In July 2026, the European Central Bank (ECB) sent a letter to financial institutions mandating them to submit a clear plan by the end of October 2026 to address the escalating threats posed by frontier AI cyber models. The ECB identified modernization of legacy infrastructure as a central tenet of the plan. This is a necessary response to the new cyberthreat landscape where frontier AI models such as Mythos have drastically compressed the window between vulnerability discovery and exploitation. AI-enabled attacks turn even more dangerous because they hit systems that were already exposed. Hardware and software that have reached end-of-life (EoL) and are no longer receiving security patches are a treasure trove for threat actors. Not only are they an open gate to get into organizations, but once inside, they enable attackers to move faster, dwell longer, and inhibit the ability of defenders to remove them. The fast arrival of frontier AI models has underlined the urgency of removing obsolete, unsupported devices from critical networks. Globally, nearly half of business network infrastructure assets were already aging or obsolete at the start of this decade. Volt Typhoon, the state-sponsored group which targets unpatchable network infrastructure in critical infrastructure sectors, is a live example of what happens when critical systems run on EoL technology. A converging EU position on the dangers of legacy technology The ECB’s letter is a recognition that critical infrastructure faces systemic exposure, at a moment when AI accelerates the speed of attack and shortens the window organizations have to respond. The European Supervisory Authorities (ESAs) have issued a parallel statement on ICT risks from frontier AI models. They require entities to reduce the attack surface by “eliminating unnecessary exposures, enforcing segmentation, and decommissioning legacy systems”. They insist that these steps must evolve from basic hygiene measures like inventory
Why Fixing Europe's Legacy Tech Problem is a Real AI <b>Cyber Security</b> Test
Read the original article
blogs.cisco.com →