Overview
- OSFI sent an urgent warning to chief technology, security and risk officers on April 29 that Anthropic’s Claude Mythos compresses the timeframe for effective risk mitigation, according to documents reported by multiple outlets.
- Claude Mythos is a specialised model built to scan code for vulnerabilities at machine speed, and banks that tested it through limited pilots reported uncovering hundreds to thousands of previously unknown flaws that triggered emergency patching.
- Regulators in the United States, United Kingdom, the EU and Japan have held meetings or issued alerts about Mythos, signalling a coordinated cross-border supervisory response to the new AI-driven cyber risk.
- Anthropic acknowledges the technology’s dual-use nature and said its review of banned malicious accounts showed AI is helping attackers become more effective, a concern that extends to smart contracts and other public crypto code.
- The immediate effects include large remediation workloads for banks, pressure to upgrade aging systems, and likely growth in demand for AI-based security tools as institutions and regulators tighten governance and access controls.