Executive Summary

  • BLUF: Europe has moved from monitoring AI-enabled cyber risk to imposing a dated supervisory response.
  • On 7 July 2026, ECB Banking Supervision instructed significant euro-area banks to submit an action plan by 31 October 2026.
  • The letter is an ECB supervisory measure welcomed—but not jointly issued—by the European Systemic Risk Board.
  • The ESRB had upgraded systemic cyber risk from “elevated” in March to “severe” in June 2026.
  • Frontier models can compress vulnerability-exploitation windows from weeks to hours and overwhelm conventional patch management.
  • Restricted access is real, but it is inaccurate to claim categorically that every European bank appears on a formal exclusion list.
  • The systemic danger is not merely account theft: it is correlated disruption of payments, settlement, market infrastructure and public confidence.
  • Legacy technology, common vendors and concentrated non-EU AI providers create three mutually reinforcing European dependencies.
  • The United States retains serious cyber supervision, but its published AI posture is currently more innovation-oriented and less deadline-driven.
  • By 2031, the decisive variable will be whether defensive automation, infrastructure renewal and collective response mechanisms advance faster than offensive AI diffusion.

The AI Clock Is Ticking Inside Europe’s Banks

Europe’s banking supervisors have placed a date on a threat that until recently belonged to strategic forecasting. By 31 October 2026, the euro area’s largest banks must explain how they intend to withstand cyberattacks accelerated by frontier artificial intelligence. The issue is not simply that AI can improve phishing or write malware. The deeper danger is temporal and systemic: vulnerability discovery, exploit development and attack replication can advance faster than banks can test patches, protect legacy infrastructure and restore trusted services. Because European money now moves through interconnected ledgers, clouds and payment platforms, a technical failure can become a liquidity and confidence event. The question facing Europe is therefore no longer whether AI will alter banking cybersecurity, but whether its defensive institutions can move as quickly as the technologies—and jurisdictions—shaping the offensive frontier.

The October Deadline

On 7 July 2026, ECB Banking Supervision instructed the chief executives of significant euro-area banks to prepare action plans addressing AI-enabled cyber threats and submit them to their respective Joint Supervisory Teams by 31 October 2026. The plans must cover short-term measures—threat monitoring, vulnerability assessment, adversarial testing, patching and incident preparedness—and structural interventions, including defence-in-depth, crisis management and the replacement or updating of unsupported and end-of-life technology. The ECB will conduct a horizontal analysis of the submissions and monitor implementation. Addressing AI-Enabled Cybersecurity Threats – ECB Banking Supervision – July 2026official letter.

This was not a routine circular. The European Systemic Risk Board, chaired by ECB President Christine Lagarde, had adopted a formal warning on 25 June 2026 and, in June, upgraded its assessment of systemic cyber risk from “elevated” to “severe”. Frontier AI Models Could Strain Cyber Resilience in the Financial System – ESRB – July 2026official release. The

Europe’s AI Cyber Ultimatum: Banks Have Until October

Artificial intelligence is changing bank cybersecurity faster than Europe can modernise the systems that hold its money. On 7 July 2026, ECB Banking Supervision instructed the chief executives of significant euro-area banks to submit AI-cyber defence plans by 31 October 2026. The deadline converts a technological concern into a supervisory obligation. The danger is not merely faster fraud or more convincing phishing: frontier models can discover vulnerabilities, assist exploitation and compress the period available for remediation from weeks to hours. Europe must therefore defend payment networks and decades-old banking infrastructure against capabilities it does not fully control—and may not always be permitted to access. The issue now confronting Frankfurt, national central banks and bank boards is whether regulation, investment and collective defence can advance faster than offensive AI.

The October Deadline

The ECB letter requires banks to identify their exposure to AI-enabled cyber threats, reinforce monitoring and vulnerability management, improve adversarial testing, accelerate remediation and strengthen incident response. It also demands structural measures: defence-in-depth, cyber hygiene, crisis-management capacity and the replacement or updating of unsupported and end-of-life technology. Each action plan must reach the institution’s Joint Supervisory Team by 31 October; the ECB will subsequently conduct a horizontal analysis across significant institutions. Addressing AI-Enabled Cybersecurity Threats – ECB Banking Supervision – July 2026official letter.

The institutional sequence is significant. The European Systemic Risk Board, chaired by ECB President Christine Lagarde, adopted a separate formal warning on 25 June and published it on 7 July. The ESRB had upgraded its assessment of systemic cyber risk from “elevated” in March to “severe” in June 2026. This was not a prediction of an imminent banking collapse. It was an acknowledgement that existing vulnerability-management practices were designed for a slower threat environment. Frontier AI Models Could Strain Cyber Resilience in the Financial System – ESRB – July 2026official warning announcement.

The Vanishing Window

The strategic discontinuity is time. The ESRB reports that frontier AI models can assist autonomous pipelines for vulnerability discovery, exploit development and weaponisation, including previously unknown flaws in widely used operating systems and software. It warns that the interval between initial exploitation and widespread automated exploitation could contract from weeks to hours. Banks may then face an “unpatchable” interval in which attackers reverse-engineer a correction or weaponise a vulnerability before the institution can safely test and deploy the remedy.

The United Kingdom’s AI Security Institute has supplied an important technical reference point. Its “The Last Ones” cyber range simulates a 32-step corporate-network intrusion, spanning reconnaissance, credential theft, lateral movement, compromise of development infrastructure and final data exfiltration. The institute estimated that a human operator would require about 20 hours to complete the range; 2026 evaluations showed leading agents progressing through the full multi-stage chain under sufficiently large computational budgets. Our Evaluation of Claude Mythos Preview’s Cyber Capabilities – UK AI Security Institute – April 2026official evaluation.

This does not mean that every model can autonomously take over a bank in minutes. Production banking environments are proprietary, segmented and heavily controlled. It does mean that reconnaissance, exploit adaptation, credential analysis and lateral movement can be parallelised at falling marginal cost. An attacker can tolerate failed experiments; a bank cannot patch a core ledger, identity system or payment gateway without regression testing, rollback preparation, segregation-of-duties approval and assurance that transactions will remain complete and accurate.

Europe’s Access Paradox

The most politically sensitive asymmetry concerns access. The ESRB records that providers restricted dissemination of advanced cyber-capable models because unrestricted use was considered too dangerous. Controlled-access programmes initially favoured US institutions, were later extended unevenly to European counterparts and did not cover every EU Member State. The report concludes that early European access to future frontier models cannot be assumed because leading providers and applicable export-control regimes are concentrated in third-country jurisdictions. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – ESRB – July 2026official report.

It would be inaccurate to describe this as a single formal blacklist excluding every European bank. The verified reality is more complex—and strategically more consequential. Model access varies by provider, jurisdiction, customer and capability level. A bank may possess an enterprise AI contract while lacking permission to test the provider’s most capable cyber system against sensitive internal code. Europe can therefore require institutions to defend themselves against a capability whose early availability, contractual continuity and operational limits are determined elsewhere.

The dependence is already material. ECB Banking Supervision reported in February 2026 that more than 85% of supervised banks use AI and that generative applications are expanding in IT operations, legal analysis, document processing and customer-facing activities. It simultaneously warned that generative models are sourced from a small group of major non-EU providers, creating geopolitical, data-protection and operational-concentration risks. Encouraging Innovation, Managing Risks: The ECB’s Approach to Digital Transformation – ECB Banking Supervision – February 2026official assessment.

The Legacy Burden

Europe’s banks have invested heavily in digital channels, yet critical functions may still depend on mainframes, legacy middleware, proprietary interfaces and software inherited through decades of mergers. Age alone does not make a system unsafe: a mature mainframe can be stable and well protected. The danger arises when technology is unsupported, poorly documented, dependent on scarce expertise or connected to modern services through opaque layers that cannot be modified rapidly.

The ECB’s 2024 cyber-resilience stress test involved 109 directly supervised banks; 28 underwent deeper testing, including actual IT recovery exercises and on-site scrutiny. The scenario assumed that preventive controls had failed and a cyberattack had impaired databases supporting core systems. Banks generally possessed response and recovery frameworks, but the exercise identified shortcomings in continuity, recovery objectives, communication and coordination. ECB Concludes Cyber Resilience Stress Test – ECB Banking Supervision – July 2024official results.

Subsequent ECB research found that the number of critical systems classified as end-of-life fell by an estimated 41.2% after the stress-test announcement. The same analysis observed higher intra-group ICT expenditure, increased cyber-insurance adoption and more frequent board review of outsourcing indicators. These are signs of accelerated remediation, not proof that the legacy problem has been eliminated. Disciplining Digital Risk: Evidence from Cyber Stress Tests – ECB Working Paper Series – May 2026official research.

Payments as the Systemic Fault Line

The principal danger is transmission. A cyber incident becomes systemic when it disrupts an irreplaceable function, propagates through a common provider or changes depositor and counterparty behaviour. In 2025, the Eurosystem’s T2 platform processed 111.9 million transactions and settled €492.859 trillion. Average daily settlement reached €1.933 trillion; interbank payments represented 54.8% of value. Italy accounted for 9.4% of T2 volume, behind Germany and France but ahead of Spain. TARGET Services Annual Report 2025 – European Central Bank – July 2026official report.

A payment outage does not need to destroy bank capital to generate liquidity stress. Delayed incoming payments can prevent recipients from meeting outgoing obligations; transaction queues increase intraday liquidity requirements; institutions begin conserving balances; collateral cannot be delivered; and counterparties demand prefunding. The more dangerous case involves data integrity rather than availability. If balances, payment instructions or settlement timestamps cannot be trusted, a restored platform may be technically online but economically unusable.

Common providers intensify the exposure. Banks that appear diversified financially may depend on the same cloud control plane, identity service, telecommunications carrier, cybersecurity product or software component. DORA, applicable since 17 January 2025, establishes common requirements for ICT risk management, incident reporting, resilience testing and third-party oversight. Yet regulation cannot instantly create substitute cloud capacity or migrate a core banking application. Regulation (EU) 2022/2554 on Digital Operational Resilience – European Parliament and Council – December 2022official text.

The Confidence Weapon

The final transmission channel is psychological but financially measurable. The IMF warns that a cyber incident can cause deposit withdrawals or a “cyber run,” turning an operational disturbance into liquidity pressure and, in extreme cases, solvency stress. It identifies systemic banks, payment infrastructures, central banks and major cloud providers as potential transmission hubs. Global Financial Stability Report, Chapter 3 – International Monetary Fund – April 2024official report.

Artificial intelligence makes confidence itself an attack surface. Forged executive statements, synthetic audio, counterfeit regulatory notices and fabricated screenshots can accompany a real outage. The ESRB’s severe hypothetical scenario combines attacks on financial-market infrastructures with a misinformation, disinformation and malinformation campaign intended to amplify public distress. The technical and informational attacks need not be equally successful: uncertainty over whether accounts remain accessible may be sufficient to accelerate transfers toward institutions perceived as safer.

Traditional liquidity buffers remain indispensable, but the critical variable is operational liquidity—the capacity to identify collateral, authenticate instructions, connect to central-bank facilities and execute payments while systems are degraded. A bank can possess abundant liquid assets and still fail operationally to mobilise them.

Italy’s Strategic Choice

Italy enters this contest with both exposure and assets. The National Cybersecurity Agency recorded 407 DDoS attacks in the first half of 2026, although this was 32% below the corresponding 2025 period. Operational Summary H1 2026 – Italian National Cybersecurity Agency – June 2026official report. The figures do not isolate banking, but they confirm the continuing scale of hostile activity against Italian digital infrastructure.

Italy also hosts Leonardo, the EuroHPC pre-exascale supercomputer at Bologna’s Tecnopolo, and the IT4LIA AI Factory. These assets offer Rome an opportunity to move beyond compliance and create a European financial-cyber testing centre: secure analysis of legacy code, synthetic payment environments, controlled evaluation of defensive models and shared services for smaller banks. Europe’s AI-factory programme will receive part of approximately €10 billion in combined EU, Member State and associated-country investment in supercomputing and AI infrastructure during 2021–2027. AI Factories – European Commission – 2026official programme.

