The European Central Bank’s push for lenders to develop action plans to address AI-driven cyber threats will strengthen banks’ ability to withstand increasingly sophisticated attacks and give “laggards” a chance to close resilience gaps, according to analysis from Moody’s Ratings.

Claudia Buch, chair of the ECB’s supervisory board, last week wrote to European banking chiefs giving them till October 31 to submit action plans assessing AI-enabled cyber threats, highlighting concerns about frontier AI models shortening the time between identifying and exploiting software vulnerabilities.

Moody’s described the ECB’s supervisory exercise as “credit positive” for banks, arguing the move should strengthen banks’ operational resilience and accelerate the patching of vulnerabilities at a time when AI is increasing the speed and scale of cyber attacks.

Niclas Boheman, vice-president of ratings at Moody’s, told The Banker that ECB oversight should reinforce the work of banks with modern tech platforms and strong IT governance frameworks.

However, “laggards” with weaker controls could also gain more over the longer term if “resilience gaps” are closed, he added.

Bank of England governor Andrew Bailey warned earlier this year that frontier AI models such as Anthropic’s Claude Mythos Preview could “crack the whole cyber-risk world open” by detecting IT vulnerabilities that have lain hidden for decades.

While AI models’ ability to identify and exploit security weaknesses could be “credit negative” for banks, particularly if they are unable to meet heightened regulatory expectations, the ECB’s intervention is likely to improve cyber governance and risk management, said Boheman.

Moody’s said the ECB expects lenders to assess how the threat landscape is evolving and develop “detailed” action plans regarding resource allocation, remediation of vulnerabilities and implementation timelines.

Near-term priorities include accelerating vulnerability and patch management, strengthening monitoring and “AI-enabled” defensive capabilities, improving oversight of third-party IT providers and enhancing protection of “internet-facing assets”.

To meet its requirements, banks with more extensive legacy IT infrastructure, weaker controls or unresolved supervisory actions may need to invest more in cyber security, IT modernisation, staffing and managing third-party risks, said Moody’s.

However, the potential benefits from reducing financial losses, operational disruption and reputational damage associated with a severe cyber incident should “outweigh these costs” and “narrow resilience gaps” across the sector, it added.

According to the rating agency, European lenders are relatively “well positioned” compared to other sectors such as utilities, with a relatively low prevalence of security flaws. However, unresolved security vulnerabilities still take time to patch, with a median remediation period of between 60 and 80 days for European banks, it estimates.

While frontier AI models can increase the speed at which existing cyber threats materialise, banks are also leveraging AI to improve their ability to detect and patch software vulnerabilities at pace.