension. It warns that leading frontier AI providers are concentrated outside the European Union, creating potential asymmetry between jurisdictions and between institutions with different access to advanced defensive capabilities. This creates a difficult question for Europe: if advanced AI models can materially improve defensive testing and vulnerability discovery, restricted or uneven access may become a resilience gap in itself.

The issue is not limited to the euro area. On the same day, the Bank of England’s Financial Policy Committee said rapid advances in frontier AI had increased financial stability risks related to cyber and operational resilience. It warned that software vulnerabilities could be identified and exploited faster than firms can respond, and that patching itself could become a source of systemic operational risk if performed under pressure across interconnected services.

The Financial Stability Board had already flagged the same direction in June, noting that powerful frontier AI models may sharply increase cyber risks and that patching efforts, while necessary, can create problems if rushed or poorly executed. This confirms that the topic is moving from national cyber agencies into the language of central banks, macroprudential supervisors and financial-stability bodies.

CyberKreuz believes the immediate lesson for cybersecurity leaders is that AI-driven cyber risk cannot be managed only inside the security function. It requires board-level decisions on acceptable operational risk, technology debt, third-party exposure, patching speed, resilience testing and crisis readiness. The institutions best prepared for this shift will be those that can combine faster security operations with disciplined change management and clear executive accountability.

For financial institutions, the October deadline should be treated as more than a supervisory submission date. It is a test of whether cyber resilience programmes are still calibrated to the current threat landscape. For other regulated sectors, the conclusion is the same: once AI changes the economics and timing of cyberattacks, resilience expectations will follow.