AI Regulation Tracker · ECB · Letter

What does ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) say about AI in banking?

Published Jul 7, 2026 · Last reviewed Aug 26, 2026

On 7 July 2026 Claudia Buch, Chair of the ECB Supervisory Board, sent letter SSM-2026-0301, 'Addressing AI-enabled cybersecurity threats', to the CEO of every significant institution. It states that emerging AI models can identify vulnerabilities and generate working exploits at unprecedented speed — a long-term shift, not a risk tied to any single tool — and, invoking DORA, requires each bank to assess the threat landscape without delay and submit a comprehensive action plan to its Joint Supervisory Team by 31 October 2026. Short-term priorities are accelerated vulnerability and patch management at scale, better monitoring, detection and AI-enabled defence, and third-party risk management fit for the situation; the ECB also postponed the annual IT Risk Questionnaire from September 2026 to February 2027.

DocumentECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutions
Issued byEuropean Central Bank — Banking Supervision (SSM)
TypeLetter
StatusIn force
PublishedJul 7, 2026
EffectiveJul 7, 2026
Applies toCEOs of all significant institutions directly supervised by the ECB (about 110 banking groups).
Official sourcebankingsupervision.europa.eu
Use casesCybersecurity · Third-party & vendor AI · Generative & agentic AI · AI governance (general)

What are the key points of ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)?

  • Reference SSM-2026-0301, dated 7 July 2026, signed by Supervisory Board Chair Claudia Buch; addressed to every SI CEO
  • Action plan due to the bank's JST by 31 October 2026, with concrete measures, resources, named roles and responsibilities, and timelines, built on the existing cyber-risk strategy
  • Short-term focus: accelerate vulnerability and patch management at scale; enhance monitoring, detection and AI-enabled defensive capabilities; verify third-party (ICT provider) risk management
  • Prioritise perimeter technologies and internet-facing assets, including third-party software and open-source components
  • Structural measures: defence-in-depth and cyber hygiene, replacing legacy/unsupported/end-of-life technology, response and recovery, crisis management, information sharing
  • Management bodies must revisit ICT investment, resource allocation and ICT risk-tolerance frameworks where needed; open findings from inspections, targeted reviews and the 2024 cyber-resilience stress test to be closed without delay
  • ECB will run a horizontal analysis of all action plans and share conclusions; further workshops possible depending on frontier-AI developments
  • IT Risk Questionnaire deadline moved from September 2026 to February 2027; other supervisory activities may be adjusted case by case

What did ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) change for banks?

This is the first ECB 'letter to banks' in several years and the first ever devoted to a technology threat. It converts speech-level warnings into a dated, bank-by-bank deliverable that JSTs will monitor, effectively making AI-driven cyber risk a 2026 SREP topic for every significant institution.

When is the ECB AI cybersecurity action plan due?

By 31 October 2026, submitted to the bank's Joint Supervisory Team, per letter SSM-2026-0301 of 7 July 2026.

What must the ECB AI-cyber action plan contain?

Concrete measures to strengthen controls, allocated resources, clear roles and responsibilities and implementation timelines, covering accelerated patching, enhanced detection and AI-enabled defence, third-party risk management, and structural measures such as legacy replacement and response and recovery.

Did the ECB delay the IT Risk Questionnaire in 2026?

Yes. The letter extends the annual IT Risk Questionnaire collection from September 2026 to February 2027 so banks can focus on the action plans.

DateDocumentStatus
Jun 3, 2026Elderson speech: 'Strengthening operational resilience for the age of AI' (June 2026)Strengthening operational resilience for the age of AI — speech by Frank EldersonFinal
Feb 24, 2026Machado speech: 'Technology is neutral, governance is not' (Feb 2026)Technology is neutral, governance is not: AI adoption in the banking sector — speech by Pedro MachadoFinal
Feb 3, 2026Montagner speech: 'Encouraging innovation, managing risks' (Feb 2026)Encouraging innovation, managing risks: the ECB's approach to digital transformation — speech by Patrick MontagnerFinal
Nov 20, 2025Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025)AI's impact on banking: use cases for credit scoring and fraud detection (Supervision Newsletter, November 2025)Final
Nov 18, 2025SSM supervisory priorities 2026–28ECB Banking Supervision: SSM supervisory priorities for 2026–28In force
Oct 14, 2025Machado speech: 'Artificial intelligence and supervision: innovation with caution' (Oct 2025)Artificial intelligence and supervision: innovation with caution — speech by Pedro MachadoFinal

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →