News 05 Dec. 2024
Partner Dr. Alexandra G. Maier Recognized Again in Lexology Client Choice Award 2025, Mining Experts Category 2025
more
Event 23 Oct. 2024
Counsel Mohannad El Murtadi Suleiman to Speak at the 2nd Annual Africa Arbitration Day in New York
Event 18 Aug. 2023
Partner Borzu Sabahi Speaks at FDI Moot Shenzhen
News 25 Jul. 2023
Partner Eric Gilioli Ranked in Top 10 Influential Energy & Natural Resources Lawyers in Kazakhstan in Business Today
Client Alert 10 Sep. 2026
California Responsible Textile Recovery Act: What Fashion and Luxury Companies Need to Know
Client Alert 20 Apr. 2026
Italy Implements the EU's “Breakfast Directive”: New Rules for honey, Juices, Jams and Milk
News 24 Aug. 2026
Curtis Advises Ecopetrol Capital AG on US$1.2 Billion Bridge Financing for Acquisition of Controlling Stake in Brava Energia
News 22 Oct. 2025
Curtis Named Leading Firm in Legal 500: Latin America 2026
News 17 Jun. 2025
Curtis Announces Dual Promotion to Partner and Counsel in Dubai
News 02 Jun. 2025
Curtis advises Al Ain Farms on two strategic acquisitions, making it the largest integrated dairy and poultry producer in United Arab Emirates
News 04 Aug. 2026
Curtis Files Amicus Brief on Behalf of Community-Based Organizations in the U.S. Territories in Supreme Court NEPA Case
Client Alert 10 Jul. 2024
EU Adopts New Restrictive Measures Against Belarus
Client Alert 26 Jun. 2024
The EU Adopts its 14th Sanctions Package Against Russia
news
Legal 500 Recognizes Curtis as Leading Firm in UK 2027 Guide
client alert
Digital Operational Resilience and Artificial Intelligence
Client Alert 01 Oct. 2026
Within weeks of one another, the European Systemic Risk Board (“ESRB”) and the European Central Bank (“ECB”) sounded a coordinated alarm on the systemic cybersecurity risks posed by frontier artificial intelligence models. The Bank of Italy and the three European Supervisory Authorities (“ESAs”) have since confirmed ICT and cyber resilience and AI-driven threats as a shared supervisory priority.
Two recent Italian cases show why: an AI-driven fraud against a major private-banking institution, in which a forged WhatsApp message and an AI-cloned voice call led to wire transfers of approximately EUR 95 million, with at least EUR 36 million still unrecovered; and the theft of confidential data belonging to 680 customers of a well-known European fintech bank, obtained by impersonating an Italian Ministry of Interior office.
The ESRB warns that frontier AI models (“FAIMs”) can now discover vulnerabilities and execute full-scale cyber-attacks at unprecedented speed and scale – a paradigm shift that widens the gap between attackers and defenders and exposes weaker institutions to systemic risk.
The ECB has asked Significant Institutions under its direct supervision to submit a comprehensive action plan to their Joint Supervisory Team by October 31, 2026, covering vulnerability management, AI-enabled monitoring and third-party risk.
The Bank of Italy has called on Supervised Entities to strengthen safeguards across governance, cyber hygiene, ICT asset management, vulnerability management, monitoring and resilience testing, with a structured report and work plan – vetted by the Board of Directors and Board of Statutory Auditors – due by December 31, 2026.
The ESAs’ joint risk assessment confirms these as converging EU-wide priorities: an EBA survey on non-EU/EEA dependencies shows that around 80% of banks surveyed cite dependency on ICT service providers as their single biggest challenge.
The upcoming deadlines demand immediate board-level attention and a structured assessment across governance, cybersecurity, vendor management and crisis-response readiness. Entities that sit within the supply chain of Significant Institutions and Supervised Entities – including ICT service providers, cloud and software vendors, payment-solution providers and other outsourced or critical third parties – should not underestimate the impact: contractual obligations, due-diligence and audit requirements imposed by supervised counterparties, reputational exposure and the incoming AI Act are turning these standards into a market-wide benchmark that extends well beyond directly supervised entities.
Existing verification and authentication procedures should be stress-tested against AI-enabled social-engineering and impersonation attacks, and cybersecurity risk assessments should translate into concrete technical controls, consistent with Article 32 GDPR and recent enforcement precedent.
At Curtis. our team advises banking and financial institutions on the governance and cybersecurity commitments underlying the action plans required by the ECB and the Bank of Italy, reviews authentication and third-party risk management procedures, and navigates the intersection of the DORA Regulation, the AI Act, data-protection law and corporate governance.
Banking and Finance
Corporate
Data Protection and Privacy Law
Artificial Intelligence
Cryptocurrency, Digital Assets and Blockchain
Gaia Morelli
Partner
Giovanni Sagramoso
Maria Elena Sarvia
Associate
Rome
+39 06 6758 2201
Milan
+39 02 7623 2001