


On 7 July 2026, the ECB gave every supervised bank four months to submit an action plan against AI-enabled cyberattacks. We've built the framework: a guide plus a fill-in Word template ready for the Board and your JST.
A concise walkthrough of the mandate:
A fill-in .docx structured for JST submission:



All significant institutions directly supervised by the ECB, including the largest euro-area banks and the euro-area subsidiaries of international groups such as US banks. If a Joint Supervisory Team oversees you, the 31 October deadline applies.
A formal action plan against AI-enabled cyberattacks: concrete immediate and longer-term measures, named accountability, and Board-level direction, submitted to your Joint Supervisory Team.
It builds on the same resilience agenda. Our template cross-references DORA obligations, including incident reporting timelines, the Register of Information and threat-led testing, so one control set satisfies both.
Yes. We ask for your business details so we can send you the files and relevant updates, including the ECB’s announced follow-up on quantum-computing risk. Unsubscribe anytime.
Yes. Regulators in the UK and US are signalling the same expectations. The ECB letter is simply the first with a date attached. The framework works as a readiness baseline for any financial institution.