Why Fixing Europe’s Legacy Tech Problem is a Real AI Cyber Security Test The European Central Bank (ECB) mandated financial institutions to submit a plan by the end of October 2026 to address cybersecurity threats from frontier AI models, focusing on modernizing legacy infrastructure. The European Supervisory Authorities (ESAs) issued a parallel statement requiring entities to decommission legacy systems and reduce attack surfaces, highlighting that end-of-life technology has become a systemic risk. The ECB's approach serves as a model for other sectors and EU policy, though the current EU Cybersecurity and AI Action Plan overlooks this urgent issue. In July 2026, the European Central Bank ECB sent a letter https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026 letter on AI enabled cybersecurity threats.en.pdf to financial institutions mandating them to submit a clear plan by the end of October 2026 to address the escalating threats posed by frontier AI cyber models. The ECB identified modernization of legacy infrastructure as a central tenet of the plan. This is a necessary response to the new cyberthreat landscape where frontier AI models such as Mythos have drastically compressed the window between vulnerability discovery and exploitation. AI-enabled attacks turn even more dangerous because they hit systems that were already exposed. Hardware and software that have reached end-of-life EoL and are no longer receiving security patches are a treasure trove for threat actors. Not only are they an open gate to get into organizations, but once inside, they enable attackers to move faster, dwell longer, and inhibit the ability of defenders to remove them. The fast arrival of frontier AI models has underlined the urgency of removing obsolete, unsupported devices from critical networks. Globally, nearly half of business network infrastructure assets were already aging or obsolete at the start of this decade. Volt Typhoon, the state-sponsored group which targets unpatchable network infrastructure in critical infrastructure sectors, is a live example of what happens when critical systems run on EoL technology. A converging EU position on the dangers of legacy technology The ECB’s letter is a recognition that critical infrastructure faces systemic exposure, at a moment when AI accelerates the speed of attack and shortens the window organizations have to respond. The European Supervisory Authorities ESAs have issued a parallel statement https://www.eba.europa.eu/publications-and-media/press-releases/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision-mitigate-ict-risks-frontier on ICT risks from frontier AI models. They require entities to reduce the attack surface by “eliminating unnecessary exposures, enforcing segmentation, and decommissioning legacy systems”. They insist that these steps must evolve from basic hygiene measures like inventory management to evolve toward AI-driven attack surface management. Building on their expertise and DORA’s comprehensive operational resilience provisions, the ECB and EU financial regulators independently identified decommissioning legacy systems as a frontline defense against AI-enabled attacks. EoL technology has shifted from an IT hygiene issue to a systemic risk; one the ESAs explicitly link to cascading failures across interconnected financial infrastructure. The ECB approach: an example for other sectors and EU policy Policy makers should look at the financial sector for building their action plans to treat this urgent issue at scale; an opportunity unfortunately overlooked by the current EU Cybersecurity and AI Action Plan. The approach mandated by the ECB stands out for its sense of urgency, prioritization and focus. It demands immediate, direct action, and signals that other supervisory activities need to be delayed or adjusted to concentrate efforts on this urgent systemic risk. The ECB and ESAs’ prioritize patch management, perimeter security, and third-party risk, which translate into specific actions for critical infrastructure that Europe should look to accelerate: Live asset registers and lifecycle assessments: you cannot manage EoL risk you haven’t inventoried. Defense-in-depth architecture , built on Zero Trust and micro-segmentation, so a single legacy failure point doesn’t become a systemic one. Automated patching and real-time telemetry , which only work on infrastructure that still receives support. Modernization is the precondition for AI-assisted monitoring. Incident reporting that flags EoL technology’s role in breaches , closing the data gap and giving regulators evidence to prioritize future rules. Secure supply chains: AI can identify weak links across supply chains to automate multi-stage attacks. EoL exposure often enters via these third-party connections within institutions that have modernized their own core systems. The scale of this problem beyond banking remains poorly understood. WPI Strategy’s report, U pdate Critical: Counting the Cost of Cybersecurity Risks from End-of-Life Technology on Critical National Infrastructure , commissioned by Cisco, showed the issue is growing but is under-researched, especially when it comes to weigh the cost of “technical debt” against the cost of replacement. The report’s recommendations track closely with what the ECB and ESAs are now asking of banks. Scaling the solution to a fast-growing problem The tools to scale this approach across Europe could be activated swiftly if policymakers chose to activate them: ENISA and national cyber authorities should issue clear directives to replace legacy systems and patch edge-facing network devices across national government and critical infrastructure;- The NIS2 targeted amendments should bring EoL technology risk explicitly into scope; - The Digital Omnibus ‘ push to harmonize incident reporting could finally surface sector-wide data on how often EoL technology is a critical root cause of breaches; - The proposed European Competitiveness Fund could provide the financial leverage to accelerate the replacement of legacy technology at the pace the ECB and ESAs are now demanding. Cisco’s Chief Security & Trust Officer Anthony Grieco recently announced https://blogs.cisco.com/news/doubling-down-on-resilient-infrastructure changes to make secure configurations the default across Cisco offerings, and to proactively alert administrators when insecure choices are being made. This “security by default” principle is the type of action that reduces the burden on institutions racing to upgrade their resilience against AI cyber threats. The ECB’s October 2026 deadline can work as a forcing function because it’s specific and near-term. Institutions that treat it as an isolated compliance exercise will miss the point and fail to address the underlying vulnerability. Those that use it to fix asset visibility, patch discipline, and architecture will be ahead. The issue of legacy technology, leading to dangerous technical debt, was always going to require resolution. The ECB has just given it a clear approach, vision and timeline.