The Bank of England is convening senior bank and insurer executives this week. Regulators want to know how firms are preparing for the cyber risks tied to Anthropic’s new AI.
Regulators move quickly
The Bank of England has scheduled talks with the heads of major banks and insurance firms to discuss preparations for potential cyber threats linked to Anthropic PBC’s new model, Mythos. The meeting follows similar urgent sessions held by US authorities, where Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell summoned Wall Street leaders to outline concerns. Regulators are treating this as an immediate operational problem, not just a theoretical one.
Officials have told banks to harden their defences now against this risk.
In Washington, Bessent and Powell gathered executives from systemically important banks at Treasury headquarters to stress the need for stronger defences and awareness of a new class of threats. Those US sessions were organised on short notice and included lenders already in town for a Financial Services Forum meeting, according to reporting. The presence of the Fed chair made clear the focus was systemic risk, given the Fed’s role supervising large banks and its network of examiners.
Across the Atlantic, the Bank of England has picked up the same thread and called its own meetings. The central bank will meet industry leaders to discuss how they’re preparing and what additional steps might be needed to protect critical systems.
What Mythos does
Anthropic has said Mythos is a more powerful model than previous releases and that, when directed, it can identify and then exploit vulnerabilities across major operating systems and web browsers. Anthropic has limited wider access to the system for now, releasing it first to a small set of tech and finance partners under what the company calls Project Glasswing. Project Glasswing includes firms such as Amazon.com Inc., Apple Inc. And JPMorgan Chase & Co., according to reporting.
Anthropic has been cautious in its rollout of the model.
Regulators worry that if the model can find and exploit software flaws, attackers could use it to probe and attack financial systems quickly and at scale. That makes people wonder about incident detection, response plans and the robustness of third-party software used across banks. And those questions are the reason central banks and finance ministries are pulling executives into meetings rather than waiting for tests or incidents to happen.
But the industry faces a real trade-off. Firms want to understand powerful tools that might boost security or operations, but they also need to prevent the same tools becoming an attack vector. Some of the companies invited into early trials are both potential users and potential partners on hardening efforts, which complicates how firms and regulators coordinate information-sharing and safeguards.
How banks were told to prepare
Officials in Washington urged senior bank leaders to assess their exposure and step up cyber defences, according to people briefed on the meetings. The US sessions focused on ensuring banks were aware of possible future risks and taking precautions to defend their systems, rather than on singling out any one firm or product.
That approach is mirrored in Canada. Bloomberg reported the Bank of Canada convened meetings with major domestic banks and financial firms to discuss the same Mythos-related cybersecurity risks. So Canadian institutions have already been pulled into the conversation about how to respond if highly capable AI tools fall into hostile hands.
Regulators are asking for concrete, operational measures. They’re asking banks to review how they manage software vulnerabilities, to test detection and response routines, and to evaluate the security of vendor code and cloud services. Those are standard parts of cyber resilience, but the new emphasis is on scenarios where AI could automate vulnerability discovery and exploitation — making attacks faster and harder to trace.
Firms are being urged to update playbooks and run tabletop exercises that imagine AI-augmented attackers. Some banks with in-house security teams are also being asked to map out dependency chains for critical infrastructures, so they can understand what a successful exploit of a single component might mean for core services.
Industry reaction and next steps
Executives summoned to the US meeting included leaders of banks deemed systemically important by regulators, meaning their stability is a priority for the global financial system.
That group’s attendance signalled the authorities’ aim: to get senior decision-makers involved, not just technical teams. Jerome Powell’s participation showed the Fed wanted the discussion to land at the highest managerial level.
Anthropic’s own caution — restricting Mythos access to a select set of partners — has so far aligned with regulators’ concerns. The company’s controlled rollout was described as a deliberate step to limit public exposure until safety and security questions are addressed.
But the meetings make clear regulators aren’t content to wait. They’re pushing firms to shore up defences and to share assessments with supervisors. At the same time, companies involved in Project Glasswing may be asked to cooperate on threat modelling and mitigation strategies that could inform broader industry guidance. That raises governance questions about how much information companies can share without exposing proprietary details or opening new vulnerabilities.
Right now, central banks and finance ministries are running two tracks: short-term tactics to cut immediate exposure and longer-term reviews to see if rules or industry standards must change. The short-term push looks like more frequent supervisory outreach and scenario testing. The longer-term work could end up shaping how highly capable AI systems are assessed and authorised for use in critical sectors.
What this means for Canadian firms
Canadian authorities have already shown they’re engaged. This Bank of Canada’s meeting with major banks and financial firms means domestic institutions are part of multinational coordination on AI-related cyber risks. That dialogue will influence supervisory expectations in Canada, even if Ottawa or the central bank doesn’t impose new mandatory controls immediately.
Canadian banks will likely face increased scrutiny over vendor risk management, incident response readiness and software patching practices. They’ll also be encouraged to participate in cross-border information-sharing exercises, since cyber threats that exploit AI capabilities can propagate quickly across jurisdictions.
Historically, regulators tighten oversight after new technologies reveal systemic weaknesses. The arrival of Mythos has pushed that clock forward for bank supervisors in multiple countries. What’s different this time is the pace — models can probe systems at machine speed, and defenders worry that manual controls alone won’t be enough to keep up.
Some firms are already leaning into defensive uses of AI to accelerate threat detection and to triage responses. Others are proceeding cautiously, wanting clearer guardrails before deploying or testing models that could both help and harm security. Balancing innovation and defence is at the centre of current regulator-industry talks.
Related Articles
National Economic Council Director Kevin Hassett said, "There’s definitely a sense of urgency."
This article was created with AI assistance.