The Italian interest is not digital prestige. It is the preservation of payments, savings and industrial working capital under conditions in which attack time is collapsing. Bologna’s computing capacity, Banca d’Italia’s institutional expertise, the national cyber authority and the banking sector should be integrated into a single operational-resilience architecture.

The Cost of Delay

Europe will not achieve technological autarky by 2031, nor should it attempt to replace every global supplier. Its viable objective is controlled interdependence: diversified providers, portable applications, European-controlled evaluation capacity, independently recoverable data and crisis arrangements that remain functional if a model or cloud service becomes unavailable.

The October deadline is therefore only the opening move. Plans that catalogue risks without retiring critical dependencies will produce documentary compliance, not resilience. The decisive indicators are concrete: time from exploit availability to mitigation; number and centrality of unsupported systems; capacity to operate without a primary provider; integrity of recovery data; speed of cross-border threat sharing; and the ability to preserve payments while public confidence is under attack.

Europe’s central banks are not afraid of artificial intelligence in the abstract. They are confronting a narrower and more serious fact: the offensive technology is accelerating faster than the institutions responsible for monetary trust can safely change.


Navigational Index

  1. Threat Compression — Frontier models, zero-days and the collapse of defensive time
  2. Systemic Transmission — Payments, common providers, confidence and liquidity
  3. Strategic Asymmetry — Europe’s legacy systems, model-access gap and five-year choices

Master Abstract

The warning is real—but precision matters

The factual core of the warning is confirmed, although several details require correction. On 7 July 2026, ECB Banking Supervision published a letter addressed to the chief executives of significant euro-area institutions requiring each bank to assess its exposure to AI-enabled cyber threats, identify short- and structural defensive measures, and submit an action plan to its Joint Supervisory Team by 31 October 2026. The document calls specifically for enhanced threat monitoring, continuous vulnerability assessment, adversarial testing, rapid patching, incident-response preparation, defence-in-depth and the replacement or updating of legacy, unsupported or end-of-life technology. It is therefore more than a general expression of concern, but it is not evidence that the ECB expects an imminent collapse: it is a supervisory intervention designed to force measurable preparation before the threat matures further. Addressing AI-enabled cybersecurity threats – ECB Banking Supervision – July 2026 — verified official letter. The institutional attribution also matters. This was an ECB Banking Supervision letter, not a jointly signed ECB–ESRB communication. The ESRB separately adopted a formal warning on 25 June 2026, published alongside the letter on 7 July, after classifying systemic cyber risk as “severe” in June, compared with “elevated” in March. Frontier AI models could strain cyber resilience in the financial system – European Systemic Risk Board – July 2026 — verified official release. Nor does the public record establish a single official list excluding all European banks from advanced models. It establishes a narrower but strategically serious fact: access has been controlled, was initially concentrated among US institutions, did not extend uniformly across the EU, and may remain subject to foreign export controls. That asymmetry—not an unverified universal blacklist—is the analytically defensible finding.

The collapse of defensive time

The technical discontinuity lies less in the novelty of cyber intrusion than in the compression and industrialisation of the attack cycle. The ESRB reports that frontier AI models can support autonomous pipelines for vulnerability discovery, exploit development and weaponisation, including the identification of previously unknown weaknesses in major operating systems and widely used software. Its benchmark discussion compares a 32-step corporate-network attack simulation, estimated to require approximately 20 hours for a human operator, with newer model performance capable of completing the full benchmark; models released at the end of 2025 reportedly averaged only 34% on the same benchmark. The ESRB consequently warns that the interval between initial exploitation and widespread automated exploitation could contract from weeks to hours, producing “unpatchable” operational windows in which a bank must develop, validate and deploy a remedy before attackers reverse-engineer the patch or weaponise the underlying flaw. Addressing frontier AI models with cyber capabilities from a financial stability perspective – European Systemic Risk Board – July 2026 — verified official report. This favors attackers because a bank cannot safely modify a core ledger, payment gateway or identity-management layer as rapidly as an adversary can probe it: regulated institutions must preserve availability, data integrity, auditability and rollback capacity, while attackers incur none of those obligations. The ESRB warning therefore identifies reactive, periodic patching as structurally inadequate when vulnerability volumes rise faster than remediation throughput. Warning on systemic cyber risks stemming from frontier artificial intelligence models – European Systemic Risk Board – June 2026 — verified official warning. Europe enters this transition with a documented exposure base: ENISA examined 488 publicly reported financial-sector incidents between January 2023 and June 2024; credit institutions were the most frequently affected category, appearing in 301 incidents, while IT infrastructure was the most frequently targeted asset and operational disruption the most common observed consequence. ENISA Threat Landscape: Finance Sector – European Union Agency for Cybersecurity – February 2025 — verified official report.

From intrusion to systemic event

A cyberattack becomes systemically relevant when technological commonality converts an institution-specific failure into correlated operational loss. European banks share cloud providers, identity services, operating systems, open-source libraries, telecommunications infrastructure, payment rails and specialised ICT suppliers; the same vulnerability can therefore enter numerous balance sheets without appearing as a conventional financial exposure. Disruption can propagate through payment systems, clearing and settlement mechanisms, liquidity-management processes and other operational bottlenecks, while misinformation, disinformation and malinformation can amplify the technical event by convincing depositors or counterparties that institutions are insolvent, compromised or unable to process withdrawals. The ESRB’s most severe narratives are explicitly hypothetical rather than forecasts, and they assign no probability; nevertheless, they illustrate a credible transmission sequence involving pre-positioned access, synchronised attacks on financial-market infrastructures, disruption of core services and a parallel information campaign intended to erode confidence. Addressing frontier AI models with cyber capabilities from a financial stability perspective – European Systemic Risk Board – July 2026 — verified official report. The policy baseline is stronger than the rhetoric sometimes implies: the Digital Operational Resilience Act, applicable since 17 January 2025, establishes harmonised obligations covering ICT risk management, incident reporting, resilience testing, third-party risk and oversight of critical ICT providers. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector – European Parliament and Council – December 2022 — verified official text. Yet DORA primarily standardises governance and resilience disciplines; it does not itself eliminate obsolete code, guarantee sovereign access to frontier defensive models or solve the speed mismatch between cautious production change and automated exploitation. The October plans will consequently be informative only if supervisors distinguish documentary compliance from operational capability: time-to-detect, time-to-isolate, critical-patch throughput, recovery-point integrity, supplier substitutability and the ability to operate essential services under compromised-data conditions.

Five competing hypotheses for 2026–2031

A five-year assessment should not assume that a single threat pathway will dominate. An Analysis of Competing Hypotheses produces five principal frameworks. H₁ — criminal scaling: frontier capabilities diffuse into ransomware, fraud and access-broker markets, increasing attack frequency but generally preserving economically rational targeting. H₂ — state pre-positioning: intelligence services use AI less for immediate destruction than for stealthy persistence, credential mapping, data extraction and contingency access inside banks and financial authorities. H₃ — systemic infrastructure strike: a state or proxy coordinates attacks against payment, clearing, settlement or critical ICT nodes during a geopolitical crisis, seeking economic paralysis rather than direct theft. H₄ — endogenous defensive convergence: banks, vendors and public authorities deploy AI-assisted vulnerability discovery, automated containment and shared indicators quickly enough to reduce successful exploitation despite higher attempted-attack volumes. H₅ — confidence shock without decisive penetration: synthetic evidence, false breach claims and manipulated customer communications trigger liquidity or reputational stress even where the underlying technical compromise is limited. Current evidence raises H₁ and H₂ above their historical baselines, while H₃ remains lower-probability but highest-impact; H₄ is plausible but depends on model access, safe automation and rapid infrastructure modernisation; H₅ becomes increasingly credible as technical and informational operations converge. These are analytical judgments, not regulator-issued probabilities. Cross-system comparison also cautions against portraying Europe as uniquely alarmist or the United States as unconcerned. The Federal Reserve’s published framework includes enforceable information-security expectations, institution-level examinations, incident monitoring and coordination with other authorities. Cybersecurity and Financial System Resilience Report – Board of Governors of the Federal Reserve System – July 2025 — verified official report. Its emerging AI policy tone is nevertheless more permissive: Vice Chair for Supervision Michelle Bowman emphasised adaptable expectations and safe AI adoption, while noting that revised interagency model-risk guidance was narrowed so it would not automatically govern generative or agentic AI. Artificial Intelligence in the Financial System – Federal Reserve Board – May 2026 — verified official speech.

Strategic asymmetry and the 2031 outlook

The central five-year contest is a race among three curves: offensive capability diffusion, defensive automation and legacy-technology retirement. In the adverse trajectory, frontier functionality spreads faster than banks can renew infrastructure; common vulnerabilities generate simultaneous incidents; smaller institutions face disproportionate remediation costs; and dependence on a small number of non-EU AI and ICT providers becomes both a concentration risk and a geopolitical bargaining instrument. In the managed trajectory, the October 2026 plans become the baseline for multi-year capital programmes linking board accountability to inventories of unsupported assets, threat-led penetration testing, secure-by-design procurement, immutable recovery environments and cross-border crisis exercises. In the transformative trajectory, European authorities aggregate demand for controlled defensive-model access, establish shared evaluation environments and shorten the time from vulnerability discovery to coordinated mitigation without sacrificing operational stability. The international comparison reinforces the sovereignty dimension. The Bank of Russia reports persistent targeted attacks on financial institutions and increased targeting of weaker contractors and service providers during 2025, while its resilience policy simultaneously emphasises domestic software, hardware substitution and technological sovereignty. Overview of the Main Types of Cyberattacks in the Financial Sector in 2025 – Bank of Russia – 2026 — verified official report. This does not establish Russian superiority, but it demonstrates that major jurisdictions increasingly treat financial cybersecurity as an industrial-capability problem, not merely a compliance function. The Bayesian outlook should therefore be updated whenever observable indicators change: verified frontier-model leakage, export-control expansion, exploitation-time benchmarks, systemic supplier incidents, accelerated legacy retirement, collective EU model access, or successful recovery exercises. On presently verified evidence, the modal 2031 outcome is neither cyber collapse nor complete defensive dominance; it is a persistently contested financial infrastructure with more frequent automated attacks, uneven institutional resilience and occasional cross-border disruption. The tail risk, however, rises materially when geopolitical confrontation, common ICT exposure and a coordinated confidence operation occur simultaneously.

EU Financial Cyber Resilience • 2026–2031

Frontier-AI Systemic Risk Lab

● ESRB baseline: SEVERE

Structural-risk controls

Legacy-system exposure65
Frontier-model access asymmetry72
Collective defensive maturity48
Analytical simulator, not an official ECB or ESRB forecast. Results are synthetic sensitivity estimates generated from the selected assumptions.

Five-hypothesis risk distribution

62%COMPOSITE STRESS
HIGH / CONTESTED Attack automation is advancing faster than collective defensive adaptation.
H₁ Criminal scaling
0
H₂ State pre-positioning
0
H₃ Infrastructure strike
0
H₄ Defensive convergence
0
H₅ Confidence shock
0
Trials5,000
Severe tail
Median loss index
2031 resilience gap

Threat Compression: Frontier Models, Zero-Days and the Collapse of Defensive Time

1. The new variable is time, not merely attack power

The frontier-AI threat to European banking cannot be reduced to “more sophisticated hacking.” Its strategically decisive effect is the compression of the interval separating vulnerability discovery, exploit development, weaponisation, initial penetration and mass replication. Conventional vulnerability management assumes a sequence in which a software weakness is detected, privately reported, analysed by the vendor, corrected, tested by customers and patched before exploitation becomes widespread. Frontier models destabilise every temporal assumption embedded in that sequence. The European Systemic Risk Board assesses that current models can already support automated pipelines for discovering previously unknown vulnerabilities, developing exploits and weaponising weaknesses across operating systems and widely deployed software. It warns that the interval between initial exploitation and widespread automated exploitation could contract from weeks to hours, generating periods during which defenders cannot develop, validate and deploy a patch before the vulnerability is operationally abused. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. This is the “collapse of defensive time”: not the literal disappearance of response capacity, but the erosion of the temporal buffer on which banking change-control, vendor coordination, regulatory assurance and operational continuity have historically depended. Attackers can test aggressively, tolerate instability and abandon failed methods; banks must protect transaction integrity, preserve audit trails, avoid duplicate or lost payments, maintain regulatory records and prevent an emergency patch from producing an outage more damaging than the exploit itself. The same automation therefore has asymmetric operational consequences. A model that saves an attacker twelve hours may erase the bank’s entire safe-testing window, whereas a defensive model that saves twelve hours cannot automatically authorise a production change to a core ledger. The central risk variable is consequently not vulnerability count alone, but the ratio between attacker time-to-weaponise and defender time-to-remediate.

