• The ECB gave EU banks until 31 October. 

    Get the Identity Readiness Checklist

    AI is compressing the time between a stolen credential and a live breach. Phishing-resistant hardware authentication closes the one gap passwords, OTPs, and push notifications can’t.

    The Directive

    On 7 July 2026, the European Central Bank told eurozone banks to have plans in place by 31 October to address AI-enabled cyber threats capable of disrupting financial services. It’s a concrete deadline, not a guideline—and identity is one of the few control layers banks can act on directly, without waiting on vendors or infrastructure overhauls.

    What AI actually changes

    Attackers use AI to generate convincing, personalized phishing at a scale and speed manual campaigns never reached.

    Voice-cloning and deepfake tooling now defeat call-center and helpdesk verification steps that once relied on human judgment.

    The gap between credential theft and account takeover is shrinking—from days to minutes in many observed cases.

    Passwords, SMS codes, and app-based push approvals all depend on a human making the right call under pressure. AI is specifically built to exploit that moment.

    Get the Identity Readiness Checklist

    Stop hijacked identity

    YubiKey hardware security keys remove the exploitable moment entirely. Because authentication is bound to a physical device using FIDO2/WebAuthn, there’s no code to phish, no push to approve under duress, and no shared secret for an AI-generated voice or message to extract. It’s one of the few controls that stays effective even as attack sophistication increases.

    This isn’t a replacement for a full AI threat mitigation plan — it’s the identity control that keeps working when the rest of the plan is still catching up.

    Proof

    Used by leading global banks and financial institutions to secure privileged and customer-facing access.

    FIDO2/WebAuthn hardware authentication is explicitly recognized as phishing-resistant by NIST and major regulators.

    Deployable across workforce and high-risk customer segments without replacing existing IAM infrastructure.

    Added bonus: deploying phishing-resistant MFA to satisfy the ECB mandate simultaneously checks critical boxes for DORA’s ICT risk management and strong authentication requirements.

    Close the identity gap before 31 October

    Download the checklist built for banking security leaders mapping identity controls to the ECB’s AI threat mitigation expectations.

    Get the checklist

    Fill out this form to get the checklist