A July supervisory letter gives banks until 31 October 2026 to file an action plan on AI-enabled cyber threats, tying the request to DORA-style operational resilience.
Euro-area supervisors are pushing significant banks to prepare an action plan by 31 October 2026, signaling that AI-driven threat acceleration has become a governance issue, not just an IT problem.