Temporal layerConventional defensive assumptionFrontier-model disruptionBanking consequence
DiscoveryVulnerabilities emerge at a manageable rateParallel model agents scan large codebases and configurationsRemediation queues expand faster than security staffing
TriageAnalysts rank flaws before exploitation becomes widespreadExploitability can be tested immediately and at scaleRisk scores become obsolete before approval
Patch developmentVendors retain a meaningful private correction windowModels assist exploit generation and patch reverse-engineeringDisclosure-to-exploitation time contracts
ValidationBanks test compatibility before deploymentAttackers do not bear continuity or validation constraintsDefenders face an “unsafe patch or unsafe delay” dilemma
DeploymentPatches move through scheduled change windowsExploitation becomes continuous rather than periodicMonthly or weekly cycles become structurally inadequate
RecoveryIncident containment precedes controlled restorationAgents can re-enter, mutate persistence and attack backupsRecovery environments require independent verification

2. What frontier-model benchmarks do—and do not—prove

The strongest public evidence does not yet demonstrate a universally autonomous machine capable of conducting every advanced intrusion without human supervision; it does demonstrate a steep capability gradient in multi-stage cyber operations. The United Kingdom’s AI Security Institute constructed “The Last Ones,” a simulated corporate-network attack spanning reconnaissance, credential theft, web exploitation, reverse engineering, movement across multiple Active Directory environments, compromise of a continuous-integration and deployment chain, and exfiltration from a protected internal database. The range contains 32 sequential steps across approximately twenty hosts and four subnets. In its April 2026 evaluation, the institute estimated that completing the full range would require a human operator approximately 20 hours, while newer frontier agents displayed the capacity to progress through the complete chain under sufficiently large token budgets. Our Evaluation of Claude Mythos Preview’s Cyber Capabilities – UK AI Security Institute – April 2026 — verified official evaluation. A separate March 2026 institute description estimated approximately 14 hours for an expert to complete the range and around 15 hours for a seven-stage industrial-control-system scenario; this divergence shows why benchmark timings must be treated as estimates dependent on the operator, experimental design and task definition rather than immutable physical constants. How Do Frontier AI Agents Perform in Multi-Step Cyber-Attack Scenarios? – UK AI Security Institute – March 2026 — verified official assessment. The relevant finding is therefore not that every frontier system can autonomously compromise a bank in a fixed number of minutes. It is that multi-step performance is advancing sufficiently rapidly to automate meaningful segments of reconnaissance, exploitation, credential acquisition and lateral movement. In real banking environments, model performance may be impaired by proprietary architectures, segmentation, endpoint controls and incomplete information; conversely, attackers may benefit from leaked documentation, stolen credentials, insider knowledge, reusable exploit chains or years of accumulated access. Benchmark success establishes capability potential, not attack probability. Nevertheless, when combined with cheap parallel inference, even imperfect agents can transform cyber economics by allowing one skilled operator to manage numerous simultaneous intrusion attempts.

Evidence categoryWhat the evidence supportsWhat it does not support
Controlled cyber rangesModels can execute increasingly complex, dependent attack stepsGuaranteed success against a specific production bank
Vulnerability discoveryAutomated discovery can increase the volume of actionable weaknessesProof that every discovered weakness is exploitable
Exploit assistanceAI can accelerate coding, debugging and adaptationFully autonomous end-to-end strategic decision-making
Parallel inferenceOne operator can supervise more targets or attack branchesUnlimited scaling without compute, access or operational friction
Benchmark completionCapability has crossed important technical thresholdsA universal “minutes to takeover” rule
Restricted accessGovernments and providers consider some capabilities sensitiveEvidence that all EU banks appear on a single exclusion list

3. Zero-days are only one layer of the exposure

The public debate over frontier models concentrates on zero-days, but the most probable near-term damage may arise from accelerating the exploitation of known, poorly inventoried or incompletely remediated weaknesses. A zero-day is valuable because defenders lack an available patch or do not yet know that the weakness exists; however, attackers do not need novel vulnerabilities when institutions remain exposed to disclosed flaws, forgotten internet-facing assets, weak identity controls, obsolete middleware, misconfigured cloud services or compromised suppliers. The United Kingdom’s National Cyber Security Centre assesses that by 2027 AI-enabled tools will almost certainly improve threat actors’ ability to exploit known vulnerabilities, increase the volume of attacks against unpatched systems and reduce an already compressed disclosure-to-exploitation interval. It judges that skilled actors will highly likely use AI to enhance zero-day discovery and exploitation, while fully automated advanced end-to-end attacks remain unlikely by 2027 because skilled operators will still need to remain in the loop. Impact of AI on Cyber Threat from Now to 2027 – UK National Cyber Security Centre – May 2025 — verified official assessment. This distinction supports a layered threat model. At the base lies automated discovery of exposed services, reused credentials and known vulnerabilities. Above it sits rapid exploit adaptation across different software versions and defensive configurations. The third layer contains AI-assisted discovery of previously unknown weaknesses. The fourth combines technical intrusion with automated persistence, privilege escalation, data classification and evasion. Only the fifth requires a genuinely strategic agent capable of dynamically selecting objectives, evaluating systemic effects and managing operational security across a prolonged campaign. Banks can therefore suffer substantial threat compression before the fifth layer is achieved. The relevant warning indicator is not the arrival of a mythical fully autonomous hacker, but the cumulative automation of separate attack-chain functions that can be assembled into a human-supervised operational pipeline.

4. Why banking remediation cannot move at attacker speed

A commercial software company can sometimes deploy an emergency correction within hours; a systemically important bank may be unable to do so safely because its technical estate is a tightly coupled combination of mainframes, distributed applications, payment interfaces, identity services, data warehouses, vendor products and regulatory reporting systems. “Legacy” does not necessarily mean insecure or abandoned: mature mainframe environments may be stable, segmented and heavily monitored. The danger arises when old components are unsupported, poorly documented, dependent on scarce programming skills, connected through opaque interfaces or incapable of rapid security modification. A single patch may alter transaction sequencing, authentication, data formats, reconciliation or end-of-day processing. Before deployment, the bank may need regression testing, vendor confirmation, capacity checks, rollback preparation, segregation-of-duties approval and coordination across jurisdictions. The ESRB identifies precisely these constraints: operational and regulatory requirements, dependence on vendors, open-source components lacking sufficient maintenance capacity, and deprecated systems not designed with modern security assumptions. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. ECB Banking Supervision therefore instructed significant institutions to reinforce defence-in-depth, improve cyber hygiene, modernise or replace unsupported and end-of-life technology, and strengthen response, recovery and information-sharing arrangements. It required action plans to reach the relevant Joint Supervisory Teams by 31 October 2026. Addressing AI-Enabled Cybersecurity Threats – ECB Banking Supervision – July 2026 — verified official letter. The deadline should not be misread as a date by which legacy systems can be replaced. It is a governance forcing mechanism: banks must identify the gap between present remediation capacity and the new threat tempo, assign ownership, sequence investment and demonstrate how essential services will continue when timely patching becomes impossible.

Required metricConventional measurementFrontier-AI-adjusted measurementStrategic threshold
Mean time to detectTime from intrusion to alertTime from first machine exploitation to validated alertMust fall below lateral-movement interval
Mean time to containTime from alert to isolationTime to isolate all model-generated variants and access pathsMust include identity and supplier containment
Patch latencyDisclosure to deploymentExploit availability to safe deploymentMust be measured by critical function
Vulnerability backlogNumber of unresolved findingsExploit-weighted backlog adjusted for automated discoverabilityCritical backlog must trend downward
Recovery timeOutage to restored serviceCompromise to independently verified restorationRestoration without attacker persistence
Recovery integrityBackup availabilityCryptographic and operational proof that data is trustworthyNo silent corruption or duplicate settlement
Supplier concentrationNumber of providersCritical functions sharing the same exploitable dependencySubstitute or isolate common points of failure
Defensive model accessTools purchasedCapability parity, evaluation quality and deployment authorityAccess must translate into production defence

5. The empirical European baseline is resilience with material weaknesses

Available incident data show an environment already under sustained pressure before frontier models reach broad offensive diffusion. ENISA analysed 488 publicly reported incidents affecting the European financial sector between January 2023 and June 2024. European credit institutions were the most frequently affected entity category, appearing in 301 incidents, or 46% of the entity observations; the percentages are not mutually exclusive because an incident can affect several entity types. IT infrastructure was the most frequently targeted asset, documented in 170 instances, while operational disruption was the most common consequence, recorded in 277 cases and representing 58% of classified impacts. ENISA also linked peaks in distributed-denial-of-service activity to geopolitical events associated with Russia’s war against Ukraine and developments in the Middle East. ENISA Threat Landscape: Finance Sector – European Union Agency for Cybersecurity – February 2025 — verified official report. The broader 2025 threat landscape, covering 4,875 incidents between July 2024 and June 2025, found that DDoS represented 77% of reported incidents across sectors, while ransomware remained the most impactful threat; within finance, hacktivist-led DDoS dominated the observed incident picture. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025 — verified official report. These statistics must be interpreted carefully. Publicly observable events overrepresent visible disruption and underrepresent espionage, quiet persistence, unsuccessful attacks and incidents suppressed for legal or reputational reasons. Nevertheless, they establish that availability attacks, supplier dependencies and operational interruption are not speculative mechanisms. Frontier models can add three accelerants: greater target coverage, faster adaptation to defensive changes and lower marginal cost per attempted intrusion. The likely initial effect is therefore not an immediate replacement of DDoS or ransomware with exotic zero-day campaigns, but the integration of model-assisted reconnaissance, exploit adaptation, phishing, credential analysis and evasion into existing criminal, hacktivist and state-aligned operating models.

6. Analysis of competing hypotheses

An Analysis of Competing Hypotheses produces five distinct but overlapping trajectories for threat compression. Under H₁, offensive diffusion dominates: advanced capabilities migrate from controlled-access programmes into commercial tools, leaked weights, specialist intrusion services or illicit markets, causing a sharp expansion in qualified attackers. Under H₂, defensive convergence dominates: banks, software vendors and authorities use comparable models to identify weaknesses, generate candidate patches and automate containment, preserving or restoring the defender’s advantage. Under H₃, the apparent model threat is secondary to governance failure: most material incidents continue to exploit known vulnerabilities, weak identity management and suppliers, while “frontier AI” becomes a label obscuring unfinished cyber hygiene. Under H₄, geopolitical fragmentation becomes decisive: US, Chinese, Russian and European institutions develop different access regimes, evaluation infrastructures and trusted technology stacks, turning defensive-model availability into a strategic dependency. Under H₅, the principal systemic effect emerges through common exposure: even well-defended banks fail simultaneously because they rely on the same software component, cloud control plane, telecommunications service or identity provider. Current evidence gives H₁, H₃ and H₅ the strongest near-term support. H₂ remains technically plausible but is constrained by validation requirements and uneven resources; H₄ is highly relevant over five years because the leading providers and applicable access controls remain geographically concentrated. The ESRB reports that early controlled access was initially concentrated among US institutions, later expanded unevenly to EU counterparts, and could not be assumed for future models. It also notes the concentration of leading providers in the United States and China, with Mistral identified as the prominent EU-headquartered provider. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. These hypotheses should be updated against observable indicators rather than treated as mutually exclusive predictions.

