TL;DR: The European Central Bank has told Eurozone banks to have an AI-threat response plan by 31 October 2026, and the article argues that identity controls are the fastest way to reduce exposure because AI compresses exploitation windows from days to minutes, according to Yubico. The practical takeaway is that phishing-resistant authentication, help desk verification, and tighter access governance now matter more than legacy MFA assumptions.
NHIMG editorial — based on content published by Yubico: ECB AI cyber threat mandate for Eurozone banks and the identity controls it makes non-negotiable
By the numbers:
- 86% of phishing attacks now are AI-driven, according to Yubico.
- 44% year-over-year increase in exploitation of public-facing applications was reported by IBM threat intelligence research.
- Account takeovers can drop by as much as 99.9% when organisations replace legacy MFA with FIDO2/WebAuthn hardware passkeys.
Questions worth separating out
Q: How should banks adapt IAM controls for AI-driven phishing attacks?
A: Banks should prioritize phishing-resistant authentication for both privileged and exposed accounts, because AI can generate convincing lures faster than people can verify them.
Q: Why do help desk recovery flows become a major risk in AI-enabled attacks?
A: Help desk workflows often trust voice, urgency, or partial identity proof, which AI can now imitate convincingly.
Q: What breaks when legacy MFA is used against AI-assisted credential theft?
A: Legacy MFA breaks because it still depends on a human noticing deception before approving the request.
Practitioner guidance
- Deploy phishing-resistant authentication for internet-facing and privileged access Replace push approvals, codes, and shared-secret flows with hardware-backed FIDO2/WebAuthn for the accounts most likely to be targeted first, then expand coverage beyond the privileged tier.
- Redesign help desk recovery workflows Require recovery steps that cannot be satisfied by a cloned voice or generated message, and separate identity proofing from routine support approvals.
- Map access paths that bypass strong auth Identify password reset, account recovery, and call-centre escalation routes that can restore access more easily than direct login flows, then harden those routes first.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- The ECB countries in scope and the exact 31 October 2026 planning requirement for Eurozone banks.
- The checklist of five identity controls banking security teams are expected to map against the mandate.
- The argument for why phishing-resistant authentication can satisfy both the ECB requirement and DORA-aligned authentication expectations.
- The practical discussion of help desk verification and public-facing access points as attack surfaces.
👉 Read Yubico's analysis of the ECB AI cyber threat mandate for banks →
ECB AI cyber mandate: are bank identity controls ready yet?
Explore further
Identity has become the operational control surface for AI-accelerated bank attacks. The ECB’s deadline reflects a reality that many IAM programmes still understate: AI reduces the time available to detect deception, validate access, and revoke abuse. In practice, the control that changes fastest is identity, while infrastructure changes lag behind. Banks should treat identity hardening as the first resilience move, not a supporting task.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly many teams still remove exploitable access.
A question worth separating out:
Q: Who is accountable for AI-threat readiness under the ECB mandate?
A: Accountability sits with the bank’s security, IAM, and risk leadership, because the mandate requires a documented plan and concrete mitigations, not a vague policy statement. Teams should align that plan with existing resilience obligations such as DORA, since the overlap makes identity controls part of both compliance and operational readiness.
👉 Read our full editorial: ECB AI threat deadline puts bank identity controls under pressure