Part of the AI Regulation News hub.
Banca d'Italia has told the intermediaries it supervises directly to put a board-level report and work plan on frontier-AI cyber risk in front of its Supervision arm by 31 December 2026
Eight days after the ECB moved on significant euro area banks, Banca d'Italia covered the ones the ECB does not supervise. The communication invites firms to improve six areas, but the report, the work plan and the December deadline are written in the language of obligation.
Bottom line: A supervisory communication to the market, not a regulation. It creates no new rule. What it does create is a filing: a Report with a work plan attached, to be transmitted to Supervision by 31 December 2026, and a named internal owner to be communicated to the supervisor.
Who this affects: Compliance, ICT risk and board secretaries at less significant Italian banks and banking groups including Bancoposta, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, alternative investment fund managers, management companies, crowdfunding service providers and article 106 financial intermediaries.
Issue date: 17 July 2026. The single operative deadline in the document is 31 December 2026. It is the only date in the text.
What changed: Board and management bodies must revisit the risk appetite framework to take in frontier-technology risk, and each entity must run a joint session of the Consiglio di Amministrazione and the Collegio Sindacale to examine the communication and start drafting the Report in that same sitting.
Analysis: Read the verbs. Banca d'Italia invites intermediaries to strengthen the six areas. It does not invite them to file. The Report must be transmitted, work on it shall be started at the joint session, and every entity shall identify and communicate a responsibility point. The soft framing covers the substance; the hard framing covers the paperwork and the date.
Primary sources: Comunicazione al mercato (PDF, IT, 5 pages) · Banca d'Italia notice page (IT)
- Instrument (EN)
- Communication to the market on digital operational resilience and advanced Artificial Intelligence models
- Authority
- Banca d'Italia, Dipartimento Vigilanza Bancaria e Finanziaria
- Jurisdiction
- Italy
- Status
- Supervisory communication to the market
- Bindingness
- The communication invites the substantive measures. It uses mandatory language for the Report, the attached work plan, the responsibility point and the transmission deadline.
- Issue date / next deadline
- 17 July 2026. Report with work plan to be transmitted to Supervision by 31 December 2026.
- Related EU instrument
- Digital Operational Resilience Act, cited four times, including articles 4.1, 24.1 and 25.1 and the threat-led penetration testing regime
- Scope note
- Addressed to entities supervised directly by Banca d'Italia's banking and financial supervision department. Significant institutions under direct ECB supervision are not the addressees.
- Editorial Note
- Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
- Primary source
- https://www.bancaditalia.it/compiti/vigilanza/avvisi-pub/2026.07.17-comunicazione/Comunicazione-al-mercato-in-materia-di-resilienza-operativa-digitale-e-modelli-avanzati-di-intelligenza-artificiale.pdf
The filing, and the date
The operative paragraph sits on the last page of a five-page communication published on 17 July 2026. Banca d'Italia expects the Consiglio di Amministrazione, sitting jointly with the Collegio Sindacale, to examine the communication. In that same session, work must begin on drafting a Report.
The Report has a specified shape. For each of the areas the communication identifies, it must set out the current level of risk exposure and the adequacy of existing controls, identify the main gaps and the corresponding intervention priorities, and define a work plan setting out the actions, the timing and the investments required, proportionate to the intermediary's risk profile, the complexity of its services, its business and its operations. The plan must also define how the board will verify its own progress against it.
Separately, every financial entity must identify and communicate to the supervisor a specific point of internal responsibility. The communication offers the second-line ICT risk control function as its example.
Then the deadline, which is the only date in the document: the Report, with the work plan attached, must be transmitted to Supervision by 31 December 2026.
Who is in scope, and who is not
This is the detail most likely to be reported wrongly, because it is in a footnote rather than the body. The communication is addressed to entities supervised directly by Banca d'Italia's Dipartimento Vigilanza Bancaria e Finanziaria, and the footnote lists them: less significant banks and banking groups, Bancoposta included, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, alternative investment fund managers, management companies, crowdfunding service providers, and article 106 financial intermediaries.