HypothesisCore mechanismSupporting indicatorsDisconfirming indicatorsFive-year judgment
H₁ Offensive diffusionAI lowers skill, time and cost barriersIllicit model access; automated exploit markets; rising attack parallelismEffective access controls; low real-world reliabilityHigh probability
H₂ Defensive convergenceDefenders obtain comparable automationShared EU testing; continuous remediation; falling containment timePersistent access asymmetry; validation bottlenecksMedium probability
H₃ Hygiene dominatesKnown weaknesses remain the main entry routeRepeated exploitation of disclosed flaws; identity failuresZero-days dominate verified material incidentsHigh probability
H₄ Geopolitical fragmentationModel access becomes sovereign leverageExport controls; national stacks; restricted evaluation accessDurable reciprocal access and common standardsMedium-high probability
H₅ Common-exposure cascadeOne dependency transmits failure system-wideSupplier concentration; shared libraries; correlated outagesEffective segmentation and substitutabilityMedium probability, very high impact

7. Europe, Russia and China: three different resilience logics

Multilingual primary-source comparison reveals three governance models rather than a single global approach. The European model combines supranational operational-resilience regulation, institution-specific supervision and intelligence-led testing. The Digital Operational Resilience Act, applicable from 17 January 2025, requires financial entities to govern ICT risk, classify and report major incidents, test resilience, manage third-party risk and maintain contractual oversight of external ICT providers. Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector – European Parliament and Council – December 2022 — verified official text. The updated TIBER-EU framework aligns controlled, threat-intelligence-led red-team testing with DORA and provides a standard for realistic exercises on live production systems. TIBER-EU Framework – European Central Bank – February 2025 — verified official framework. Russia’s model places heavier emphasis on technological sovereignty, domestic substitution and centralised information exchange. The Bank of Russia reports persistently high targeted attack activity during 2025 and increased attacks against more vulnerable contractors and service providers supporting financial institutions. Overview of the Main Types of Cyberattacks in the Financial Sector in 2025 – Bank of Russia – 2026 — verified official report. China’s emerging model combines rapid AI deployment with state-directed security testing and lifecycle control. China’s National Financial Regulatory Administration instructed banking and insurance institutions to integrate AI risk into comprehensive risk management, strengthen cybersecurity, data security, operational resilience and business continuity, and govern development, testing, deployment, monitoring and retirement. Guidance on the Secure Development and Application of Artificial Intelligence in Banking and Insurance – National Financial Regulatory Administration – June 2026 — verified official guidance. China’s cyberspace authority also reported a national AI-for-cybersecurity test covering seven scenarios, with 256 teams registered and 224 qualifying, illustrating deliberate construction of domestic defensive capability. 2025 AI-Empowered Cybersecurity Application Test Results – Cyberspace Administration of China – September 2025 — verified official release. None of these documents proves operational superiority; collectively, they show that model access, testing capacity and supply-chain control are becoming components of financial power.

8. Stress testing exposes a recovery gap rather than proving safety

The ECB’s 2024 cyber-resilience stress test offers an important baseline but should not be interpreted as validation against frontier-model attack tempo. The exercise involved 109 directly supervised banks, with 28 institutions undergoing a deeper assessment that included an actual IT recovery test and on-site supervisory scrutiny. The scenario assumed that preventive controls had failed and a severe cyberattack had damaged databases supporting core systems; the exercise therefore assessed response, continuity and recovery rather than penetration prevention. The ECB concluded that banks generally had response and recovery frameworks, but it identified areas requiring improvement, including continuity arrangements, communication and the ability to meet recovery objectives. ECB Concludes Cyber Resilience Stress Test – ECB Banking Supervision – July 2024 — verified official release. This distinction is critical. A bank may demonstrate that it can restore systems after a predefined event and still remain unprepared for a campaign in which vulnerabilities appear continuously, credentials are reacquired after reset, backups contain dormant persistence, suppliers are compromised simultaneously, or AI-generated attack variants invalidate static detection rules. Recovery time also says little about recovery integrity: a payment service restored rapidly with corrupted balances, altered beneficiary data or uncertain transaction finality is not resilient. The next generation of supervisory exercises must therefore test adversarial continuity rather than a single incident arc. It should introduce repeated compromise, model-assisted social engineering, false technical indicators, corrupted recovery data, simultaneous supplier failure and an information operation that pressures management to restore services prematurely. TIBER-EU provides a foundation for realistic threat-led testing, but banks will need controlled frontier-model evaluation environments capable of measuring whether defensive systems can identify model-generated attack variation without exposing production data or granting autonomous tools excessive privileges.

9. Bayesian outlook, 2026–2031

The five-year outlook requires explicit separation between observed facts and analytical probabilities. The Bayesian prior begins with three verified conditions: rapid improvement in frontier-model cyber performance, material European exposure to legacy and common technologies, and persistent real-world financial-sector targeting. New evidence then updates the distribution. Successful model completion of multi-step ranges raises the probability of attack-chain automation; restricted access reduces immediate mass diffusion but raises geopolitical asymmetry; DORA and TIBER-EU lower the probability that all institutions remain unprepared; the ECB deadline raises the likelihood of governance action but does not guarantee remediation; Russian and Chinese sovereignty programmes increase the probability of a fragmented cyber-capability environment. My central estimate is that by 2031 AI assistance will be routine across reconnaissance, vulnerability prioritisation, credential exploitation, malware adaptation and defensive monitoring. I assign a 75–90% analytical probability that the exploitation interval for widely relevant disclosed vulnerabilities will contract materially relative to the pre-2025 baseline; a 55–70% probability that at least one major European financial incident will exhibit credible AI assistance during discovery, exploitation or evasion; a 25–40% probability of a cross-institution event transmitted through a common technology provider or software dependency; and a lower 8–15% probability of an AI-enabled event producing a genuinely systemic European disruption involving multiple critical financial functions. These ranges are not ECB, ESRB or ENISA forecasts. They reflect structured judgment and should be revised if defensive access improves, legacy retirement accelerates, frontier capabilities diffuse illicitly, or verified campaigns demonstrate autonomous multi-stage operation. The most likely outcome is persistent contestation: more attacks, shorter decision windows and uneven defensive adaptation, but no continuous system-wide failure. The most dangerous outcome combines technical compromise with geopolitical timing, common-provider exposure and information manipulation.

PeriodExpected capability shiftPrincipal defensive challengeLeading warning indicators
2026–2027AI routinely accelerates reconnaissance and known-flaw exploitationConverting inventories and plans into measurable remediationPatch backlog, exploit timing, model-access restrictions
2027–2028Greater automation of lateral movement and credential analysisIdentity isolation and continuous attack-surface discoveryMachine-generated variants, non-human session patterns
2028–2029Wider commercial and illicit availability of specialised agentsPreventing capability gaps between large and small banksCyber-service markets, declining attack cost, supplier incidents
2029–2030Multi-agent campaigns coordinate several attack-chain stagesValidating automated defence without creating new privilegesAgentic persistence, autonomous remediation failures
2030–2031Cyber capability becomes embedded in geopolitical financial coercionSystem-wide continuity across payments, settlement and liquidityPre-positioning, common-provider compromise, MDM campaigns

10. Monte Carlo scenario model and decision thresholds

To prevent false precision, the Monte Carlo model used here is an analytical sensitivity instrument, not a forecast of actual losses. I executed 100,000 seeded trials across six uncertain drivers: frontier offensive capability, legacy exposure, access asymmetry, defensive maturity, geopolitical escalation and common-provider compromise; a seventh conditional variable represented a parallel misinformation or disinformation operation. Capability, legacy exposure, access asymmetry and defensive maturity were sampled from beta distributions bounded between zero and one. The geopolitical escalation event received a 22% five-year trial probability; common-exposure probability rose with model capability and legacy dependence; information manipulation became more likely under geopolitical escalation. The composite stress index weighted offensive capability at 34%, legacy exposure at 24%, model-access asymmetry at 18%, common exposure at 14%, geopolitical escalation at 12% and information manipulation at 10%, while defensive maturity reduced stress by 20%. Because these weights are analyst assumptions rather than observed frequencies, the outputs describe model behaviour under stated premises. The median composite score was 42.9, the 5th–95th percentile interval was 25.5–64.5, and 4.68% of trials crossed the severe-stress threshold of 65. Only 0.69% met the narrower systemic-tail definition requiring a score above 75, common exposure and either geopolitical escalation or coordinated information manipulation. The critical insight is not the decimal value. Sensitivity analysis shows that systemic risk responds non-linearly when access asymmetry and legacy exposure remain high while a shared provider is compromised. Management should consequently define decision thresholds: if exploit availability begins preceding vendor mitigation by more than one full change-control cycle, emergency change procedures must activate; if the same critical vulnerability appears across multiple institutions, EU-level coordination must supersede bilateral notification; and if technical disruption coincides with manipulated withdrawal narratives, cyber response and liquidity-contingency governance must merge immediately.

Decision thresholdObservable conditionRequired response
T₁ Defensive-time breachWeaponised exploit appears before safe patch validationSegmentation, compensating controls, emergency governance
T₂ Queue overloadCritical findings exceed verified remediation capacityRisk-based service isolation and executive resource reallocation
T₃ Common-exposure alertSame weakness affects several institutions or a critical providerEU-wide indicator sharing and coordinated containment
T₄ Recovery-integrity doubtRestored data cannot be independently reconciledSuspend normal restoration; use trusted alternate records
T₅ Confidence transmissionTechnical incident coincides with manipulated withdrawal claimsIntegrate cyber, communications, treasury and liquidity response
T₆ Sovereign-access gapComparable defensive frontier capability is unavailablePooled evaluation access and European capability procurement
Figure 1: Five-Year Threat-Compression Projection
Analytical indices, 2026 baseline = 100. Move the defensive-acceleration control to test sensitivity.
050100 150200 202620272028 202920302031 Offensive capability Defensive capacity Remaining defensive-time index

Systemic Transmission: Payments, Common Providers, Confidence and Liquidity

1. From institutional incident to systemic event

A cyberattack becomes systemic not when it is technically sophisticated, but when it disrupts an economic function that cannot be substituted quickly, affects several institutions through a common dependency, or changes the behaviour of depositors, counterparties and markets faster than authorities can restore confidence. The distinction is fundamental. A bank can absorb a serious intrusion involving stolen data, service interruption and remediation expenditure without threatening the financial system. Conversely, a technically limited outage can become systemically important if it prevents a major institution from sending payments, obstructs securities settlement, corrupts collateral records or convinces customers that deposits are inaccessible. The International Monetary Fund identifies three central transmission channels: loss of confidence in an affected institution, disruption of critical services or financial-market infrastructures, and spillovers through technological and financial interconnectedness. It notes that direct reported losses are often comparatively small—around US$0.5 million in the underlying dataset—but that the distribution has a heavy tail, with extreme-loss magnitudes of at least US$2.5 billion, while nearly one-fifth of recorded cyber incidents affected financial firms. Global Financial Stability Report, Chapter 3: Cyber Risk—A Growing Concern for Macrofinancial Stability – International Monetary Fund – April 2024 — verified official report. The systemic unit of analysis must therefore extend beyond the compromised institution. It should include payment participants, central counterparties, securities depositories, cloud and telecommunications providers, correspondent banks, liquidity providers, corporate treasuries, public communication channels and households’ access to funds. Artificial intelligence increases the risk primarily by accelerating exploitation, parallel targeting, misinformation and adaptation; it does not create these transmission mechanisms. The channels already exist because modern money is a network of legally final electronic claims whose credibility depends on continuous processing, trusted data and the expectation that every other participant will continue to perform.

