Banking industry scrambles for Anthropic鈥檚 Mythos as global regulators review risks

FRANKFURT/NEW YORK 鈥 The emergence of Anthropic鈥檚 Mythos is setting up a scramble from the banking industry to gain access and test the technology as regulators rush to examine the cybersecurity risks the new artificial intelligence model raises and how prepared financial firms are to tackle them.
Mythos is viewed by cybersecurity experts as posing significant challenges to the banking industry and its legacy technology systems, prompting a series of warnings from regulators and policymakers gathered at last week鈥檚 International Monetary Fund spring meeting in Washington. A string of US banks have so far been given access to Mythos 鈥 while the rest of the industry tries to catch up.
鈥淚t鈥檚 certainly not something that鈥檚 causing panic or setting off any alarm bells on our end right now, but it鈥檚 definitely something we need to keep in mind in our day-to-day risk management 鈥 and that鈥檚 exactly what we鈥檙e doing,鈥 Deutsche Bank CEO Christian Sewing, who leads Germany鈥檚 biggest bank, told journalists. Mr. Sewing said banks were in close contact with European watchdogs about Mythos.
鈥淭he banks are prepared for this and have their own responses. So this is something we have to live with, and of course everyone is trying to gain access, but I also think it鈥檚 right that access is limited for now,鈥 he said, adding that a German banking association would discuss the issue on Monday.
Anthropic has so far restricted access to the model to partners in its Project Glasswing initiative and about 40 additional organizations that build or maintain critical software infrastructure. JPMorgan, which is part of Glasswing, was the only bank Anthropic has publicly said has access, although Bank of America has been part of Glasswing since the start and has been testing the Mythos technology internally, according to a source familiar with the matter.
Other US banks have more recently said they have been given access to Mythos.
Morgan Stanley CEO Ted Pick told analysts during the bank鈥檚 earnings call last week that the bank has been discussing cyber risks within the Financial Services Forum. 鈥淎nd yes, we are permissioned on Claude Mythos Preview,鈥 he said, adding that cyber risk is an increasing threat. 鈥淪o we will, I imagine, collectively get better via that, and then there will be other competitive products.鈥
Goldman Sachs CEO David Solomon also confirmed during the bank鈥檚 earnings last week that it had access.
鈥淲e鈥檙e aware of Mythos and its capabilities,鈥 Mr. Solomon said on the call. 鈥淲e have the model. We鈥檙e working closely with Anthropic and all of our security vendors to kind of harness frontier capabilities wherever it鈥檚 possible.鈥
Citigroup also has access to Mythos and is using it for internal tests, one person with knowledge of the matter said.
Some banks without access have questioned whether there should be broader access to Mythos and whether JPM received an advantage, a topic that is likely to be raised with the US Treasury, a source familiar with the matter said. JPM declined comment. The Treasury and Anthropic did not immediately respond to requests for comment.
Multiple senior banking and regulatory sources in Europe told Reuters they were not aware of any European financial institution with access to Mythos yet.
鈥楽UBSTANTIALLY MORE CAPABLE AT CYBER OFFENSE鈥
The British government wrote an open letter to Anthropic leaders on April 15 saying that testing by its AI Security Institute had shown Mythos to be 鈥渟ubstantially more capable at cyber offense than any model we have previously assessed.鈥
Some Asian regulators said on Monday they were also monitoring the development. South Korea鈥檚 Financial Supervisory Service said it met with information security officials from financial firms last week to review Mythos-related risks.
Mythos was a key topic on the sidelines of the IMF meetings last week. European supervisors are not yet overly concerned and for now are assessing it through their existing cyber resilience processes, three European supervisory sources told Reuters.
One banking source said the ECB and other regulators have been in contact with European banks to assess their preparedness for new cybersecurity risks. Supervisors have asked about banks鈥 awareness of the threat and their ability to respond, the source said.
The capabilities of Mythos to code at a high level have given it a potentially unprecedented ability to identify cybersecurity vulnerabilities, experts say, prompting greater scrutiny from regulators globally.
Barclays CEO C.S. Venkatakrishnan said on Friday in Washington that Mythos was a serious threat to the global banking system and likely to be followed by similar, more powerful cyberthreats. 鈥 Reuters