The phrase that matters is less significant. Under the Single Supervisory Mechanism, significant institutions are supervised directly by the ECB, and on 9 July 2026 the ECB told those banks to file AI cyber-resilience action plans with their joint supervisory teams. Banca d'Italia's communication lands eight days later and covers the population the ECB does not reach directly.
So an Italian bank reading both documents should not assume it is answering the same request twice. Whether you file with a joint supervisory team or with Banca d'Italia's Supervision arm depends on which side of the significance line you sit, and the two exercises have different deadlines.
The reach beyond banking is the other thing worth noting. A crypto-asset service provider or a crowdfunding platform authorised in Italy is squarely inside this communication, and those firms have historically had less supervisory correspondence about ICT risk than banks have.
Why Banca d'Italia says it is doing this
The reasoning is unusually specific for a supervisory communication, and it is worth quoting in substance because it explains the scope of what is being asked.
Latest-generation models, the communication says, can identify vulnerabilities in software systems and simultaneously generate the means of exploiting them, in extremely short times and without the need for specific technical skills. The consequence Banca d'Italia draws is a sensible reduction in the interval between a vulnerability being found and being exploited, and therefore an increase in the risk of effective cyber attacks.
From that it reaches the asymmetry argument: new AI technologies could increase the asymmetry between attackers and defenders, to the detriment of the latter, such that rapid adaptation by financial entities becomes necessary. And then the framing sentence, which is the one compliance functions will find quoted back at them: strengthening digital operational resilience is not merely a compliance requirement, but an essential condition for ensuring business continuity and the ability to offer reliable financial services.
Note what the reasoning does not claim. There is no assertion that a specific attack has occurred against an Italian intermediary, no threat-intelligence citation, and no named model or capability. The argument is prospective.
The six areas
The communication asks intermediaries to put measures in place across six areas. Governance comes first, and it is the only one addressed to a body rather than a function: administration and management bodies must revisit the risk appetite framework to incorporate risks arising from frontier technologies, coherently with strategic decisions including ICT investment and resource allocation. The same paragraph asks that the board include members with adequate technological competence, artificial intelligence included, and that it budget for their continuing training.
Governance also carries the third-party angle. Boards are required to define appropriate controls for the governance of external IT service providers, and the communication is specific about what those include: adequate contractual requirements to ensure effective security monitoring and patch management by the supplier, and rigorous criteria for ex-ante assessment and selection.
The remaining five are IT hygiene, built on defence-in-depth, strict authentication and authorisation, granular access management and network segmentation; management of IT assets and the potential exposure surface, which turns on complete and reliable inventories and on classifying assets by criticality including their direct internet exposure and cloud reliance, with modernisation of legacy technology; vulnerability and patch management, prioritising open source software and externally accessible systems and singling out zero-day exposure; monitoring, detection and defensive measures, including traffic to and from third-party IT providers, with monitoring synchronised to the asset inventory; and testing, tied explicitly to the DORA regime.
AI appears on both sides of these areas, which is the part generic coverage tends to flatten. It is the threat in the framing, but the communication also contemplates intermediaries using AI-based scanning to close the gap with attackers and AI-based tooling to analyse large volumes of data and identify anomalies in real time. A footnote attaches conditions to that: if intermediaries choose AI-based defensive tools, their use must be consistent with the firm's AI strategy and accompanied by an adequate assessment of the specific risks, plus suitable controls including performance and degradation monitoring and human oversight.
How this sits on top of DORA
Banca d'Italia is explicit that it is not displacing anything. It frames the communication as consistent with the approach of European single supervision, and says the requirements of the Digital Operational Resilience Act retain their full force in this context. DORA is cited four times.