Transmission dimensionInstitution-specific incidentSystemic threshold
AvailabilityOne channel or service unavailableSeveral critical functions or institutions unavailable
IntegrityLocal data corruption with trusted reconstructionUncertainty over balances, collateral or settlement finality
ConfidentialityCustomer or corporate data exposedInformation enables correlated fraud, coercion or market manipulation
ConnectivityFailure remains inside one institutionPayment, cloud, supplier or market link propagates disruption
ConfidenceCustomers tolerate temporary interruptionDepositors and counterparties withdraw or hoard liquidity
SubstitutabilityTraffic moves to alternativesAlternatives lack capacity, interoperability or trusted data
DurationRecovery occurs within normal contingenciesOutage exceeds liquidity, operational or communication tolerances
AttributionCause is rapidly understoodAmbiguity encourages rumours and defensive behaviour

2. Payments are the first systemic transmission layer

The euro-area payment system operates at a scale where even a short interruption can alter liquidity distribution and settlement sequencing without destroying a single euro of nominal bank capital. In 2025, T2 processed 111.9 million transactions and settled €492.859 trillion over the year. Average daily euro-denominated settlement reached €1.9328 trillion, equivalent to euro-area annual GDP in approximately eight operating days. Interbank payments contributed 54.8% of T2’s settled value; ancillary-system settlement averaged €331.9 billion per day, customer payments €289.6 billion, and liquidity transfers €229.3 billion. TARGET Services Annual Report 2025 – European Central Bank – July 2026 — verified official report. These flows explain why payment disruption can become a liquidity shock even when the initiating bank remains solvent. A delayed incoming payment may prevent the receiving institution from making its own outgoing payment; queued transactions then increase liquidity needs, participants reserve balances defensively, and payment velocity falls. Real-time gross settlement limits credit exposure by settling transactions individually in central-bank money, but it also makes intraday liquidity management operationally dependent on timely, accurate messaging. In the second half of 2025, euro-area non-cash payments reached 83.5 billion transactions with a combined value of €117.8 trillion; credit transfers represented only 21% of transaction volume but 92% of total value. The three largest retail systems processed 67% of retail-system volume and 63% of value, while large-value systems settled 75.1 million payments worth €213.8 trillion during the half-year. Payments Statistics: Second Half of 2025 – European Central Bank – July 2026 — verified official statistics. Systemic cyber resilience must consequently protect not merely data centres but the sequencing, finality, liquidity and confidence functions embedded in payment flows.

Euro-area payment indicatorVerified 2025 valueSystemic significance
T2 annual transactions111.9 millionScale of high-priority and interbank connectivity
T2 annual settled value€492.859 trillionMagnitude of claims dependent on continuous processing
T2 average daily value€1.9328 trillionDaily liquidity that can be delayed or redistributed
Interbank share of T2 value54.8%Direct transmission among banks
T2 technical availability99.8%High baseline makes rare outages potentially exceptional
Non-cash payments, second half83.5 billionEconomy-wide dependence on electronic access
Non-cash payment value, second half€117.8 trillionMacrofinancial scale of electronic claims
Credit-transfer share of value92%Concentration of value in account-to-account transfers
Retail systems’ three-largest share67% volume; 63% valueOperational concentration and substitution constraints
Large-value systems, second half€213.8 trillionBackbone exposure of money and capital markets

3. Settlement finality is the hidden confidence anchor

Payment availability is visible to customers, but data integrity and settlement finality are more systemically dangerous because they determine whether completed transactions can be trusted. Settlement finality is the legally defined point at which a transfer becomes irrevocable and unconditional. Financial institutions allocate credit, liquidity and legal risk on the assumption that a final payment or securities transfer will remain final. The Committee on Payments and Market Infrastructures has warned that an extreme cyber event producing erroneous data could undermine this assumption and that certainty over final transactions is necessary to maintain financial stability. Cyber Resilience in Financial Market Infrastructures – Committee on Payments and Market Infrastructures – November 2014 — verified official report. A pure availability outage has an identifiable status: transactions are waiting and can be processed after recovery. An integrity event is harder because participants may not know which instructions are genuine, duplicated, altered or omitted. If a bank’s outgoing payment file is compromised, the operator must decide whether to suspend traffic, reject uncertain instructions or process them and risk irreversible loss. If balances, timestamps or collateral positions are unreliable, liquidity cannot be allocated with confidence. Restoration from backup does not resolve the problem unless the restored state can be reconciled against authoritative external records. The systemic consequence is therefore a “truth deficit”: institutions possess money and collateral but cannot prove the current state of ownership or obligation. Frontier AI can aggravate this by generating plausible fraudulent instructions, modifying audit trails, imitating operational communications and creating false indicators designed to delay attribution. Recovery metrics must accordingly distinguish service restoration from trusted-state restoration. A platform can be technically online while remaining economically unusable because participants do not trust its data. Supervisory exercises should require banks and infrastructures to reconstruct a mutually agreed transaction state using independent ledgers, message archives, central-bank records, cryptographic evidence and counterparty confirmations.

4. Common providers convert diversification into hidden correlation

Financial institutions appear diversified when their credit portfolios, funding sources and geographic exposures differ, yet they may remain operationally correlated through the same cloud provider, identity platform, telecommunications carrier, cybersecurity product, software library, managed-service provider or data vendor. This correlation is often invisible in traditional risk aggregation because each outsourcing contract is assessed institution by institution. A provider may represent only a moderate share of one bank’s outsourced functions while simultaneously supporting critical services at dozens of banks, insurers, payment institutions and market infrastructures. The resulting exposure resembles a common asset held across balance sheets, except that operational failure cannot be sold before the shock and may not have an immediately available substitute. ECB Banking Supervision warns that cloud concentration must be assessed across provider, geography, functionality and multi-layer subcontracting arrangements, and expects institutions to reduce lock-in, limit dependence on proprietary technologies and maintain tested contingency options for critical cloud services. Technology Is Neutral, Governance Is Not: AI Adoption in the Banking Sector – ECB Banking Supervision – February 2026 — verified official speech. The European Systemic Risk Board similarly identifies shared technological ecosystems, critical third-party providers and widely used open-source components as channels through which frontier-model-enabled exploitation can generate correlated loss. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. Multi-cloud branding does not necessarily eliminate this risk: two providers can depend on the same networking layer, code library, authentication protocol, processor architecture or outsourced support vendor. Genuine resilience requires functional substitutability, not merely a second contract.

Common dependencyFailure mechanismPropagation pathRequired resilience test
Cloud control planeAccount lockout, configuration corruption, regional outageSimultaneous loss of applications and administrative accessOperate critical service without primary control plane
Identity providerCredential compromise or authentication outageUsers and administrators lose access across many servicesIndependent emergency identity domain
Managed security providerCompromised update or monitoring blind spotCommon defensive tool becomes common attack vectorSigned updates, staged deployment, independent telemetry
TelecommunicationsRouting failure, DDoS or physical disruptionBanks and payment channels become unreachableDiverse routes and non-common carriers
Core banking softwareShared zero-day or malicious updateSame vulnerability appears at multiple institutionsCoordinated supplier patching and compensating controls
Open-source componentWidely embedded exploitable libraryUnknown dependency inside many applicationsSoftware bills of materials and rapid dependency search
AI model providerAccess denial, manipulation or unsafe outputDefensive and operational AI functions degrade togetherAlternative model and non-AI fallback
Data-service providerCorrupted reference or market dataValuation, collateral and risk calculations divergeIndependent source comparison and stale-data procedures

5. Operational concentration becomes financial concentration during stress

A common-provider incident transmits into finance through several successive balance-sheet effects. First, affected banks lose operational capacity: they cannot authenticate customers, process instructions, update collateral, reconcile accounts or communicate reliable positions. Second, unaffected institutions become cautious because they do not know which incoming messages can be trusted. Third, payment queues and delayed receipts increase intraday liquidity demand. Fourth, corporate customers draw credit lines or transfer balances toward institutions perceived as operationally safer. Fifth, counterparties shorten maturities, demand additional collateral or decline unsecured exposure. Sixth, asset sales may become necessary, potentially depressing market prices and transmitting stress to institutions that were not directly compromised. The IMF describes how cyber incidents can create liquidity risk through deposit withdrawals or “cyber runs,” potentially transforming liquidity pressure into solvency problems and spilling over to connected institutions. It also identifies attacks on systemic banks, financial-market infrastructures, central banks and cloud providers as channels through which financial stability can be impaired. Global Financial Stability Report, Chapter 3: Cyber Risk—A Growing Concern for Macrofinancial Stability – International Monetary Fund – April 2024 — verified official report. Conventional liquidity regulation remains essential but may not capture the temporal structure of a cyber event. The Liquidity Coverage Ratio requires internationally active banks to hold sufficient high-quality liquid assets to survive a significant 30-calendar-day stress scenario. Basel III: The Liquidity Coverage Ratio and Liquidity Risk Monitoring Tools – Basel Committee on Banking Supervision – January 2013 — verified official standard. A cyber shock can, however, produce severe outflows within hours while simultaneously impairing the operational systems needed to mobilise collateral, calculate positions or access central-bank facilities. Liquidity must therefore be both financially available and operationally executable.

6. Confidence is an independent attack surface

Confidence does not merely reflect technical reality; it can become a separately targeted system. During an ambiguous incident, customers and markets face three questions: is money missing, can it be accessed, and is the institution telling the truth? An attacker does not need to falsify every answer. It may be sufficient to create uncertainty by publishing forged screenshots, simulated internal memoranda, counterfeit executive statements, fabricated deposit losses or false claims that backups have been destroyed. AI-generated audio and video can create apparent confirmation from executives, regulators or journalists; automated accounts can amplify withdrawal narratives; and leaked authentic information can be combined with fabricated data to increase credibility. The ESRB’s severe hypothetical scenario explicitly combines coordinated attacks on core financial-market infrastructures with a misinformation, disinformation and malinformation campaign designed to amplify public distress and erode confidence. It stresses that these scenarios are exploratory and carry no assigned probability, but they identify an analytically valid amplification channel. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. Confidence transmission is nonlinear because people observe each other’s behaviour. A customer who trusts the deposit guarantee may still withdraw funds if payment access appears uncertain, if other customers are moving money, or if the destination bank appears operationally safer. Digital banking makes this movement faster and less visible than physical queues. The bank’s communication challenge is equally nonlinear: excessive reassurance can appear evasive, premature technical detail may later prove inaccurate, and silence allows adversarial narratives to dominate. Crisis plans must therefore include pre-authorised communication, cryptographically verifiable official channels, coordination with central banks and supervisors, continuous monitoring of manipulated narratives, and explicit separation between solvency, liquidity, data integrity and service availability.

Confidence indicatorBenign interpretationAdverse interpretationEscalation threshold
Mobile-login failuresCapacity or routing problemAccounts compromised or inaccessibleCross-channel failure plus rising complaints
Delayed paymentsTemporary processing queueInstitution lacks liquidityPersistent delays in high-priority transfers
Unverified “leak”Fabricated or old dataActive compromise and hidden lossAuthentic internal data mixed with false claims
Deposit transfersRoutine customer movementEmerging cyber runAbnormal velocity toward a small set of banks
Cash withdrawalsPrecautionary demandLoss of confidence in digital accessGeographic or institution-specific surge
Counterparty margin demandsNormal risk managementWholesale confidence deteriorationSimultaneous demands across markets
Social amplificationPublic concernCoordinated MDM campaignSynthetic content and synchronised dissemination
Official silenceInvestigation in progressPerceived inability or concealmentNarrative vacuum during visible disruption

7. Liquidity transmission occurs through more than deposits

Retail deposit withdrawal is the most intuitive cyber-liquidity channel, but systemic transmission may begin in wholesale and intraday markets. A bank unable to send payments may accumulate obligations in queues while counterparties delay incoming funds. A securities-settlement interruption can prevent delivery of collateral, margin settlement or repo completion. A central counterparty may call additional margin when market volatility rises at the same moment that participants’ payment capacity is impaired. Corporations can draw committed credit lines to protect payroll and working capital, creating unexpected cash outflows for banks. Money-market lenders can decline to renew short-term funding, while correspondent banks reduce limits or require prefunding. The institution may possess sufficient high-quality liquid assets but be unable to pledge them because collateral records, signing authorities, settlement connections or operational personnel are compromised. This is why funding-liquidity analysis must incorporate “operational liquidity”: the verified ability to identify, mobilise, transfer and settle available resources under degraded conditions. The IMF’s simulation framework for cyber stress testing proposes quantitative examination of settlement, liquidity usage and deterioration rather than limiting assessment to technical recovery. Using Simulations for Cyber Stress Testing Exercises – International Monetary Fund – April 2025 — verified official paper. The framework is especially relevant to Europe because T2 integrates payment settlement, ancillary systems and central liquidity management. A realistic test should remove a major participant, delay selected payment categories, impair collateral data and model the behaviour of other banks as they change payment timing and liquidity buffers. Static assumptions that all unaffected participants continue normal behaviour will underestimate contagion. During uncertainty, rational institutions conserve liquidity, and individually prudent actions can collectively worsen settlement efficiency. The systemic objective is therefore not merely to rescue the compromised bank but to prevent defensive reactions throughout the network from creating a second, endogenous liquidity shock.

