In late May 2026, the European Central Bank convened an urgent meeting with eurozone-supervised banks. The message was direct: advanced AI is compressing the time between vulnerability disclosure and real-world exploitation. In some scenarios, that window may now be as short as thirty minutes.¹ Patch cycles that were acceptable last year are not acceptable now. Banks must move faster.
The ECB is right about the problem. Its response - accelerate patching, increase scanning, elevate testing, improve recovery readiness — is the wrong race to be winning.
Every item on the ECB’s checklist operates downstream of execution. Faster patching reduces the window between a vulnerability existing and being closed. Better scanning finds weaknesses before attackers do. Improved recovery readiness means getting back to normal faster after a breach. These are all valuable. None of them prevents a consequential action from executing without verified human authority.
The ECB’s own guidance acknowledges this gap in a single line, buried in its practical checklist: “Governance and auditability: DORA pushes organisations to demonstrate that controls are effective, not just documented.”¹ Effective. Not documented. That distinction is the entire problem.
Consider what AI-accelerated attacks against banks actually target. Wire transfers initiated on spoofed executive instructions. Privileged access granted through compromised credentials. Bulk data extractions authorised through manipulated workflows. Agentic AI systems executing financial decisions the named human never actually confirmed. In every one of these cases, the attack succeeds not because a patch was missing or a scan was slow. It succeeds because a consequential action executed without verified human authority at the moment of execution.
The ECB is now telling European banks that AI can generate working exploits and compress attack timelines to minutes. The industry response is to run the downstream controls faster. GoFirm’s position is that the correct intervention is upstream at the execution boundary, before the action that causes the damage, not after.
The banking sector already proved this model works. Every retail bank in Europe confirms every significant transaction with the account holder on their personal device before it executes. That single upstream control has prevented more fraud than any downstream detection system. The ECB is now asking those same banks to apply the same rigour to their own internal operations - to their infrastructure changes, their privileged access events, their agentic AI workflows, their high-consequence decisions.
GoFirm provides that control. Before any consequential action executes - a wire transfer, a privilege escalation, a production deployment, an AI agent decision above a configured threshold - GoFirm routes a confirmation request to the named human authority on their registered personal device, through a channel entirely separate from the operational environment. The authority confirms with their biometric. The action proceeds or it does not. Every confirmation is signed, timestamped, and written to an immutable audit trail.
The ECB wants banks to demonstrate that controls are effective. An immutable record of confirmed human authority at the moment of every consequential execution is the most direct demonstration available. Not a policy document. Not a penetration test report. Cryptographic proof that the right person authorised the right action at the right time - created at the moment it happened, not reconstructed afterwards.
The exploit window is thirty minutes. The downstream controls are accelerating. The upstream boundary still doesn’t exist for most organisations.
That is the gap GoFirm closes.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. ECB tells banks to invest in cybersecurity due to AI risk, Blockchain Council, May 2026, reporting on ECB supervisory meeting, week of 25 May 2026
