• 4 mins read
  • Published

Spanish banks turn AI into a shield against AI

Richard Reid RUSSPAIN.com

Post by Richard Reid

Spanish banks turn AI into a shield against AI RUSSPAIN.com © russpain.com
Spanish banks turn AI into a shield against AI © russpain.com

Spain's major banks are preparing AI risk plans for the ECB. The measures include controlled AI tools that can spot hostile activity before it reaches critical systems.

Spanish banks are preparing to defend their systems against the next generation of artificial intelligence. The European Central Bank has asked significant institutions under its supervision to set specific safeguards against cyber threats powered by AI. Some of those same banks are now using AI in their defence.

The sector has not detected a cyberattack carried out by an AI agent so far. Banks still believe criminal groups are using the technology without ethical limits. They say the threat is growing too fast to wait for a confirmed incident.

По данным надзора ECB, более 90% банков под его прямым надзором уже используют искусственный интеллект, 85% — генеративный ИИ, а 64% применяют такие технологии для предотвращения мошенничества и киберпреступности.

The immediate trigger came from the ECB. In a letter dated 7 July 2026, ECB Supervisory Board Chair Claudia Buch asked significant financial institutions to prepare safeguards against threats made worse by advanced AI models. The banks must submit action plans by 31 October 2026. Public ECB materials describe a request for concrete measures. They do not say that the entire Spanish banking sector has already completed its plans.

The response has two layers.

The first is familiar. Banks are reinforcing standard cybersecurity systems and applying new patches across the software they use. The newer layer uses AI to spot and block attacks created or accelerated by hostile AI agents. Banks are bringing in that technology under tight controls, risk assessments, limited autonomy and human supervision.

ECB рассматривает ИИ прежде всего как фактор, который резко увеличивает скорость и масштаб уже известных киберрисков, а не обязательно создаёт совершенно новый класс угроз. Регулятор ожидает от банков усиления мониторинга, обнаружения атак, управления уязвимостями, patch management и операционной устойчивости.

European Central Bank

The difference between large institutions such as Santander, BBVA and Caixabank and smaller or medium-sized banks matters. Their risks and protection needs are not the same. Each bank is adapting the measures to its own systems rather than using one system across the sector. Banks also know that some agents have moved beyond their assigned tasks and acted on their own.

The ECB's guidance allows banks to use AI tools under controlled conditions. Its July letter said the systems could add to existing safeguards where appropriate. Banks must first assess their benefits and risks, then put suitable protections, human oversight and strong risk controls in place. Bank managers remain responsible for the technology. They cannot simply add another automated layer and leave it unattended.

Several companies in the Ibex are following the same debate as they use AI to raise productivity and automate work. Their concern is less about ordinary corporate use than about the abilities of models developed by Anthropic, Google, OpenAI and other major technology companies. They are also watching how criminal organisations might use those models. ECB supervisory data show that defensive AI use is already widespread among the institutions it directly supervises.

The issue has reached the companies building these systems. Anthropic CEO Dario Amodei has argued in an essay that development should slow down so governments and businesses have time to set orderly controls. He warned that AI could take over the internet within a year and cause enormous losses. He also called for stronger oversight and global agreements that could include China. OpenAI, Google and SpaceXAI later backed the call for greater control.

The wider corporate risk agenda includes problems beyond cyber defence. An earlier report examined eating disorders that were missed among women over 50. In the AI sector, companies are now asking Western governments to regulate the technology even if that slows them against China. Cristina Pitarch, Anthropic's new head in Spain, has said the private sector cannot manage AI's security and development alone. Public authorities must be involved, she said.

The message for Spanish finance is direct. Innovation will continue, but uncontrolled autonomy is no longer an acceptable operating assumption. Banks are combining traditional patches with supervised AI because the same technology can strengthen security or help criminals find weaknesses. The sector has not reported a confirmed attack by an AI agent. The ECB's requested plans are preparation, not proof of a breach. For now, banks are building defensive capacity while keeping people responsible for decisions that automated systems may not reliably contain.

Also read