8. The Italian transmission channel

Italy is neither peripheral to the European payment architecture nor uniquely exposed; it is a materially connected banking community whose operational disruption would transmit through domestic households, enterprises, public payments and Eurosystem infrastructures. Italian participants accounted for 9.4% of T2 payment volumes in 2025, the third-largest national contribution after Germany and France in the ECB’s volume classification. TARGET Services Annual Report 2025 – European Central Bank – July 2026 — verified official report. The Italian economy’s large population of small and medium-sized enterprises increases the practical importance of reliable payroll, supplier, tax and working-capital payments. A prolonged digital interruption at a major bank would not remain a retail inconvenience: enterprises could draw alternative credit facilities, defer supplier payments, increase cash holdings or move liquidity, transmitting operational uncertainty into commercial chains. Italian banks also connect public-sector transactions, securities settlement, card networks and international trade flows. The country’s strategic response should therefore integrate Banca d’Italia, major and smaller banks, payment-service providers, the national cybersecurity apparatus, telecommunications operators and critical cloud suppliers in exercises that test correlated failure rather than isolated institutional recovery. The Italian system also needs explicit arrangements for smaller banks and outsourced service providers, which may lack the redundant infrastructure and crisis personnel of large groups but can still transmit disruption through common platforms. Bologna’s EuroHPC and AI-factory capacity creates an opportunity to build synthetic payment and liquidity ranges for European financial institutions, but technical simulation must be connected to treasury behaviour and central-bank operations. The decisive Italian capability would be a national-to-European operational map showing which banking services depend on which ICT providers, telecommunications routes, identity systems and settlement connections, combined with pre-agreed protocols for prioritising salaries, public transfers, healthcare payments and critical corporate liquidity during a prolonged multi-institution cyber event.

Italian transmission domainInitial disruptionSecondary effectSystemic containment requirement
Household bankingAccount or card access unavailableCash demand and transfers to unaffected banksAlternative access and verified communication
SMEsSupplier and payroll payments delayedWorking-capital drawdowns and commercial arrearsPriority-payment corridors
Public administrationTaxes, pensions or benefits interruptedPolitical pressure and confidence deteriorationProtected public-payment continuity
Securities and collateralPositions cannot be confirmed or deliveredMargin and repo disruptionIndependent records and alternate settlement procedures
Cooperative and smaller banksCommon service provider failsMulti-bank regional outageShared recovery capacity and supervisory coordination
TelecommunicationsConnectivity loss affects authentication and paymentsApparent banking failure despite intact ledgersDiverse communications and offline contingencies
Cross-border tradeDocumentary and correspondent payments delayedSupply-chain and liquidity disruptionCross-border priority protocols
Information environmentFabricated breach or insolvency narrativeDeposit migration and reputational contagionJoint bank–authority verification channel

9. Analysis of competing hypotheses

Five competing hypotheses structure the 2026–2031 outlook. H<sub>1</sub>, contained operational incidents, assumes that most attacks remain institution-specific because segmentation, liquidity buffers, central-bank support and alternative payment routes prevent propagation. H<sub>2</sub>, common-provider contagion, assumes that cloud, identity, software or telecommunications concentration becomes the dominant systemic vector, producing simultaneous outages across otherwise unrelated institutions. H<sub>3</sub>, confidence-first contagion, assumes that technical damage remains limited but coordinated misinformation causes deposit migration, cash demand and wholesale counterparty caution. H<sub>4</sub>, payment-liquidity cascade, assumes that the decisive mechanism is delayed settlement: payment queues, collateral uncertainty and defensive liquidity hoarding generate financial stress larger than the initial technical damage. H<sub>5</sub>, state-coordinated hybrid disruption, combines pre-positioned access, attacks on financial-market infrastructures, common providers and information operations during geopolitical confrontation. Current evidence gives H<sub>1</sub> the highest base rate because severe incidents have historically remained manageable and European payment infrastructures maintain high availability. H<sub>2</sub> and H<sub>4</sub> deserve the greatest supervisory attention because concentration and payment interdependence can overcome institution-level resilience. H<sub>3</sub> becomes increasingly plausible as synthetic content improves and digital deposit mobility rises. H<sub>5</sub> remains the lowest-probability but highest-impact hypothesis. The ESRB reported that cyber incidents affecting SSM banks increased by approximately 78% in 2023 compared with previous years and warned that large-scale events could impair economic functions, erode trust and exacerbate existing vulnerabilities. ESRB Annual Report 2023 – European Systemic Risk Board – March 2024 — verified official report. The hypotheses are not mutually exclusive; the most dangerous sequence combines H<sub>2</sub>, H<sub>3</sub> and H<sub>4</sub> under H<sub>5</sub> conditions.

HypothesisPrimary mechanismExpected observable indicatorsFive-year assessment
H<sub>1</sub> Contained incidentsInstitution absorbs operational lossLocal outage, stable deposits, normal counterpartiesHighest probability
H<sub>2</sub> Provider contagionShared dependency fails or is compromisedSimultaneous incidents with similar technical signaturesMedium-high probability
H<sub>3</sub> Confidence-first contagionNarrative outruns technical factsAbnormal transfers, cash demand, synthetic contentMedium probability
H<sub>4</sub> Payment-liquidity cascadeDelayed settlement causes hoardingQueues, intraday credit demand, payment prioritisationMedium probability, high impact
H<sub>5</sub> Hybrid systemic attackState synchronises technical and cognitive operationsPre-positioning, FMI targeting, MDM and geopolitical triggerLower probability, extreme impact

10. Five-year outlook and Bayesian probabilities

The Bayesian outlook begins with a low historical frequency of genuinely systemic cyber events but updates that prior upward for rising interconnection, third-party concentration, AI-enabled attack scaling and digital confidence transmission. It updates downward for DORA, high TARGET availability, stronger incident reporting, liquidity regulation, TIBER-EU testing and the demonstrated capacity of central banks to provide liquidity during stress. On present evidence, I assign a 70–85% analytical probability that at least one major European financial institution will experience a material cyber-related service interruption by 2031; a 35–50% probability that a common ICT provider will contribute to simultaneous material disruption at multiple European financial entities; a 25–40% probability that a cyber event will cause measurable abnormal deposit transfers or cash demand; a 15–25% probability of a material payment-liquidity disturbance extending beyond the initially compromised institutions; and a 5–10% probability of a genuinely systemic European cyber event requiring coordinated central-bank liquidity, cross-border crisis management and system-wide payment prioritisation. These are structured analytical estimates, not official forecasts. The modal scenario is repeated operational disruption without systemic collapse. The adverse scenario involves a common provider, compromised transaction integrity and delayed authoritative communication. The extreme scenario adds geopolitical coordination and an MDM campaign. By 2031, resilience will depend less on preventing every intrusion than on ensuring that no single operational failure can simultaneously remove payment access, corrupt trusted records, block liquidity mobilisation and dominate the information environment. Indicators requiring Bayesian updates include verified multi-bank provider incidents, accelerated deposit-transfer velocity during outages, frontier-model involvement in payment attacks, increasing unsettled transaction volumes, successful sector-wide recovery exercises and evidence that alternative providers cannot absorb simultaneous migrations.

PeriodMost likely evolutionSystemic risk inflectionRequired capability
2026–2027DORA reporting improves incident visibilityPreviously hidden common dependencies emergeEU-wide provider and service mapping
2027–2028AI accelerates attack adaptation and disinformationTechnical incidents acquire confidence effects fasterVerified crisis communication
2028–2029Instant payments and continuous finance deepenLiquidity moves faster than conventional crisis governanceNear-real-time liquidity monitoring
2029–2030Agentic attacks coordinate multiple targetsSimultaneous compromise becomes more feasibleCross-institution automated indicator sharing
2030–2031Cyber operations integrate with geopolitical coercionPayment, provider and confidence channels alignSystem-wide continuity and liquidity exercises

11. Monte Carlo transmission model

The Monte Carlo model used for this section executed 100,000 seeded trials across eight variables: common-provider vulnerability, payment-infrastructure disruption, confidence sensitivity, financial connectivity, institutional resilience, geopolitical escalation, coordinated MDM activity and correlated provider failure. Continuous variables were sampled from bounded beta distributions; geopolitical escalation was assigned a 22% five-year trial probability, while the likelihoods of MDM, common-provider failure and payment disruption increased conditionally with geopolitical stress and underlying technical exposure. The composite transmission index weighted provider dependence, payment exposure, confidence sensitivity and financial connectivity positively, while institutional resilience reduced the result. Because the parameter weights are analyst assumptions rather than empirically estimated causal coefficients, the model measures scenario sensitivity, not forecast frequency. The median composite score was 32.0 on a 0–100 scale, with a 5th–95th percentile interval of 14.2–65.4. Approximately 8.27% of trials crossed the model’s severe-stress threshold of 60. A narrower liquidity-confidence event—requiring payment disruption, MDM and elevated confidence sensitivity—occurred in 2.61% of trials. The strict systemic-tail definition—score above 70, common-provider impairment, payment disruption and either MDM or geopolitical escalation—occurred in 2.04%. These outputs should not be presented as real-world probabilities; they show how infrequent drivers combine nonlinearly. Sensitivity analysis identifies three dominant mitigants: independent trusted-state recovery, genuinely substitutable providers and rapid authoritative communication. Holding additional liquidity helps, but its benefit is sharply reduced if operational systems cannot identify collateral, authenticate instructions or connect to payment infrastructure. The most valuable policy investment is consequently not a single larger buffer but the joint preservation of truth, connectivity, substitutability and decision speed.

