The European Central Bank has instructed the eurozone’s 110 largest banks to develop cybersecurity action plans addressing threats from advanced artificial intelligence systems, with a submission deadline of October 31, 2026. The plans must prioritize faster vulnerability and patch management, stronger AI-enabled monitoring and detection systems, and closer scrutiny of third-party technology providers. The European Systemic Risk Board simultaneously elevated systemic cyber risk to severe, warning that AI could dramatically reduce the time available to identify and patch software vulnerabilities before they are exploited. To give banks more time to focus on the new requirements, the ECB said it would postpone its annual IT Risk Questionnaire from September 2026 to February 2027.