# ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301): Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutions

Source: https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026
Last updated: Aug 26, 2026

On 7 July 2026 Claudia Buch, Chair of the ECB Supervisory Board, sent letter SSM-2026-0301, 'Addressing AI-enabled cybersecurity threats', to the CEO of every significant institution. It states that emerging AI models can identify vulnerabilities and generate working exploits at unprecedented speed — a long-term shift, not a risk tied to any single tool — and, invoking DORA, requires each bank to assess the threat landscape without delay and submit a comprehensive action plan to its Joint Supervisory Team by 31 October 2026. Short-term priorities are accelerated vulnerability and patch management at scale, better monitoring, detection and AI-enabled defence, and third-party risk management fit for the situation; the ECB also postponed the annual IT Risk Questionnaire from September 2026 to February 2027.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [ECB](https://www.bankingnewsai.com/ai-regulation/ecb) |
| Type | Letter |
| Status | In force |
| Published | Jul 7, 2026 |
| Effective | Jul 7, 2026 |
| Applies to | CEOs of all significant institutions directly supervised by the ECB (about 110 banking groups). |
| Official text | https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf |

## Key points

- Reference SSM-2026-0301, dated 7 July 2026, signed by Supervisory Board Chair Claudia Buch; addressed to every SI CEO
- Action plan due to the bank's JST by 31 October 2026, with concrete measures, resources, named roles and responsibilities, and timelines, built on the existing cyber-risk strategy
- Short-term focus: accelerate vulnerability and patch management at scale; enhance monitoring, detection and AI-enabled defensive capabilities; verify third-party (ICT provider) risk management
- Prioritise perimeter technologies and internet-facing assets, including third-party software and open-source components
- Structural measures: defence-in-depth and cyber hygiene, replacing legacy/unsupported/end-of-life technology, response and recovery, crisis management, information sharing
- Management bodies must revisit ICT investment, resource allocation and ICT risk-tolerance frameworks where needed; open findings from inspections, targeted reviews and the 2024 cyber-resilience stress test to be closed without delay
- ECB will run a horizontal analysis of all action plans and share conclusions; further workshops possible depending on frontier-AI developments
- IT Risk Questionnaire deadline moved from September 2026 to February 2027; other supervisory activities may be adjusted case by case

## What changed for banks

This is the first ECB 'letter to banks' in several years and the first ever devoted to a technology threat. It converts speech-level warnings into a dated, bank-by-bank deliverable that JSTs will monitor, effectively making AI-driven cyber risk a 2026 SREP topic for every significant institution.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## FAQ

### When is the ECB AI cybersecurity action plan due?

By 31 October 2026, submitted to the bank's Joint Supervisory Team, per letter SSM-2026-0301 of 7 July 2026.

### What must the ECB AI-cyber action plan contain?

Concrete measures to strengthen controls, allocated resources, clear roles and responsibilities and implementation timelines, covering accelerated patching, enhanced detection and AI-enabled defence, third-party risk management, and structural measures such as legacy replacement and response and recovery.

### Did the ECB delay the IT Risk Questionnaire in 2026?

Yes. The letter extends the annual IT Risk Questionnaire collection from September 2026 to February 2027 so banks can focus on the action plans.

## Related documents

- [Elderson speech: 'Strengthening operational resilience for the age of AI' (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-elderson-operational-resilience-age-of-ai-speech-2026) — Strengthening operational resilience for the age of AI — speech by Frank Elderson (Jun 3, 2026)
- [Machado speech: 'Technology is neutral, governance is not' (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-machado-technology-neutral-governance-speech-2026) — Technology is neutral, governance is not: AI adoption in the banking sector — speech by Pedro Machado (Feb 24, 2026)
- [Montagner speech: 'Encouraging innovation, managing risks' (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-montagner-digital-transformation-speech-2026) — Encouraging innovation, managing risks: the ECB's approach to digital transformation — speech by Patrick Montagner (Feb 3, 2026)
- [Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-supervision-newsletter-ai-credit-scoring-fraud-2025) — AI's impact on banking: use cases for credit scoring and fraud detection (Supervision Newsletter, November 2025) (Nov 20, 2025)
- [SSM supervisory priorities 2026–28](https://www.bankingnewsai.com/ai-regulation/documents/ecb-ssm-supervisory-priorities-2026-28) — ECB Banking Supervision: SSM supervisory priorities for 2026–28 (Nov 18, 2025)
- [Machado speech: 'Artificial intelligence and supervision: innovation with caution' (Oct 2025)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-machado-ai-and-supervision-speech-2025) — Artificial intelligence and supervision: innovation with caution — speech by Pedro Machado (Oct 14, 2025)
- [ECB Guide to internal models (July 2025, ML section)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-guide-to-internal-models-2025-machine-learning) — Revised ECB Guide to internal models — expectations for machine-learning techniques in internal models (Jul 28, 2025)
- [ECB Guide on outsourcing cloud services](https://www.bankingnewsai.com/ai-regulation/documents/ecb-guide-outsourcing-cloud-services-2025) — ECB Guide on outsourcing cloud services to cloud service providers (Jul 16, 2025)

Last reviewed Aug 26, 2026. Cite the official text (https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
