Anthropic to Brief FSB on AI Cyber Threats From Mythos

 

AI startup Anthropic will present findings from its unreleased Mythos model to G20 finance ministries and central banks coordinated by the FSB.

 

Anthropic brief on AI cyber threats | Illustration

 

Anthropic Summoned to Warn G20 Financial Regulators on Mythos Cyber Risk

 

Anthropic is set to brief the Financial Stability Board on cyber vulnerabilities in the global financial system identified by its latest AI model, Mythos, the Financial Times reported on Monday, citing people familiar with the plan.

 

The briefing was requested by Bank of England Governor Andrew Bailey, who chairs the FSB — an international body responsible for coordinating financial regulations for G20 economies — and will be delivered to senior officials from leading finance ministries and central banks. 

 

The planned briefing closes a regulatory arc that began with Bailey's April 15 speech at Columbia University in New York, in which he named Mythos explicitly, describing it as one of two developments that had moved cyber risk up regulators' rankings faster than any other category in recent years.

 

Speaking at that event, Bailey said: "It would be reasonable to think that the events in the Gulf are the most recent challenge to us in this world, until, I think it was last Friday, you wake up to find that Anthropic may have found a way to crack the whole cyber risk world open. The issue is: to what extent is this new version of the product going to be able to, in a sense, identify vulnerabilities in other systems which can be exploited for cyber attack purposes."

 

Mythos: An Unreleased Model With Unprecedented Exploit Capabilities

 

Anthropic announced Claude Mythos Preview on April 7, describing it as a general-purpose, unreleased frontier model that had already identified thousands of high-severity vulnerabilities, including in every major operating system and web browser. The company disclosed that over 99 percent of the vulnerabilities found had not yet been patched at the time of announcement, citing its coordinated vulnerability disclosure process as the basis for withholding further technical detail.

 

Internal evaluations showed that Anthropic's previous model, Claude Opus 4.6, had a near-zero percent success rate at autonomous exploit development. Mythos Preview, tested against the same Firefox JavaScript engine benchmark, developed working exploits 181 times out of several hundred attempts, compared to two successes by Opus 4.6.

 

The UK's AI Security Institute evaluated Mythos and found it to be the first AI model to complete a full end-to-end cyber-range attack, succeeding in taking over a simulated corporate network in three out of ten attempts. In Anthropic's own internal testing, when directed to develop working exploits against identified flaws, the model succeeded on the first attempt in more than 83 percent of cases.

 

Among the specific vulnerabilities disclosed were a 27-year-old flaw in OpenBSD's TCP stack and a 16-year-old bug in FFmpeg's H.264 codec. Anthropic also disclosed that Mythos found vulnerabilities in TLS, AES-GCM, and SSH implementations within major cryptography libraries, including bugs capable of enabling certificate forgery or the decryption of encrypted communications.

 

Emergency Meetings Across Three Continents Precede FSB Briefing

 

On April 7, US Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened an urgent, closed-door meeting with the chief executives of some of the nation's largest banks to discuss the cybersecurity risks posed by Mythos. The banks invited were those designated as systemically important, meaning disruption at any one of them could have broader consequences for the global financial system.

 

The presence of Powell was described by people familiar with the matter as significant, as the Federal Reserve chair typically preserves a clear separation from the Treasury; his attendance signalled the issue was being treated as a systemic financial stability concern rather than a technology policy matter.

 

Bank executives in attendance included Jane Fraser of Citigroup, Brian Moynihan of Bank of America, Ted Pick of Morgan Stanley, Charlie Scharf of Wells Fargo, and David Solomon of Goldman Sachs, according to The Next Web.

 

JPMorgan Chase CEO Jamie Dimon did not attend but JPMorgan is listed as a launch partner in Anthropic's associated initiative.

 

In the United Kingdom, the Bank of England, the Financial Conduct Authority, and HM Treasury entered urgent contact with the National Cyber Security Centre and engaged directly with major banks, insurers, and financial exchanges on cybersecurity concerns linked to Mythos. Germany's Federal Office for Information Security also engaged Anthropic directly.

 

BSI President Claudia Plattner confirmed: "We are in contact with the manufacturer Anthropic with respect to Claude Mythos," adding that the agency was taking Anthropic's announcements "very seriously" and that the development "raises questions of national and European security and sovereignty."

 

Project Glasswing and the $100 Million Defensive Initiative

 

In response to the risks identified by its own model, Anthropic launched Project Glasswing, extending controlled access to Mythos Preview to approximately 40 organisations that build or maintain critical software infrastructure, enabling them to scan and secure both first-party and open-source systems. The 12 named launch partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Anthropic committed up to $100 million in Mythos usage credits across the initiative, along with $4 million in direct donations to open-source security organisations.

 

Goldman Sachs CEO David Solomon confirmed during a quarterly earnings call that the bank had obtained access to Mythos and had begun using it for defensive purposes, stating: "We're hyper-aware of the enhanced capabilities of these new models. We have the model. We're working closely with Anthropic and all of our security vendors to harness frontier capabilities wherever it's possible."

 

JPMorgan Chase CEO Jamie Dimon offered a more cautionary assessment, warning analysts that AI had made cyber risk "worse" and "harder" while acknowledging that Mythos had revealed the scale of patching required across financial systems.

 

A Treasury spokesperson confirmed that Secretary Bessent had convened the bank CEO meeting to address developments in AI and that Treasury plans to lead further such meetings with regulators and institutions on an ongoing basis.

 

Anthropic also announced a commitment to report publicly within 90 days on discovered vulnerabilities that have been fixed and on improvements that can be disclosed, alongside plans to collaborate with security organisations to produce practical recommendations on how security practices should evolve in the era of powerful AI models.

 

AI Informed Newsletter

Disclaimer: The content on this page and all pages are for informational purposes only. We use AI to develop and improve our content — we love to use the tools we promote.

Course creators can promote their courses with us and AI apps Founders can get featured mentions on our website, send us an email. 

Simplify AI use for the masses, enable anyone to leverage artificial intelligence for problem solving, building products and services that improves lives, creates wealth and advances economies. 

A small group of researchers, educators and builders across AI, finance, media, digital assets and general technology.

If we have a shot at making life better, we owe it to ourselves to take it. Artificial intelligence (AI) brings us closer to abundance in health and wealth and we're committed to playing a role in bringing the use of this technology to the masses.

We aim to promote the use of AI as much as we can. In addition to courses, we will publish free prompts, guides and news, with the help of AI in research and content optimization.

We use cookies and other software to monitor and understand our web traffic to provide relevant contents, protection and promotions. To learn how our ad partners use your data, send us an email.

© newvon | all rights reserved | sitemap