Anthropic to Brief Global Regulators on Vulnerabilities Its AI Found in Financial System

An unreleased Anthropic model has found thousands of security holes across the global financial system, and the world’s top financial regulators now want to hear about them directly. Anthropic has agreed to brief the Financial Stability Board on the vulnerabilities, the Financial Times reported Monday, citing people familiar with the plan. The briefing, requested by Bank of England Governor Andrew Bailey, who chairs the FSB, will reach the finance ministries and central banks of the G20 economies that make up the board.

The session marks the first time the global financial supervision community has coordinated a response to a single AI model’s security findings, according to people familiar with the matter. An FSB spokesperson said the body “welcomes engagement with Anthropic and other firms on emerging and frontier risks to global stability.” Reuters could not immediately verify the report, and Anthropic declined to comment.

Mythos, announced last month as a preview, has not been publicly released. Anthropic describes it as a cybersecurity model designed to surface long-standing vulnerabilities in browsers, infrastructure and software, and the company says it has found thousands of high-severity flaws across major operating systems and browsers. In internal testing, when directed to develop working exploits against those flaws, the model reportedly succeeded on the first attempt in more than 83% of cases. It is the first publicly disclosed AI system that, on its developer’s own account, has found exploitable vulnerabilities in every major operating system and web browser.

The dual-use implications drew regulators’ attention before the model went on the road: the same capability that lets defenders find and patch holes can, in the wrong hands, be pointed at them. Anthropic has kept Mythos out of general release, making it available only through “Project Glasswing,” a controlled-access program that limits who can run the model and against what. Roughly 40 to 50 organizations have early access, including AWS, Apple, Google, Microsoft, Nvidia, Cisco and JPMorgan, according to reports.

Banks running legacy technology are a particular concern, according to cyber experts cited by the FT: systems that have resisted conventional security testing may be exactly where an AI-driven search finds its next target. A group of technology companies and banks — including Apple and JPMorgan — have been given access to help identify weaknesses the model may locate in their systems.

The financial system is a concentrated target. A handful of core payment networks, clearinghouses and large banks process most of the world’s money, and much of that plumbing runs on software written decades ago. If a model can enumerate exploitable flaws across that stack, the finding is a public-welfare warning and a potential attack blueprint at the same time. That tension is why the FSB — a body that normally speaks through policy papers rather than model briefings — moved the issue onto its agenda.

Bailey first put the issue on the public record in a speech at Columbia University, where he asked how much harder AI had made the attack side of cybersecurity relative to the defense side. UK banks were given their own briefing within days of those remarks, and the Federal Reserve and U.S. Treasury convened the chief executives of major American banks on the same risk shortly afterward. Australia’s securities regulator and euro-area finance ministers have raised access demands of their own, according to people familiar with the discussions.

The FSB session is the first time those requests are being coordinated rather than handled country by country. What it will not resolve, at least immediately, is the access question: bank supervisors outside the Glasswing list have been pressing for either direct access to Mythos or a regulator-mediated equivalent, and the briefing will put that issue squarely before the board.

The briefing comes as the FSB prepares a report on robust practices for the use of AI in the financial system, which it plans to publish next month for consultation — a document that will now be read with Mythos’s findings in mind. The central question Bailey has raised is whether financial firms using legacy infrastructure can adapt quickly enough to an attack surface that AI has widened.

There is also a political dimension. Mythos is a U.S.-headquartered system whose distribution and military access have separately been the subject of an ongoing dispute between Anthropic and the Trump administration, a context regulators on the receiving end of the briefing are likely to be aware of. The company has declined to release Mythos publicly, and the timing of the actual FSB briefing has not been disclosed. Whatever the session resolves about the model’s findings, the access question will remain open: the briefing turns a technical discovery — an AI that can find exploitable flaws across the global financial system — into a governance test for how regulators share and respond to AI-generated security information.

Related Posts

  • September 6, 2026
  • 6 views
Anthropic Moves Its IPO Filing to Late September

The bankers and lawyers running Anthropic’s initial public offering had told investors to expect the company’s registration documents as soon as this week. The calendar has moved. Anthropic now plans…

  • September 6, 2026
  • 6 views
OpenAI Quietly Revises GPT-6 Astra Scores After Launch

When OpenAI released GPT-6 Astra on Sept. 3, the launch post carried the usual furniture of a modern model debut: coding results, speed comparisons and a figure for how often…