Everything You Need to Know About Meeting the ECB’s Cyber Directive Deadline

The European Central Bank’s July 7th directive requires euro area banks to submit a comprehensive AI cyber action plan by October 31st. With frontier AI models now finding vulnerabilities and generating exploits at machine speed, banks must prove their supply chain controls can keep pace.

Financial institutions face two hard problems: visibility and governance. Most can’t see where AI models, MCP servers, and agent-written code sit in their software supply chain and lack the controls to govern it.

In this session you’ll learn how to:

  • Achieve full visibility and control over every AI model, MCP server, and package across your software supply chain.
  • Separate the ~10% of CVEs that are actually reachable, so triage reflects real exposure.
  • Generate an evidence trail – audit logs, SBOMs, and signed releases – as a byproduct of shipping, ready the moment DORA comes asking.

Whether you’re a CISO, security architect, or compliance leader in financial services, this session will give you a concrete framework to meet the October 31st deadline.

Explore the JFrog Software Supply Chain Platform