Japan's megabanks to access Anthropic Mythos AI as cybersecurity concerns mount globally

4 Sources

Share

Japan's three largest banks—MUFG, Mizuho, and Sumitomo Mitsui—will gain access to Anthropic's vulnerability-hunting AI model Mythos by the end of May. This marks the first Japanese entry to the restricted rollout, which has uncovered thousands of zero-day vulnerabilities across major operating systems and browsers. Japan is establishing a public-private working group to address the cybersecurity risks posed by this powerful AI model.

Japan Banks Join Restricted Anthropic Mythos Rollout

Japan's three largest banks are set to gain access to Anthropic's Mythos, the vulnerability-hunting AI model that has sent shockwaves through the global cybersecurity community, within approximately two weeks. Mitsubishi UFJ Financial Group (MUFG), Mizuho Financial Group, and Sumitomo Mitsui Financial Group will become the first Japanese institutions granted entry to the restricted preview, according to a person with direct knowledge of the matter

1

. The banking arms were informed of the decision during meetings with U.S. Treasury Secretary Scott Bessent in Tokyo this week, with onboarding expected by the end of May

2

.

This development marks a significant expansion of Anthropic's AI model Mythos beyond its initial American and European partners. The model has been confined to what Anthropic calls Project Glasswing, a controlled rollout involving 12 named launch partners including AWS, Apple, Cisco, Google, JPMorganChase, Microsoft, Nvidia, and Palo Alto Networks, plus around 40 additional institutions granted access on a case-by-case basis

2

.

Unprecedented Discovery of Software Security Vulnerabilities

Source: Market Screener

Source: Market Screener

Claude Mythos has been treated by regulators and chief executives as a category-shifting event since Anthropic disclosed its existence earlier this month. The model has discovered thousands of previously unknown zero-day vulnerabilities across every major operating system and every major web browser

2

. In internal testing, it wrote working exploits, including chains that escape both renderer and operating-system sandboxes in a browser. Mozilla shipped Firefox 150 last week with fixes for 271 vulnerabilities found by Mythos in a single evaluation pass

2

.

Cybersecurity experts view Anthropic's Mythos as posing significant challenges to the banking industry and its legacy systems, prompting a series of warnings from regulators and policymakers

1

. The model is designed for defensive cybersecurity tasks, but its capabilities have sparked fears about the threat to traditional software security

4

. Access to roughly 50 organizations globally had been restricted, including U.S. companies, American banks, and British government agencies

3

.

Japan Establishes Emergency Response Framework

Japanese Finance Minister Satsuki Katayama announced the formation of a 36-entity public-private working group to address cybersecurity risks to the Japanese financial system posed by Mythos

1

. The group comprises the country's major banks, the Bank of Japan, and the Japanese units of Anthropic and OpenAI, with its first meeting scheduled for Thursday

2

. Chaired by Mizuho's chief information security officer, the working group is charged with identifying exposures, implementing defensive measures, and drafting contingency plans for what would amount to a coordinated patching push across the Japanese financial system

2

.

Japanese Prime Minister Sanae Takaichi had instructed cabinet ministers to strengthen efforts to identify cybersecurity vulnerabilities in the country's infrastructure and reduce AI-related security risks, according to the Nikkei

3

. Tokyo had been pressing Washington for access to Anthropic's Mythos as Japan steps up cybersecurity efforts amid growing concerns over risks posed by cutting-edge AI systems .

Geopolitical Dimensions and Global Response

The geopolitical factors surrounding Mythos access are unusually visible. Bessent's role in conveying the access decision in Tokyo aligns Mythos rollout with U.S. Treasury statecraft rather than with Anthropic's commercial channel, an arrangement that has drawn complaints from European capitals

2

. Eurozone finance ministers raised the issue at an Ecofin meeting last week, where no EU government had access to the model while the White House was reported to be blocking further expansion of the partner list

2

.

For the three banks involved, the immediate question is operational. Mythos under Project Glasswing terms is delivered with restrictions on output disclosure, with the model used to find vulnerabilities in a partner's own systems and to draft remediation, not to publish exploits

2

. The Mozilla case offers a template: 271 vulnerabilities patched in a single Firefox release after a Mythos sweep, with the model's findings handed back to Mozilla engineers under non-disclosure rather than published

2

.

Industry views on Mythos remain split. Some cybersecurity researchers have argued that the cybersecurity vulnerabilities Mythos surfaced are reachable through clever orchestration of public models, and that the bigger story is the rate of improvement of frontier AI in offensive cyber, not Mythos itself

2

. Others, including Anthropic chief executive Dario Amodei, have described the moment as a "cyber moment of danger" that justifies the access controls .

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved