The ECB Action Plan Against AI Cyberattacks: What Banks Must Submit by 31 October 2026
3 Aug 2026On 7 July 2026, ECB Banking Supervision sent a clear message to significant institutions: by 31 October 2026, every significant institution must submit a concrete action plan to address AI-enabled cyber threats.
This is not a routine compliance exercise. It reflects a structural shift in how cyber risk emerges and scales.
What the ECB is Asking for
The ECB expects banks to build on their existing cyber strategies and translate them into actionable plans with clear priorities, ownership, and timelines. DORA remains the regulatory anchor. A key prerequisite is sequencing. Open supervisory findings, including those from inspections and the 2024 cyber resilience stress test, must be addressed first. Existing weaknesses will become more critical as attack speed increases.
Why AI Changes the Equation
The ECB does not describe AI as a new category of risk, but as an amplifier.
AI significantly compresses the time between vulnerability discovery and exploitation. What used to unfold over weeks or months can now happen in hours. This shift challenges existing operating models in security teams, which are not designed for this level of speed and frequency.
As a result, the response cannot be incremental. Banks need to rethink prioritization, detection, and control mechanisms across their entire cyber stack.
The Six Focus Areas
The action plans themselves are structured across six focus areas:
- Prioritize attack surfaces. Full asset inventory including third-party and open-source components, with perimeter and internet-facing systems first.
- Accelerate vulnerability and patch management. Prioritized scanning and faster patching, with AI tools used only under human oversight.
- Strengthen monitoring and AI-enabled defense. Better analysis of application and access logs and network traffic.
- Reinforce governance, funding, and supply chain. AI-specific metrics in the risk appetite framework, awareness training, harder third-party risk management.
- Advance defense-in-depth. Segmentation, zero-trust verification of users, applications, APIs, and service accounts, least privilege, MFA, and legacy replacement.
- Improve operational resilience. Tested crisis management and recovery, exercises against zero-day waves and destructive attacks, and secure information sharing.
After submission, supervisors will review plans across institutions and continue the dialogue with each bank.
Where NEXIS Fits: The Identity Layer
While much of the ECB’s guidance focuses on traditional security controls, identity plays a central role across multiple focus areas.
Attack surfaces are not only technical. They are also defined by who and what has access. This is where NEXIS adds value.
As an Identity Visibility and Intelligence Platform (IVIP), NEXIS consolidates identity data across IGA, PAM, and other systems into a unified view.
Least privilege. Focus area 5 calls for least-privilege access and continuous verification of users, applications, APIs, and service accounts. Excess entitlements and orphaned accounts are part of the attack surface. NEXIS surfaces unused authorizations and drives their removal, which tightens least privilege and can also retire unused licenses.
Non-human identities and agentic AI. The AI shift multiplies the identities that act. Per a whitepaper from KPMG, non-human identities already outnumber human ones by 25 to 50 times, and MCP servers and autonomous agents push that higher. Service accounts and agents need the same governance as people: lifecycle processes, segregation-of-duties rules that apply to NHIs, and context-based limits. NEXIS governs human and non-human identities in one model.
Visibility (IVIP). An Identity Visibility and Intelligence Platform gives a consolidated view of who and what can access which systems across IGA, PAM, and access management. It exposes cross-system Segregation of Duties (SoD) conflicts that stay invisible in separate silos, and supplies the data foundation that AI-driven monitoring needs.
DORA-ready IAM Governance Documentation. Instead of Word, Excel, or wikis, NEXIS generates authorization concepts from central templates, versions them audit-proof, and checks them continuously against actual configuration through drift detection. That gives the supervisor current, audit-ready evidence the plan has to show anyway.
Conclusion
The deadline is fixed and it’s time for action. The identity layer is no side note: least privilege, governance of fast-growing non-human identities, and audit-ready IAM Governance Documentation each carry several of the six focus areas. Build visibility and control here now, and you do more than satisfy the supervisor. You shrink your attack surface.
See how it works: a short walkthrough of DORA-ready identity implemenation and least-privilege evidence for your ECB action plan:
Sources:
[1] KPMG: EZB fordert Aktionsplan gegen KI-Cyberangriffe bis zum 31. Oktober 2026: Was für Banken jetzt zählt: https://kpmg.com/de/de/themen/finance-und-risk/ezb-fordert-aktionsplan-gegen-ki-cyberangriffe.html#accordion-f80b0b714a-item-5555efdc49
[2] European Central Bank: Addressing AI-enabled cybersecurity threats. July 7, 2026: https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.de.pdf
[3] KPMG & Nexis: Manage and Control Non-Human Identities: https://nexis-secure.com/insights/document/manage-and-control-non-human-identities/