ECB orders eurozone banks to tighten cyber-security as AI alters threats

▼ Summary
– The European Central Bank has instructed eurozone banks to tighten cyber-security due to AI-led attack tools, turning private guidance into a supervisory expectation.
– The trigger is Anthropic’s Mythos, a restricted AI model that autonomously exploits vulnerabilities; no eurozone institution has access to it.
– Banks must now assume attackers have AI tools of comparable capability, making monthly patching inadequate and requiring vulnerability management to compress to AI-attacker timeframes.
– The ECB flagged contractor exposure as a key risk, holding banks accountable for third-party software security due to supply-chain vulnerabilities.
– Eurozone banks have until end-2026 to demonstrate readiness, with formal supervisory dialogues starting over the summer.
The European Central Bank has formally instructed eurozone lenders to strengthen their cyber-security defenses in response to evolving threats driven by artificial intelligence. The directive, issued as a follow-up statement on Wednesday, transforms earlier informal guidance into a clear supervisory expectation.
Frank Elderson, vice-chair of the ECB’s Single Supervisory Mechanism, articulated the shift with language that signals a stricter regulatory stance rather than a mere discussion paper. The catalyst for this change is Anthropic’s Mythos, a restricted-access AI model capable of autonomously identifying and exploiting cybersecurity vulnerabilities at machine speed. Mythos has demonstrated the ability to chain minor weaknesses into more severe attacks and to reverse-engineer patches into exploitable flaws far quicker than traditional tools.
Access to Mythos remains limited to roughly 40 to 50 organizations, including a handful of U. S. banks; no eurozone institution is on that list. As Elderson stated earlier this month, “lack of access is not an excuse for inaction.” Wednesday’s statement reinforces that position. Banks are now expected to operate under the assumption that attackers will possess AI tools of comparable capability, regardless of whether defenders have them.
The supervisory implications are significant. Traditional monthly software-patching cycles are no longer sufficient. Contractor relationships must be audited for the same vulnerabilities, and the entire institutional approach to vulnerability management must compress to match AI-attacker timeframes. The ECB has indicated it will integrate AI-cyber readiness into its supervisory dialogues with individual banks.
The broader context has also evolved. BNP Paribas is now collaborating publicly with Mistral to develop a sovereign European alternative to Mythos, effectively creating a continent-wide hedge. Brussels has been engaged in stalled negotiations with Anthropic for weeks over expanding Mythos access to European institutions; Spain has described those talks as deadlocked. The ECB’s statement represents the regulatory side of that same challenge: supervisors cannot wait for the access issue to be resolved before demanding a robust defensive posture.
The harder question is what concrete changes banks must actually implement. The ECB has not published a specific list of technical controls, partly because the threat surface is evolving faster than any static checklist could capture. The closest thing to a working playbook is the implicit expectation that banks now treat any unpatched vulnerability as a discoverable target, and that the mean time to patch for critical systems must shrink from weeks to days or even hours.
Smaller eurozone banks, which have historically relied on outsourced infrastructure providers for technical operations, are in a weaker position to meet that timeline compared to the big-three universal banks. The ECB also flagged contractor exposure as an asymmetric problem. Most eurozone banks have a long tail of third-party software vendors with uneven patch discipline. An AI-driven attacker that discovers a vulnerability in a single widely deployed product can pivot into multiple bank environments through that vendor relationship. The SolarWinds-style supply-chain exposure that defined the late 2010s is now being recast in AI-attacker form. Elderson’s framing is clear: supervisors will hold banks accountable for their contractors’ security, not just their own.
Eurozone banks have until the end of 2026 to demonstrate readiness against the ECB’s new posture, with formal supervisory dialogues beginning over the summer. Mythos itself, based on current public reporting, has not been demonstrated in the wild against a European institution.
(Source: The Next Web)



