The European Central Bank sent a letter on July 7, 2026 to CEOs of Europe's largest banks warning that frontier AI models let attackers find and exploit software vulnerabilities faster than human-paced processes. The 110 largest European banks (and indirectly 1900 smaller institutions) must submit a concrete action plan with named controls, resources, and owners to their Joint Supervisory Team by October 31, 2026. CVSS-only vulnerability prioritization can't keep pace with AI-accelerated exploitation; reachability-based prioritization is proposed as a replacement, reportedly cutting noise by 80-90%. The piece also flags that most banks' plans overlook governing the AI models, MCP servers, and agent skills already running in their own environments, and ties requirements back to DORA's demand for on-demand proof like signed SBOMs and remediation timelines. JFrog outlines a six-step approach (gap analysis, single system of record, embedded security, governing agents/MCPs as supply chain components, reachability-based prioritization, automated remediation) and references its own work with a large finance client and a 2026 Software Supply Chain Security State of the Union report.

5m read timeFrom jfrog.com
Post cover image
Table of contents
What Makes AI Frontier Model Attacks So Dangerous?Where the software supply chain fitsThe blind spot inside your own stackThe JFrog Approach

Questions this post answers

What is the deadline for European banks to submit their AI cybersecurity action plan to the ECB?

European banks must submit a concrete action plan to their Joint Supervisory Team by October 31, 2026. The plan needs named controls, resources, and owners for protecting against threats posed by frontier AI models. This requirement applies directly to the 110 largest European banks and indirectly to about 1900 smaller institutions, following a letter the ECB sent to bank CEOs on July 7, 2026. Banks racing to meet the ECB's October 2026 deadline can track supply chain security guidance on daily.dev.

Why is CVSS scoring not enough to prioritize vulnerabilities against AI-accelerated attacks?

CVSS-only prioritization cannot keep pace because AI-capable attackers can turn a low-impact issue into a working exploit within minutes, often before a CVE is even published or scored, and CVSS was never a fully reliable severity indicator to begin with. Reachability analysis, which checks whether a vulnerability actually applies to what is running, is presented as the replacement and can cut vulnerability noise by 80 to 90%. Security teams weighing reachability analysis over CVSS scoring can follow supply chain security developments on daily.dev.

What does the DORA regulation require banks to prove about their software supply chain security?

DORA requires banks to prove on demand that a specific security control worked when needed, such as producing a signed SBOM, an attestation, or a timestamped remediation record for a named release. A 2026 Software Supply Chain Security State of the Union report found most organizations still need a week or more to produce that proof when asked, with only a small fraction able to do it in a day. Teams building DORA-ready evidence trails can keep up with supply chain compliance news on daily.dev.

76 Impressions