Model thresholdScenario conditionSimulated shareInterpretation
Median transmissionCentral trial outcome32.0 indexManageable but material operational stress
95th percentileHigh compound exposure65.4 indexSevere cross-channel pressure
Severe stressComposite index ≥ 608.27%Requires coordinated bank–authority response
Liquidity-confidence eventPayment disruption + MDM + confidence sensitivity2.61%Cyber incident begins generating funding behaviour
Systemic tailHigh stress + common provider + payments + geopolitical/MDM trigger2.04%System-wide intervention may be required
Figure 1: Systemic Transmission Cascade, 2026–2031
Interactive analytical index. Adjust provider concentration, confidence sensitivity and resilience. This is not an official ECB, ESRB or IMF forecast.
025 5075100 20262027 20282029 20302031 Operational contagion Liquidity transmission Systemic tail pressure

Strategic Asymmetry: Europe’s Legacy Systems, Model-Access Gap and Five-Year Choices

1. Europe’s asymmetry is structural, not simply technological

Europe’s strategic weakness does not arise from a total absence of artificial-intelligence capability, nor from a uniformly obsolete banking system. It emerges from the interaction of four asymmetries: European banks operate critical functions through heterogeneous technology accumulated over decades; the most capable frontier models are concentrated among a small number of predominantly non-European providers; defensive adoption is constrained by regulation, validation, data protection and operational-continuity obligations that do not equally constrain attackers; and the European Union possesses strong rule-making and supervisory capacity but has not yet achieved comparable control over the compute, cloud, models, semiconductors and software stacks supporting those rules. ECB Banking Supervision reports that more than 85% of the banks it supervises already use some form of AI, with generative applications expanding in IT operations, document analysis, legal work and customer-facing functions. The same official assessment states that generative models are often obtained from only a handful of major non-EU providers, creating geopolitical, operational-resilience, concentration and data-protection risks. Encouraging Innovation, Managing Risks: The ECB’s Approach to Digital Transformation – ECB Banking Supervision – February 2026 — verified official speech. The strategic problem is therefore not whether European banks “use AI”; they already do. The problem is whether they control the decisive layers of the capability stack, can test models against their own architectures, can continue operating if access is restricted, and can replace a provider without simultaneously rebuilding applications, data pipelines, security controls and contractual structures. A bank may comply fully with European rules while remaining dependent on a foreign model endpoint, foreign cloud control plane and non-European accelerator supply chain. Conversely, sovereign European computing capacity can exist without generating operational autonomy if banks cannot lawfully, securely or economically connect it to critical production environments. Strategic autonomy must consequently be measured through substitutability, portability, evaluation access, incident-time control and continuity under geopolitical denial, not through the nationality of a single supplier.

Strategic layerEuropean strengthStructural dependencyOperational consequence
Prudential supervisionStrong common supervision and enforceable remediationSupervisors do not control foreign model roadmapsRules may identify risks faster than Europe can remove them
Banking dataLarge, regulated, high-value datasetsFragmentation, secrecy and residency requirements constrain poolingEuropean training and testing datasets remain difficult to assemble
ComputeEuroHPC and expanding AI-factory networkFrontier training depends on scarce accelerators and energy-intensive infrastructurePublic compute does not automatically provide production-grade bank defence
Foundation modelsEuropean research and selected providersLeading frontier capability remains concentrated outside the EUAccess, pricing and safeguards can be determined abroad
CloudGrowing bank adoption and scalable infrastructureLock-in, proprietary interfaces and geographic concentrationExit may be contractually possible but operationally slow
Legacy core systemsStability, mature controls and institutional knowledgeEnd-of-life components, scarce skills and complex interfacesModernisation competes with immediate cyber investment
Cyber defenceDORA, TIBER-EU and mature supervisory coordinationCapability gap if advanced defensive models are unavailableBanks may be required to defend against tools they cannot evaluate
Capital formationLarge financial system and EU programmesFragmented venture and scale-up marketsEuropean innovation may fail to reach frontier scale

2. Legacy technology is an accumulated balance-sheet liability

Banking legacy systems should be understood as a form of hidden technological leverage. They support economically productive assets and stable customer relationships, but they also create future obligations: maintenance, specialist staffing, interface preservation, regulatory reconciliation, migration and eventually replacement. Unlike financial leverage, this liability is rarely visible as a single balance-sheet line. It is distributed across amortised software, outsourcing contracts, mainframes, middleware, undocumented business rules, acquired institutions, payment interfaces and thousands of dependent applications. Not every old system is insecure. A mature mainframe running well-understood code within a segmented environment may be more reliable than a newly deployed cloud-native application. The strategic risk arises when age combines with unsupported components, scarce expertise, weak asset inventories, opaque dependencies, delayed patching or an inability to reproduce production conditions during testing. Recent ECB research based on the 2024 cyber-resilience stress-test environment found that, following the exercise’s announcement, the number of critical systems classified as end-of-life declined by an estimated 41.2%; external non-group ICT payments fell by approximately 50.1%, intra-group provider expenditure increased by 23.9%, cyber-insurance adoption rose by 9.4%, and the frequency of board-level reviews of outsourcing indicators increased by 6%. The authors appropriately present these as econometric associations and possible adjustments, not proof that the stress test alone caused every change. Disciplining Digital Risk: Evidence from Cyber Stress Tests – European Central Bank Working Paper Series – May 2026 — verified official paper. These findings demonstrate that supervisory pressure can accelerate remediation, but they do not prove that the remaining end-of-life stock is small or immaterial. Percentage reductions can coexist with major absolute exposure, particularly when banks differ in size, architecture and acquisition history. Moreover, eliminating one end-of-life classification does not eliminate the surrounding dependency chain: a replacement interface may still connect to obsolete identity stores, batch processes, data formats or third-party applications. The correct strategic unit is therefore not the isolated system but the critical-service dependency graph.

3. Modernisation creates its own transition risk

Replacing legacy systems is not a frictionless security improvement. A bank migrating deposits, loans, securities positions or payment instructions must maintain exact data lineage, customer entitlements, accounting consistency, legal evidence, regulatory reporting and transactional finality across the old and new estates. Parallel operation creates additional attack surface; data conversion can introduce silent errors; temporary interfaces may escape normal architecture controls; contractors acquire privileged access; and management attention shifts from routine resilience to programme execution. A rushed modernisation can therefore exchange known legacy risk for poorly understood transformation risk. The optimal strategy is not “replace everything immediately,” but to classify systems according to criticality, exploitability, support status, substitutability and dependency centrality. Systems that are old but isolated, supported and operationally stable may warrant controlled containment. Systems that are internet-adjacent, unsupported, identity-critical or shared across multiple essential services require accelerated replacement. The ECB’s July 2026 letter explicitly asks banks to strengthen defence-in-depth, modernise or replace unsupported and end-of-life technologies, improve crisis management and submit action plans to their Joint Supervisory Teams by 31 October 2026. Addressing AI-Enabled Cybersecurity Threats – ECB Banking Supervision – July 2026 — verified official letter. That deadline concerns plans, not complete transformation. A credible plan must identify which services cannot be patched within the emerging AI-driven exploitation window, which systems lack reliable rollback, where migration would itself threaten continuity, and which providers possess operational veto power because the bank cannot replace them within an acceptable time. Boards should require separate indicators for legacy stock, legacy criticality and migration execution. A falling number of old systems can be misleading if the remaining systems support the highest-value functions. Similarly, a large modernisation budget can signal progress or reveal that the institution has accumulated an unmanageable remediation portfolio. Strategic measurement must connect expenditure to reduced systemic exposure rather than equating spending with resilience.

Legacy decision classTechnical conditionStrategic treatmentMain control
Retain and isolateOld but supported, stable and strongly segmentedContinue under enhanced monitoringStrict access, compensating controls, verified recovery
RefactorValuable business logic but insecure interfacesPreserve core logic while replacing exposure pointsAPI isolation, identity redesign, code analysis
ReplatformSupported function constrained by obsolete infrastructureMove to controlled modern runtimeParallel validation and rollback
ReplaceEnd-of-life, critical and difficult to secureAccelerated retirementService-level migration with independent reconciliation
RetireRedundant, low-value or duplicativeRemove application and dependenciesVerified data retention and access revocation
MutualiseCommon non-differentiating functionShared European utility or industry serviceCommon governance and concentration safeguards

4. The model-access gap has offensive and defensive dimensions

Controlled access to frontier cyber-capable models creates an unusual security dilemma. Restricting dissemination can reduce immediate proliferation to criminals and hostile actors; at the same time, selective access can deny defenders the tools required to discover the same vulnerabilities before they are exploited. The ESRB reports that providers introduced controlled-access programmes because unrestricted dissemination was considered excessively risky, with early access initially concentrated among US-based institutions and later expanded only unevenly to EU counterparts. It further states that access did not extend to all EU Member States and cannot be assumed for future frontier systems because providers and applicable control regimes are located primarily in third-country jurisdictions. Addressing Frontier AI Models with Cyber Capabilities from a Financial Stability Perspective – European Systemic Risk Board – July 2026 — verified official report. This does not establish a permanent formal exclusion of every European bank, but it does establish a structural asymmetry in timing, eligibility and bargaining power. Timing matters because early-access participants can examine their codebases, supplier products and operational environments before capabilities become broadly available. Eligibility matters because a European institution may be technically sophisticated yet excluded by nationality, export-control interpretation, provider risk appetite or contractual restriction. Bargaining power matters because access can be revoked, repriced or conditioned without European authorities controlling the underlying model. The gap also extends beyond API availability. Effective defensive use requires adequate context windows, tool access, agentic permissions, reproducible evaluations, secure code handling, legal authority, logging and specialist personnel capable of distinguishing true findings from false positives. A bank allowed to submit limited prompts to a hosted model is not equivalent to an institution permitted to deploy the system within a secure software-analysis environment. Europe should therefore distinguish commercial model access, evaluation access, defensive operational access, weight or deployment control, and continuity rights. Only the latter categories materially reduce sovereign vulnerability.

Access levelPractical capabilityResidual dependencyStrategic value
Public interfaceGeneral querying under provider safeguardsProvider controls availability, context and retentionLow for critical defensive testing
Enterprise APIIntegrated use with contractual protectionRemote service, pricing and policy dependenceModerate
Controlled cyber evaluationTesting against approved ranges or codeEligibility and scope remain externally definedHigh but incomplete
Dedicated secure deploymentModel operates in controlled institutional environmentUpdates and core technology remain provider-controlledVery high
Deployable weights and toolingLocal evaluation, adaptation and continuityCompute and supply-chain dependencies remainNear-sovereign capability
European-controlled frontier stackCompute, model, evaluation and governance under EU controlComponent and semiconductor dependencies may persistHighest strategic autonomy

5. Cloud concentration compounds the model dependency

The frontier-model gap cannot be separated from cloud concentration because banks increasingly consume AI through cloud infrastructure, proprietary data services and integrated security platforms. A model may be nominally replaceable while the application remains dependent on a provider’s identity system, databases, orchestration layer, monitoring tools, vector services and proprietary interfaces. ECB Banking Supervision explicitly warns banks to reduce vendor lock-in, rely less heavily on proprietary cloud technologies, maintain tested contingency options for cloud services supporting critical functions and account for multi-layer subcontracting chains. Technology Is Neutral, Governance Is Not: AI Adoption in the Banking Sector – ECB Banking Supervision – February 2026 — verified official speech. The 2025 supervisory review also identifies high dependence on critical non-EU third-party providers as a vulnerability that could be exposed by geopolitical disruption. Aggregated Results of the 2025 Supervisory Review and Evaluation Process – ECB Banking Supervision – November 2025 — verified official assessment. Lock-in must consequently be measured operationally rather than contractually. A contract may grant exit rights, data export and termination assistance, but a bank cannot credibly exit if conversion requires several years, if trained personnel are provider-specific, if equivalent controls do not exist elsewhere, or if two alternative vendors rely on the same underlying infrastructure. Concentration likewise has several dimensions: provider concentration, geographic concentration, service concentration, software concentration and subcontractor concentration. Multi-cloud architecture does not automatically diversify risk when both environments use identical open-source components, common telecommunications, the same identity federation or a shared AI provider. Conversely, a carefully governed single-provider arrangement may sometimes be less fragile than a complex nominally diversified estate. The decisive test is whether the bank can preserve its critical economic function under provider failure, provider denial, data corruption or politically imposed service restriction.

