The European Central Bank (ECB) has called on the largest banks in the eurozone to speed up their software patching processes in response to the growing cybersecurity risks posed by advanced artificial intelligence (AI) technologies. The ECB warns that AI models, such as Anthropic’s Claude Mythos, have dramatically shortened the time attackers need to exploit software vulnerabilities, making quick action essential.
Frank Elderson, vice-chair of the ECB’s supervisory board, emphasized that banks must move from a deliberate pace to a much faster response when applying security fixes. Traditionally, attackers took weeks to reverse-engineer patches and develop attacks, but AI now enables this work to be done in as little as 30 minutes. This development puts banks at greater risk if they delay patching software flaws.
The ECB recently met with top executives of its largest supervised banks to discuss strategies for faster patch deployment. These discussions are expected to continue as the regulator pushes for improved operational resilience. American banks operating in Europe are also subject to the ECB’s resilience requirements, highlighting the global reach of these cybersecurity challenges.
While urging speed, the ECB acknowledges that rushing software changes can cause system outages. Data from 2025 showed that 38% of major IT incidents at banks were linked to technology changes. This creates a difficult balance for banks: they must apply patches quickly enough to prevent attacks but cautiously enough to avoid disrupting critical systems. The ECB has stated that banks will need to reassess their risk tolerance to find this balance.
The ECB’s concerns reflect broader regulatory moves in other regions. The United Kingdom’s financial regulators and the International Monetary Fund have also warned about AI-driven cyber threats and urged financial institutions to take proactive measures. However, U.S. financial regulators have yet to issue formal guidance similar to that of the ECB, despite warnings from officials including Federal Reserve Chair Jerome Powell.
The ECB also highlights that European banks face dual challenges: defending against AI-powered attacks and managing risks associated with their growing use of AI tools from a small number of third-party providers. The regulator encourages banks to reduce dependency on single vendors to improve security.
Since January 2025, the Digital Operational Resilience Act (DORA) has empowered the ECB with oversight of banks’ technology risk management and incident responses. The ECB’s supervisory priorities for 2026-2028 identify operational resilience and cybersecurity as critical areas, noting that cyber incidents have doubled in recent years.
In summary, the ECB is leading efforts within the eurozone to enhance banking cybersecurity in an era of rapidly advancing AI threats. Banks are urged to accelerate patching processes while carefully managing operational risks, signaling a significant shift in how financial institutions must approach technology resilience going forward.