










On 7 July 2026, the European Central Bank directed Eurozone banks to have a plan in place by 31 October 2026 to address AI-enabled cyber threats capable of disrupting financial services. The mandate covers banks across the following countries in Europe: Austria, Belgium, Bulgaria, Croatia, Cyprus, Estonia, Finland, France, Germany, Greece, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Portugal, Slovakia, Slovenia, and Spain.
It’s important to note that this isn’t just a guideline—it’s a deadline to take action against increasingly sophisticated cyber threats, and identity is one of the few control layers a bank can act on directly, without waiting on a vendor roadmap or an infrastructure overhaul.
This new mandate by the ECB underscores a larger trend toward stronger identity verification as organizations face increasingly sophisticated cyber threats accelerated by AI. In fact, identity has become the primary attack surface for cybercriminals, with 86% of phishing attacks now being AI-driven.
The mandate reflects a shift regulators can no longer treat as theoretical: AI has compressed the gap between when a vulnerability is discovered and when it’s exploited. Security teams used to have weeks to patch a flaw or catch a suspicious login. In AI-accelerated attacks, that window is now measured in just minutes.
There are three primary trends driving this compression:
Access management is a key control to combat the new reality we live in. As is already the case, legacy authentication mechanisms that rely on a person to make a judgment call under pressure—approving a push notification, reading back a code or trusting a voice on the phone—are no longer sufficient to protect access.
The ECB’s directive is outcome-based, not a prescriptive technology checklist. Banks must go beyond just a policy statement, and create a documented action plan that shows they’ve assessed their exposure to AI-enabled threats, and have concrete mitigations underway. In practice, that means addressing vulnerability management, automated threat detection, and identity and access controls with the same urgency the attackers now operate at.
Identity sits at the center of that plan for a simple reason: it protects the access to systems that could have an exploitable vulnerability. Additionally, it’s the control layer banks can harden fastest, and it’s the one AI is most directly built to attack.
Two areas carry the highest immediate and long-term impact, requiring minimal effort:
The data backs the urgency: IBM’s threat intelligence research points to a 44% year-over-year increase in exploitation of public-facing applications, much of it via AI-assisted credential harvesting. Meanwhile, organizations that replace legacy multi-factor authentication (MFA) with FIDO2/WebAuthn authentication like hardware passkeys have seen account takeovers drop by as much as 99.9%—largely because there’s no phishable secret left in the flow to steal.
Continuous monitoring, just-in-time access segmentation, and incident response playbooks rehearsed against AI-accelerated timelines round out a complete plan. We’ve mapped all five identity controls banking security and risk teams should have in place—with the specific gaps AI opens in each—in a working checklist built for this deadline: Get the Checklist.
Banks already working through DORA’s ICT risk management and strong authentication requirements will recognize a lot of overlap here. Deploying phishing-resistant MFA to satisfy the ECB’s AI mandate simultaneously checks boxes for DORA’s authentication provisions. One identity investment addresses two regulatory obligations.
Eurozone banks operating in Austria, Belgium, Bulgaria, Croatia, Cyprus, Estonia, Finland, France, Germany, Greece, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Portugal, Slovakia, Slovenia, and Spain.
31 October 2026. The directive was issued 7 July 2026.
No, but the two overlap significantly. DORA governs broader ICT risk management and resilience; this mandate specifically requires a plan for AI-enabled cyber threats. Phishing-resistant authentication satisfies requirements under both.
Identity—specifically privileged-access authentication and helpdesk/call-centre verification—because it’s the fastest control to harden and the one AI most directly targets.
The full window between now and 31 October is short for an infrastructure overhaul, but identity controls don’t require one. Deploying hardware-backed, phishing-resistant authentication can happen inside existing IAM infrastructure, without a lengthy development cycle.
Start with the Identity Controls checklist to map where your bank stands today against the ECB’s expectations, and where to focus before the deadline.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。