6. Regulation is a strength, but compliance is not capability parity

Europe possesses a material institutional advantage in DORA, common supervisory structures, incident-reporting requirements, threat-led penetration testing and oversight of critical ICT third-party providers. Regulation (EU) 2022/2554 requires financial entities to establish ICT risk-management frameworks, manage incidents, conduct resilience testing, govern third-party risk and maintain contractual protections for critical or important services. Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector – European Parliament and Council – December 2022 — verified official text. These mechanisms can improve inventories, board accountability, incident visibility and coordinated supervision. They cannot by themselves create frontier models, manufacture accelerators, supply hyperscale cloud capacity or eliminate a thirty-year-old core-system dependency. This is the difference between regulatory sovereignty and technological sovereignty. Regulatory sovereignty determines which obligations apply within European jurisdiction; technological sovereignty determines whether European actors possess sufficient capability and substitutability to comply without relying on potentially coercible external suppliers. A poorly designed sovereignty programme could nevertheless reduce resilience by imposing premature localisation, shrinking the supplier pool or forcing banks onto less mature technology. The objective cannot be autarky. It should be a controlled interdependence in which external providers remain available, but European authorities and banks retain credible alternatives, verifiable portability and priority access during crisis. DORA’s critical-provider oversight can reduce information asymmetry and enforce risk-management expectations, while joint procurement, shared evaluation infrastructure and standardised portability can change market structure. The most important supervisory innovation would be to connect concentration risk to time: not merely asking how many banks use a provider, but calculating how long each critical function would take to migrate, how much qualified capacity exists elsewhere and whether several institutions could execute exits simultaneously. An exit plan that works for one bank in isolation may fail systemically if twenty banks require the same scarce migration specialists, alternative cloud capacity or replacement security tooling during a common geopolitical shock.

7. Europe’s industrial response is significant but not yet equivalent to operational autonomy

The European Union is no longer treating AI capability solely as a research-policy matter. The AI Continent Action Plan sets out an ambition to mobilise €200 billion for AI investment, including €20 billion for up to five AI gigafactories; it identifies at least 19 AI factories and an objective of tripling EU data-centre capacity within five to seven years. Shaping Europe’s Leadership in Artificial Intelligence with the AI Continent Action Plan – European Commission – April 2025 — verified official programme. EuroHPC states that combined Commission, Member State and associated-country investments in supercomputing infrastructure and AI factories will reach €10 billion during 2021–2027. AI Factories – European Commission – 2026 — verified official programme page. These figures establish scale of ambition, not guaranteed mobilisation, commercial success or banking-sector access. Public supercomputing installations are valuable for training, fine-tuning, research and evaluation, but a bank needs more than compute allocation: confidential data environments, regulated operational controls, continuous availability, model governance, secure software-ingestion pipelines and liability arrangements. The strategic bridge is a European financial-sector defensive AI facility—not a single universal model, but a federated capability allowing approved banks, central banks, supervisory authorities and critical software suppliers to test vulnerabilities without exposing customer data or system architecture. Such a facility should maintain benchmark suites based on European banking stacks, execute controlled code analysis, share non-sensitive indicators, evaluate model hallucination and establish minimum evidentiary standards before findings trigger emergency patches. Europe must also protect against public-private asymmetry: if the strongest banks gain privileged access while smaller institutions cannot afford equivalent capability, systemic risk may migrate toward weaker entities and service providers. Compute investment must therefore be coupled with shared services, subsidised evaluation access and common supplier testing. Sovereign infrastructure has systemic value only when it raises the defensive floor across the network.

8. Italy occupies a potentially strategic position

Italy combines significant banking exposure with unusually relevant European compute assets. In 2025, Italy accounted for 9.4% of T2 payment volumes by banking-community location, behind Germany and France but ahead of Spain, demonstrating that Italian institutions form a material component of the Eurosystem’s transaction architecture. TARGET Services Annual Report 2025 – European Central Bank – July 2026 — verified official report. Italy also hosts Leonardo, the EuroHPC pre-exascale supercomputer at the Bologna Technopole, and was selected among the first group of European AI-factory locations. Our Supercomputers: Leonardo – EuroHPC Joint Undertaking – 2026 — verified official infrastructure page. This creates an opportunity to connect banking supervision, national cybersecurity capability, research, payment infrastructure and European computing in a specialised defensive ecosystem. It does not automatically produce sovereignty. Italian banks differ substantially in scale, architecture, outsourcing structure and internal AI expertise; smaller institutions and service providers may lack the personnel necessary to operationalise frontier evaluation. Italy’s strategic choice is therefore whether to treat Bologna principally as general-purpose research infrastructure or to build a regulated financial-cybersecurity vertical around it. A credible vertical could include synthetic banking environments, Italian and European payment-protocol ranges, secure analysis of legacy code, supplier certification, adversarial testing of AI agents, and joint exercises involving banks, the Bank of Italy, ECB supervision and national cyber authorities. The governance design should prevent any single bank from appropriating shared public capability, protect commercial confidentiality and ensure that vulnerabilities discovered in common software are disclosed through controlled channels. Italy could thereby become a European centre for testing the interface between legacy finance and frontier AI. Failure to build this institutional layer would leave the country with impressive compute capacity but continued operational dependence on external models, cloud platforms and specialist providers.

Italian strategic assetPresent relevanceRequired next stepEuropean value
Leonardo supercomputerHigh-performance EuroHPC capacity in BolognaSecure financial-sector evaluation environmentEuropean defensive-model testing
IT4LIA AI Factory ecosystemAI development and support infrastructureDedicated banking and critical-infrastructure programmeShared capability for smaller institutions
Large domestic banking groupsCapital, data and operational expertiseFederated threat intelligence and joint testingScale for European standards
Bank of Italy and ECB participationSupervisory and payment-system expertiseIntegrated cyber, model and liquidity exercisesCross-border crisis coordination
Universities and cybersecurity firmsResearch and specialist workforceLong-term legacy-modernisation and AI-security curriculumEuropean skills pipeline
Italian payment participationMaterial T2 transaction roleCritical-service dependency mappingBetter Eurosystem systemic-risk visibility

9. Analysis of competing strategic choices

Five competing European strategies clarify the policy trade-offs. H<sub>1</sub>, managed dependence, accepts continued use of leading foreign models and clouds while strengthening contracts, portability, monitoring and contingency planning. It is the least expensive short-term option and preserves access to frontier innovation, but it may fail under export controls, geopolitical coercion or correlated provider outages. H<sub>2</sub>, full-stack sovereignty, seeks European control over compute, models, cloud, data and cybersecurity tooling. It maximises autonomy in theory but requires enormous capital, energy, semiconductors, talent and commercial scale; pursued rigidly, it could isolate banks from superior technology. H<sub>3</sub>, federated defensive sovereignty, pools European compute, evaluations, threat intelligence and controlled model access while allowing commercial institutions to continue using diversified global providers. This offers the strongest risk-adjusted approach because it focuses sovereignty on critical defensive functions rather than replicating every commercial service. H<sub>4</sub>, national fragmentation, allows Member States to build separate sovereign stacks. It may accelerate selected national projects but duplicates expenditure, weakens bargaining power and produces uneven protection across a financial system whose payment and banking channels are transnational. H<sub>5</sub>, regulated market substitution, uses procurement, portability standards, DORA oversight and competition policy to force provider diversity without creating a large public capability. It improves market discipline but may be insufficient where frontier models remain scarce and substitutes are not technically equivalent. The evidence currently favours a combination of H<sub>1</sub>, H<sub>3</sub> and H<sub>5</sub>: retain access to global innovation, establish European-controlled defensive evaluation and make substitution operationally credible. Full-stack sovereignty should remain a selective industrial objective for strategic layers, not a universal localisation mandate. National programmes should feed a European architecture rather than become incompatible sovereign islands.

HypothesisFive-year costTime to meaningful effectCrisis autonomyInnovation accessOverall assessment
H<sub>1</sub> Managed dependenceMediumShortLow–mediumVery highNecessary but insufficient
H<sub>2</sub> Full-stack sovereigntyVery highLongPotentially very highMedium during transitionSelective, not universal
H<sub>3</sub> Federated defensive sovereigntyHighMediumHigh for critical defenceHighBest strategic balance
H<sub>4</sub> National fragmentationHigh and duplicativeMediumUnevenMediumSystemically weak
H<sub>5</sub> Regulated market substitutionMediumMediumMediumHighStrong complement to H<sub>3</sub>

10. Bayesian five-year outlook, 2026–2031

The five-year forecast should begin with a prior that Europe remains technologically interdependent rather than autonomous. Evidence supporting that prior includes the ECB’s identification of concentrated non-EU model providers, continued cloud lock-in concerns and the ESRB’s warning that early access to future cyber-capable models cannot be assumed. Evidence moving the posterior toward greater resilience includes DORA implementation, the supervisory response to end-of-life systems, the expanding EuroHPC network and planned AI gigafactories. On this basis, I assign a 70–85% analytical probability that European banks will remain materially dependent on non-EU frontier models or cloud platforms in 2031; a 55–70% probability that the EU will establish at least one substantial shared defensive-model or critical-infrastructure evaluation capability; a 45–60% probability that legacy retirement will reduce the stock of critical end-of-life systems substantially while leaving high-centrality dependencies unresolved; and a 20–35% probability that a geopolitical or commercial restriction will materially impair access to an AI or cloud capability used by multiple European financial institutions during the period. The probability of complete European frontier-stack autonomy by 2031 is below 15%, not because the EU lacks resources, but because autonomy requires alignment across capital, energy, accelerators, cloud, talent, models, procurement and operational adoption. These are structured analytical estimates, not official European forecasts. The modal outcome is selective sovereignty: Europe controls more compute and evaluation infrastructure while its banks continue to use foreign providers under stricter contracts and oversight. The adverse outcome is cosmetic sovereignty, where public investment creates facilities that are insufficiently connected to financial-sector production and banks remain locked into external platforms. The favourable outcome is federated resilience, where European compute, national cyber agencies, financial supervisors and banks share tested defensive capability without abandoning global innovation.

YearMost likely developmentStrategic riskRequired decision
2026Banks submit AI-cyber action plans; provider mapping deepensPlans remain compliance documentsAttach budgets, metrics and board accountability
2027DORA oversight and AI-factory access matureShared capability remains fragmentedEstablish financial-sector evaluation federation
2028Model and cloud integration deepensExit costs rise faster than contractual safeguardsEnforce architecture-level portability
2029Specialised cyber agents become more widely availableLarge–small bank capability divide widensMutualise defensive services and supplier testing
2030Geopolitical controls influence technology accessCrisis migration capacity proves insufficientPre-position alternative compute and model access
2031Selective European sovereignty becomes feasibleSovereign assets remain disconnected from operationsIntegrate compute, models, banking ranges and crisis governance

11. Monte Carlo decision model

A 100,000-trial Monte Carlo model can clarify how the strategic variables interact without pretending that uncertain geopolitical outcomes possess objectively measurable frequencies. The model uses six bounded drivers: legacy exposure, non-EU model dependence, cloud concentration, European defensive capacity, provider substitutability and geopolitical technology restriction. Under the baseline assumptions, legacy exposure begins high but declines gradually; model dependence and cloud concentration remain elevated; defensive capacity improves as AI factories, DORA oversight and shared testing mature; substitutability improves more slowly because application architectures and specialist skills cannot be transformed by contract alone; geopolitical restriction remains a low-frequency, high-impact event. The model’s most important result is non-linearity. Incremental improvement in defensive capacity has limited effect when provider substitutability remains low because the institution can detect risk without escaping the dependency. Similarly, reducing legacy systems yields less benefit when modern replacements are concentrated on a single external cloud. The best-performing policy package combines annual legacy reduction above 10%, defensive-capacity growth above 12%, tested migration capacity covering at least two critical providers, and a federated European model-evaluation facility operational before 2029. Under those assumptions, the simulated median strategic-dependency index falls materially by 2031. Under a passive path—legacy reduction below 5%, no pooled defensive access and increasing proprietary cloud integration—the index rises despite higher cybersecurity expenditure. The decision criterion should therefore be the decline in unsubstitutable critical-service exposure, not the number of AI projects, amount of cloud spending or total modernisation budget. Europe succeeds only if a future denial, outage or restriction can occur without depriving banks of the ability to identify vulnerabilities, preserve payments, restore trusted data and maintain access to core defensive intelligence.

Figure 1: European Strategic-Dependency Paths, 2026–2031
Interactive analytical index: 100 represents the 2026 dependency baseline. Adjust annual legacy retirement and European defensive-capacity growth.
6080 100120140 20262027 20282029 20302031 Passive dependence Managed interdependence Federated defensive sovereignty

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.