Client Alert 01 Oct. 2026

Digital Operational Resilience and Artificial Intelligence

The European Systemic Risk Board and the ECB sound the alarm on frontier AI models

Within weeks of one another, the European Systemic Risk Board (“ESRB”) and the European Central Bank (“ECB”) sounded a coordinated alarm on the systemic cybersecurity risks posed by frontier artificial intelligence models. The Bank of Italy and the three European Supervisory Authorities (“ESAs”) have since confirmed ICT and cyber resilience and AI-driven threats as a shared supervisory priority.

Two recent Italian cases show why: an AI-driven fraud against a major private-banking institution, in which a forged WhatsApp message and an AI-cloned voice call led to wire transfers of approximately EUR 95 million, with at least EUR 36 million still unrecovered; and the theft of confidential data belonging to 680 customers of a well-known European fintech bank, obtained by impersonating an Italian Ministry of Interior office.

What are the Regulators saying?

The ESRB warns that frontier AI models (“FAIMs”) can now discover vulnerabilities and execute full-scale cyber-attacks at unprecedented speed and scale – a paradigm shift that widens the gap between attackers and defenders and exposes weaker institutions to systemic risk.

The ECB has asked Significant Institutions under its direct supervision to submit a comprehensive action plan to their Joint Supervisory Team by October 31, 2026, covering vulnerability management, AI-enabled monitoring and third-party risk.

The Bank of Italy has called on Supervised Entities to strengthen safeguards across governance, cyber hygiene, ICT asset management, vulnerability management, monitoring and resilience testing, with a structured report and work plan – vetted by the Board of Directors and Board of Statutory Auditors – due by December 31, 2026.

The ESAs’ joint risk assessment confirms these as converging EU-wide priorities: an EBA survey on non-EU/EEA dependencies shows that around 80% of banks surveyed cite dependency on ICT service providers as their single biggest challenge.

Why does this matter to you?

The upcoming deadlines demand immediate board-level attention and a structured assessment across governance, cybersecurity, vendor management and crisis-response readiness. 
Entities that sit within the supply chain of Significant Institutions and Supervised Entities – including ICT service providers, cloud and software vendors, payment-solution providers and other outsourced or critical third parties – should not underestimate the impact: contractual obligations, due-diligence and audit requirements imposed by supervised counterparties, reputational exposure and the incoming AI Act are turning these standards into a market-wide benchmark that extends well beyond directly supervised entities.

Existing verification and authentication procedures should be stress-tested against AI-enabled social-engineering and impersonation attacks, and cybersecurity risk assessments should translate into concrete technical controls, consistent with Article 32 GDPR and recent enforcement precedent.

How Curtis can help

At Curtis. our team advises banking and financial institutions on the governance and cybersecurity commitments underlying the action plans required by the ECB and the Bank of Italy, reviews authentication and third-party risk management procedures, and navigates the intersection of the DORA Regulation, the AI Act, data-protection law and corporate governance.

Related resources

client alert

Digital Operational Resilience and Artificial Intelligence

Read

client alert

California Responsible Textile Recovery Act: What Fashion and Luxury Companies Need to Know

Read

news

Curtis Advises Ecopetrol Capital AG on US$1.2 Billion Bridge Financing for Acquisition of Controlling Stake in Brava Energia

Read