When something serious happens you have hours, not weeks. Why the record of what your AI did has to exist before the incident.
On 7 July 2026 the European Central Bank sent a letter to every significant bank it supervises. It has a reference, SSM-2026-0301, and a deadline. By 31 October 2026 each bank hands its joint supervisory team an action plan on AI-driven cyber threats, and the board approves it first. That last detail is the sort that changes who is in the room.
The letter is about attackers using AI, and on first reading it is a security memo: attack surface, patching, monitoring, suppliers, defence in depth, resilience. Most of that lands on the security team, and the security team will do what it always does, which is buy something and write a slide. This post is about the part that lands somewhere else.
What the letter asks for
Six areas, broadly. Know your attack surface, including the AI systems you run and where they are exposed. Find and fix vulnerabilities faster, because an attacker with AI finds them faster. Monitor for AI-enabled attacks, and use AI in your own defence where it helps. Govern your third parties and suppliers, the AI ones included. Build defence in depth, so one failure is not the whole story. Be ready to recover, and share what you learn with the rest of the sector.
Read it once and it is a cyber letter. Read it twice and every one of the six is a request for an account: a description of what actually happens, owned by the people who will be asked about it. The board signs, which means the board is being asked to state, in writing, what its AI does and how it knows.
The awkward item on the list
The attack surface item is the interesting one for anyone who has spent the last year putting copilots into the back office. It does not say the AI your security team knows about. It says the attack surface. The copilot that reads customer files, the chat tool that drafts credit memos, the agent someone wired to the payments API during a hackathon and never unwired: all of it counts, and the letter would like to know how it is governed.
Most banks can produce a list of models. Fewer can produce, for any one of them, a record of what it read, what it was allowed to do, and who signed off when it did something consequential. That is the difference between an inventory and an account, and the letter is asking for the second. Nobody convenes a board to approve an inventory.
What a good answer looks like
The plan the board approves in October will be tested in the ordinary way: an incident, a question from the supervisory team, a follow-up visit. When that happens the useful evidence is not the plan. It is the record of what the AI did on the day, and that record has three properties or it is a log.
It is written at the moment of the action, not reconstructed the week after. It is bound: the thing a person approved and the thing that ran are the same bytes, so "the model did something else" is a check rather than an opinion. And someone who does not work for you and does not trust your systems can verify it on their own machine with a free tool. A supervisor is, professionally, a person who does not take your word for it. Give them something they do not have to.
Athena produces that record. Data Control sees what the AI reads and sends. Secure Runtime stops consequential actions for a named person and binds the approval to what runs. Sovereign Compliance seals the result so anyone can check it offline. None of that is a cyber control in the letter's sense. It is what makes the answer to "how do you know" a file rather than a meeting.
Before 31 October
We are not lawyers, and this is not advice on what your plan must contain. That belongs to your compliance and legal teams, who will already have the letter open. The engineering question underneath is simpler and less comfortable: for each AI system on your attack-surface list, can you show, today, what it did last Tuesday and who allowed it?
If yes, write that down, because it is most of the paragraph the board wants. If no, you have eight weeks. That is enough to put a record in front of the AI you already run, and about the time it takes your vendors to answer the supplier questionnaire they are about to receive anyway.
Banks were always going to be asked to prove what their AI did. Now the question has a date.


