The call from the Bank of Italy brings the risk of cyber attacks linked to artificial intelligence into the spotlight for most of the financial system. According to Repubblica, the authority does not just signal the danger but asks those being watched to react and explain by December what measures they intend to take. The deadline introduces a precise passage of accounting for the defenses taken.

The scope indicated by the source does not only concern the more significant banks considered. The request extends to all subjects under surveillance by the Bank of Italy. It includes both major banks and less significant ones, as well as other categories of financial operators subject to supervision.

Examples include investment companies and alternative fund managers. The message thus takes on a transverse scope regarding the diverse dimensions and activities of the intermediaries. The specific element of the call-out is represented by the cyber attacks that exploit artificial intelligence.

Repubblica reports the warning without providing details on classification of techniques used, economic estimates of damage or data on number of incidents. No concrete cases involving individual banks, investment companies, or asset management societies are mentioned. The request articulates itself into two planes.

The first is the need to react to the danger, hence organizing defenses. The second is the obligation to clarify what each subject intends to do. By December, therefore, interested intermediaries must make explicit their response to the risk signaled by the authority.

The deadline of December is the main temporal reference reported. The source published on July 18, 2026, does not specify which day of the month represents the final term nor describe how information should be transmitted. Neither is it specified whether uniform models, intermediate checks, or different requirements will apply depending on the category and dimension of the watched subject.

The involvement of lesser-known operators is an important step in understanding the initiative. The indicated risk does not circumscribe itself only to major groups considered. The request extends to all subjects under surveillance by the Bank of Italy.

It includes both significant and less-significant ones, as well as other categories of financial operators subject to supervision. Examples include investment companies and alternative fund managers. The message thus takes on a transverse scope regarding diverse dimensions and activities of the intermediaries.

The specific element of the call-out is represented by cyber attacks that exploit artificial intelligence. Repubblica reports the warning without providing details on classification of techniques used, economic estimates of damage or data on number of incidents. No concrete cases involving individual banks, investment companies, or asset management societies are mentioned.

The next verifiable step will be the deadline set for December when the watched subjects must explain what they intend to do against the threat. Details on degree of detail required, criteria with which Bankitalia evaluates responses, and eventual consequences for who presents insufficient measures remain unclear. The source does not anticipate these aspects determining the actual extent of the call.