European watchdog sounds the alarm. Advanced AI models pose a serious risk to European banks’ defenses

European watchdog sounds the alarm. Advanced AI models pose a serious risk to European banks’ defenses

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
10. 7. 2026
5 minutes reading
European watchdog sounds the alarm. Advanced AI models pose a serious risk to European banks’ defenses

    The European Systemic Risk Board (ESRB) issued a warning that can be summed up in one sentence: the most advanced artificial intelligence models are beginning to weaken the cyber resilience of the financial system. On the same day, the European Central Bank’s banking supervision arm sent a letter to the heads of the eurozone’s largest banks stating that they must have a plan ready by the end of October on how to defend against AI-powered attacks. The ESRB classified systemic cyber risk as “severe,” after rating it as “elevated” as recently as March.

    Advanced AI models

    These are so-called frontier models, cutting-edge artificial intelligence systems capable of fundamentally affecting both offensive and defensive operations in cyberspace. The ESRB describes them as a turning point for cybersecurity.

    What is interesting is how the board described the ambiguity of the entire situation. In the long term, these models will probably strengthen defenses, but in the short and medium term they favor attackers, enabling them to identify weaknesses and carry out attacks faster, on a larger scale, and with greater sophistication. In other words, the technology that is supposed to protect the gate one day is currently more likely to help break through it.

    Security experts have documented a specific example. Advanced models can reverse-engineer a security patch in roughly thirty minutes, effectively eliminating the time between the release of a fix and the moment an attacker exploits the original vulnerability. Banks used to have entire days to deploy a fix. Now they have literally only minutes

    Orders for banks

    That is precisely why ECB supervision issued an unusually specific requirement. The letter was sent to approximately 110 banks under the central bank’s direct supervision. According to the letter, this is not a temporary phenomenon but a long-term transformation of the threat landscape. The new models reportedly do not introduce entirely new types of risks, but they significantly increase the speed and scale at which those risks materialize.

    Frankfurt now expects several things from the banks. They must accelerate software patching, strengthen defenses that use AI itself, and tighten oversight of third-party suppliers. In the long term, they must also modernize outdated infrastructure. Priority should be given to internet-facing systems, exposed technical assets, and open-source components.

    Banks must submit their completed plans to their joint supervisory teams by October 31, 2026. The ECB will discuss the plan with each institution and conduct a cross-sector benchmarking analysis to identify both common weaknesses and best practices.

    To give banks some breathing room, supervisors have also made a concession. The ECB is postponing the regular IT risk questionnaire, originally scheduled for September, until February of next year and is considering adjustments to other supervisory activities.

    Dark scenarios

    The ESRB did not stop at a general warning and outlined what a disaster could look like. It described a whole range of scenarios, from a gradual loss of confidence in smaller banks and state-sponsored espionage to coordinated attacks on payment, clearing, and settlement systems, which could also be amplified by disinformation campaigns.

    The board also warned that incidents can spread rapidly through shared technology providers and software used across the financial sector. It is therefore enough to breach a single weak point at a supplier on which dozens of banks depend.

    And then there is trust, banking’s most fragile commodity. The ESRB warned that widespread cyber outages could erode confidence and trigger attacks on weaker institutions. In an extreme case, this could reportedly affect companies or countries perceived as less secure.

    Europe is dependent on foreign technology

    According to the ESRB, the concentration of leading AI providers outside the European Union exposes the EU to strategic dependencies and geopolitical risks. Put simply, Europe does not have its own cutting-edge models and must rely on foreign companies.

    The cyber capabilities of some systems are considered so powerful that access to them has been restricted, and eurozone banks are currently excluded from Anthropic’s Mythos model. European banks are therefore expected to defend themselves against tools to which they do not have access, while some US institutions face no such restriction.

    The ECB is therefore pushing for information sharing among European banks. It argues that collectively sharing intelligence about threats could at least partially compensate for the lack of access to the most powerful models.

    Another issue that has yet to fully emerge was also raised. The ECB warned that quantum computers will have a significant impact on cybersecurity and that the transition to post-quantum encryption must begin now. It plans to address this threat in a separate letter at a later date.

    Three different perspectives

    An interesting comparison can be made with other central banks that issued their positions on the same day. Frankfurt adopted the toughest tone.

    Bank of England Governor Andrew Bailey described the ECB’s warning as “reasonable,” but promised a less directive approach himself. He said it was not about issuing orders, but about sitting down together and sharing intelligence about vulnerabilities. The British have long advised banks to strengthen their defenses, but they do not set public deadlines.

    The US central bank sounded even more moderate. The Fed’s Michelle Bowman emphasized the responsible adoption of AI, proportionality, and a “lighter supervisory touch” for lower-risk uses, focusing more on supporting innovation than on responding to systemic cyber threats.

    Three authorities, the same risk, three different speeds. European banks now have four months to show that the strictest of them means business.

    Sources: euronews.com, wmbdradio.com, reuters.com

    Category:AI
    Did you enjoy this article?
    Discover more interesting posts on our blog
    Back to blog

    Related posts

    Altman Announced the Singularity Days After His Models Escaped the Lab on Their OwnAltman Announced the Singularity Days After His Models Escaped the Lab on Their Own
    OpenAI chief Sam Altman declared on the Relentless podcast that humanity has already entered the singularity. “We’re like, in the singularity now,” he said verbatim. For decades, the term belonged more to science-fiction literature
    6 min read
    28. 7. 2026
    AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.
    Since April, Australian radio has been playing a dance remake of Madonna’s hit Like a Prayer on repeat. Released by Queensland DJ Josh Fawaz, it tops the radio airplay chart and has 35 million Spotify streams.
    6 min read
    28. 7. 2026
    Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?
    A first-person shooter that runs directly in the browser, with its own physics and eleven separate code modules. Around 55,000 lines in total, split across eleven subsystems and built on Thr
    4 min read
    28. 7. 2026
    Přihlaste se k odběru našeho newsletteru
    Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
    CodedTrip

    Operated by CodedTrip LLC, USA.

    YouTube
    TikTok