The European Central Bank (ECB) has put a date on the calendar, and security leaders beyond banking should pay attention.
In July, the ECB issued “Addressing AI-enabled cybersecurity threats,” its first published letter to banks in more than four years. The message reflects the seriousness of the shift: AI is accelerating vulnerability discovery and exploitation, increasing the speed and scale at which cyber risks can materialize. By 31 October 2026, significant institutions are expected to submit an action plan outlining how they will strengthen defenses as AI accelerates vulnerability discovery and exploitation. The ECB calls for action across attack surface protection, vulnerability and patch management, monitoring and detection, AI-enabled defense, third-party risk, defense in depth and operational resilience.
For security leaders, the pressure is understandable. Most enterprises operate complex environments spanning legacy infrastructure, cloud, identity, SaaS, third parties and critical systems. As parts of the attack chain move at machine speed, defenders have less time to understand behavior and act before business impact.
AI changes the speed of attacks, not the path.
AI can accelerate vulnerability discovery, exploit development, reconnaissance and decision-making. Once attackers gain access, they still need to discover systems, abuse credentials, escalate privileges, move laterally, establish control and reach valuable assets. Those behaviors remain opportunities to detect and stop an attack.
The ECB guidance maps closely to four security use cases enterprises should pressure-test now.
1. Reduce exposure before attackers exploit it
The ECB puts immediate emphasis on protecting exposed assets and accelerating vulnerability and patch management. AI raises the pressure because vulnerabilities can be discovered and weaponized faster, while security teams still have finite remediation capacity.
The priority is knowing which exposures create a meaningful path toward critical systems and data. Vectra AI continuously identifies assets, identities and observed exposures across the environment, then adds behavioral and privilege context so teams can focus on risky access and attack paths that deserve attention first.

For security leaders, the practical question is simple: if AI finds weaknesses faster, can your team identify which ones give an attacker somewhere valuable to go next?
2. Protect AI agent identities and non-human access
The ECB also calls for stronger zero-trust verification across users, devices, applications, APIs and service accounts. That becomes more important as AI agents and other non-human identities gain access to enterprise systems and act continuously.
An AI agent may authenticate successfully and still create risk through compromise, excessive privilege or unexpected behavior. Security teams need visibility after access is granted, especially when the actor can operate at machine speed.
Vectra AI analyzes behavior across human and non-human identities to identify privilege abuse, suspicious administrative activity, lateral movement and other signs that trusted access is being misused. The focus is on what the identity is doing now, not only whether it authenticated successfully.
Ask yourself: can you recognize risky behavior from an AI agent or service account when every login involved looks legitimate?
3. Close visibility gaps around unmanaged devices
The ECB calls on institutions to strengthen monitoring of network traffic, critical internal systems and other indicators of compromise, while maintaining accurate asset inventories. That is difficult when important devices sit outside endpoint coverage.
Unmanaged devices, legacy systems, IoT and OT, network infrastructure and specialized workloads can all become blind spots when endpoint agents cannot be deployed. Attackers can still use those systems to move, communicate and reach critical assets.
Vectra AI provides agentless network visibility into managed and unmanaged devices, continuously observing communication behavior and suspicious activity without requiring endpoint software. That gives security teams coverage where EDR cannot reach and another source of evidence when an attack crosses those systems.
The readiness question: what percentage of your environment can participate in an attack without appearing in your endpoint security view?
4. Operationalize the SOC for AI-speed attacks
The ECB explicitly encourages stronger monitoring, detection and AI-assisted defense, with governance, validation and human oversight. That is where defender speed becomes critical.
The recent Hugging Face incident shows why this matters. An autonomous agent carried out roughly 17,600 actions across Kubernetes, AWS, VPN, databases and source control. The pace was new, but the behaviors were familiar: discovery, credential acquisition, privilege escalation and movement between environments.
Most enterprises already collect large volumes of security telemetry. The challenge is that signals sit in separate tools while the attacker moves across identity, cloud and the network. Every minute analysts spend connecting evidence or chasing false positives gives the attacker more time to move.
Vectra AI uses Attack Signal Intelligence to detect, triage, correlate and prioritize attacker behavior across domains. Agentic investigation analyzes prioritized threats, reconstructs attack progression, summarizes what happened and recommends next steps. AI-assisted hunting lets analysts investigate further with natural-language questions across network, identity and cloud activity.


This matters across the enterprise, especially in critical 24/7 environments where automated actions can disrupt essential operations. Speed still needs explainability, evidence and appropriate human oversight.
Ask how long it takes your SOC today to recognize that events across identity, cloud and the network are actually one attack.
Use the October deadline to pressure-test your resilience
The ECB also encourages banks to exercise high-speed, high-volume attacks, including zero-day compromise, ransomware and cloud or supply-chain disruption. Use that as a practical test of the full defensive chain.
Start from an assumed breach and ask:
- Can we identify the attack paths that create the greatest exposure?
- Can we recognize compromise when valid credentials or non-human identities are being used?
- Can we see unmanaged devices and activity outside endpoint coverage?
- Can we follow attacker progression across identity, network and cloud?
- Can analysts get from detection to understanding quickly enough?
- Can we demonstrate that our controls work under an AI-speed scenario?
Vectra AI helps enterprises reduce exposure, protect human and non-human identities, extend visibility to unmanaged devices, and operationalize detection and investigation at AI speed. Together, those capabilities strengthen the post-compromise layer of defense the ECB is asking institutions to test and improve.
31 October is a useful deadline. The threat will keep moving.
AI will continue to accelerate vulnerability discovery and attack execution. Security leaders need confidence that when something gets through, the organization can still see the attacker, understand how the attack is progressing and act before it reaches a critical business asset.
For institutions preparing their ECB action plans, now is the time to assess where AI-speed attacks could outrun existing controls and where stronger attack signal, broader visibility and faster investigation can close the gap.
See how Vectra AI maps to the ECB action plan and where we can help strengthen your defenses: Read the ECB Action Plan Brief.
Learn how Vectra AI Pro helps you defend at AI speed: Read the blog.
See how we can help build your action plan for AI-enabled cyber threats: Contact us.


.jpeg)