The citations are specific rather than decorative. Article 4.1 is invoked for proportionality, on cost and benefit against the intermediary's overall risk profile and the complexity of its services. Articles 24.1 and 25.1 are quoted for the digital operational resilience testing programme and its contents, and the communication preserves the threat-led penetration testing requirements for entities that competent authorities have designated for them.
The practical reading is that this creates a reporting obligation rather than a substantive one. The measures Banca d'Italia describes are, for the most part, restatements of duties that DORA already imposes. What is new is that supervised intermediaries must now self-assess against them area by area, commit to a remediation timetable with named investments, and hand that assessment to their supervisor on a fixed date.
What we did not verify
We fetched the five-page communication PDF directly from bancaditalia.it, extracted its text with a clean decode and no replacement characters, and took every fact here from that document. The title was separately confirmed against the live notice page.
We did not verify any parallel instrument from IVASS, the Italian insurance supervisor. Press summaries of this communication have paired the two authorities. The string IVASS does not appear anywhere in this PDF, so if such a communication exists it is a separate document that we have not opened, and nothing in this article should be read as describing insurance-sector obligations.
We did not open the ECB action plan document itself for this piece, and our description of its scope comes from our own earlier reporting rather than from a fresh reading. We did not open the Governor's Considerazioni Finali sul 2025, which the communication cites in a footnote on third-party providers.
We will not say what happens if an intermediary misses 31 December 2026. The communication specifies no sanction, no escalation path and no consequence for non-filing, and we did not find one stated in a source we opened.
If Banca d'Italia supervises you directly, the calendar item is a board meeting, not a filing. The Report has to be started in a joint session of the Consiglio di Amministrazione and the Collegio Sindacale, it has to cover all six areas with gaps and priorities, and it has to carry a costed work plan with a board-verification mechanism attached. Working backwards from 31 December 2026, the joint session is the long pole. Name your responsibility point early, because that has to be communicated to the supervisor separately.
Source File
Open the five-page PDF and confirm three things: the title on page 1, footnote 1 on the same page listing the addressees and the words banche e gruppi bancari meno significativi, and the final sentence on page 5 setting the 31 dicembre 2026 transmission deadline for the Relazione and its piano di lavoro.
La Relazione, con allegato il piano di lavoro, deve essere trasmessa alla Vigilanza entro il 31 dicembre 2026. (Italian original. In English: the Report, with the work plan attached, must be transmitted to Supervision by 31 December 2026.) Banca d'Italia, Comunicazione al mercato, 17 July 2026, page 5
FAQ
Who has to file with Banca d'Italia by 31 December 2026?
Entities supervised directly by Banca d'Italia's banking and financial supervision department. The communication's footnote lists less significant banks and banking groups including Bancoposta, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, alternative investment fund managers, management companies, crowdfunding service providers and article 106 financial intermediaries.
Does this apply to Italy's significant banks supervised by the ECB?
They are not the addressees of this communication. Significant institutions are supervised directly by the ECB, which asked those banks for AI cyber-resilience action plans through their joint supervisory teams on 9 July 2026. Check which supervisor you file with before assuming the two exercises are the same request.
What exactly has to be transmitted?
A Report with a work plan attached. For each area covered by the communication the Report must state the current level of risk exposure and the adequacy of existing controls, identify the main gaps and intervention priorities, and set out a plan with actions, timing and investments proportionate to the firm's risk profile and complexity, including how the board will verify progress.
Is the communication legally binding?
It is a supervisory communication rather than a regulation, and it invites intermediaries to strengthen the six areas. It uses mandatory language for the procedural obligations: the Report must be transmitted by the deadline, work on it shall begin at a joint board and Collegio Sindacale session, and each entity shall identify and communicate a responsibility point to the supervisor.
Does it require firms to use AI defensively?
No. It contemplates AI-based vulnerability scanning and AI-based anomaly detection as options where appropriate. If a firm does adopt them, a footnote requires that their use be consistent with the firm's AI strategy and accompanied by an assessment of the specific risks and suitable controls, including performance and degradation monitoring and human oversight.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.