
The European Central Bank (ECB) has taken a firm stance. In a letter sent to the CEOs of the 110 banks it directly supervises, the Chair of the Supervisory Board, Claudia Buch, demands that banks submit a detailed plan by October 31 to mitigate cybersecurity risks stemming from artificial intelligence (AI). The letter, described as having an "unusually urgent" tone, establishes this task as an "absolute priority" and places the responsibility squarely on management bodies, not just technical teams.
The reason for such urgency is none other than the emergence of next-generation AI models, such as Mythos, developed by the US firm Anthropic. According to Buch, these systems are capable of identifying software vulnerabilities at unprecedented speed, compressing the time between the discovery of a breach and its widespread exploitation . The supervisor warns that this is not a passing risk, but rather "a structural change in the threat landscape."
The Mythos threat and the coordinated response of European institutions

Anthropic acknowledged in April that Mythos possesses such advanced programming capabilities that the company decided to veto its release to the general public. Only a small group of tech and financial giants, such as Amazon, Google, Microsoft, and JPMorgan Chase, have access to the model through Project Glasswing. The White House even temporarily banned its use by foreign nationals for national security reasons , although the ban was lifted in early July due to the rise of Chinese competition, such as Zhipu AI's model.
In this context, the European Systemic Risk Board (ESRB) has raised the risk of systemic cyberattacks from "high" to "severe." In a statement, the body warns that more advanced AI models "give cybercriminals an advantage" by allowing them to discover vulnerabilities and execute attacks with greater speed, scale, and sophistication . The ESRB also notes that the concentration of AI providers outside the EU leaves the bloc exposed to strategic dependence and geopolitical risks, and therefore urges a coordinated response involving banks, security firms, and software developers.
Three lines of defense and tight deadlines for the banks

The ECB's letter is not overly prescriptive, but it does highlight three key areas that banks must strengthen. The first is "security by design": preventing software from having vulnerabilities from the outset . The second is correcting any vulnerabilities that do appear as quickly as possible through patches, drastically reducing remediation times to days, not months. The third is having robust defenses in place, including intrusion detection systems, protocols for isolating compromised systems, and the ability to quickly restore operations.
Significant Spanish banks, such as Santander and BBVA, must submit their plans to the Joint Supervisory Teams (JSTs) by October 31, leaving less than four months to design, approve, and document strategies that will then need to be ratified by their boards of directors. The ECB has decided to postpone the annual collection of the Technology Risk Questionnaire until February 2027 so that banks can focus their resources on this priority. Furthermore, the supervisor warns that it will use all the tools at its disposal, including potential fines or capital surcharges, if it detects serious deficiencies.
Buch also pointed out that other emerging technologies, such as quantum computing, will have a significant impact on cybersecurity, although for now the focus is on AI. "While these advances don't introduce entirely new risks, they significantly amplify the speed and scale at which they materialize ," warns the Chair of the Supervisory Board. European banks, therefore, face a major challenge: to protect themselves against a threat that is evolving faster than their own technology departments, against the clock.
