Cybersecurity9 hrs ago

Banks face two clocks on AI: NCSC oversight guidance and ECB's October demand

NCSC's resilience director says agentic AI must stay observable, constrained and overseen, while the ECB demands frontier-AI risk plans by end of October.

Peter Olaleru/3 min/GB

Published October 7, 2026

Editor & Founder

TweetLinkedIn
Banks face two clocks on AI: NCSC oversight guidance and ECB's October demand
Credit: UnsplashOriginal source

Banks are being pulled in two directions on artificial intelligence at once. The National Cyber Security Centre's director of national resilience, Jonathon Ellison, has said financial institutions need to ensure agentic AI remains observable, constrained and subject to appropriate oversight as adoption accelerates. The same institutions are under separate pressure from the European Central Bank, which wrote to banking CEOs on July 7 requiring action plans by the end of October.

Ellison's comments, reported by The Banker, are guidance rather than a formal rule. No other outlet has confirmed them, and the NCSC has not published an agentic-AI-specific framework for the sector. Ellison also said AI could deliver significant benefits across financial services, but that organisations should adopt technologies such as agentic AI carefully and proportionately to the risks involved. That is not a call to stop. It is a call to keep the systems legible.

The distinction matters because agentic AI systems can act with less human review than conventional tooling. It can propagate through third-party chains that banks already struggle to oversee — a problem the ECB letter addresses directly by calling on banks to ensure third-party risk management is fit for purpose.

The ECB's October deadline is tied to frontier AI and third-party risk, not to agentic AI specifically.

What defenders should do:

- Inventory agentic AI deployments, including embedded agents inside third-party and SaaS products, and map each to the data and systems it can reach. - Enforce least privilege for agent identities and service accounts; require human approval for high-impact actions such as payments, data exports and configuration changes. - Log agent actions at the tool-call level and retain them. Observability means being able to reconstruct what an agent did, under whose authority, and why. - Extend third-party risk assessments to cover subprocessors and model providers, not just the contracting vendor. - Set kill switches and rate limits per agent, and test them before the October plans are discussed with the ECB.

Sources

- https://www.thebanker.com/content/d895f408-2462-4aa8-bbae-087ce49c4b53 - https://www.thebanker.com/content/117f63a7-327b-43d4-bee3-343a4cbbac9e

TweetLinkedIn

More in this thread

Reader notes

Loading comments...