8 Sources
[1]
India orders infosec red alert in case Mythos sparks crime
Securities regulator urges market players to develop new strategies and nail cyber-basics before AI models fuel mass attacks India's Securities and Exchange Board has advised participants in the nation's equities industry to immediately revisit their information security systems and practices, in
[2]
Australia regulator calls for urgent cybersecurity action to counter Mythos
SYDNEY, May 8 (Reuters) - Australia's corporate regulator has urged the country's financial sector to take urgent action on tackling potential cyber risks from frontier AI systems such as Mythos. The Australian Securities and Investments Commission on Friday published a letter sent to the
[3]
Australia regulator calls for urgent cybersecurity action to counter Mythos
Australia's corporate regulator warns financial firms about new cyber threats from advanced AI systems. These powerful AI models can find security weaknesses quickly. Regulators stress the need for immediate action to strengthen cybersecurity. Financial institutions are adopting AI faster than
[4]
Anthropic's Mythos: What Investors Should Watch
Anthropic built a model it decided was too dangerous to release. What happened next is a case study in how fast AI risk has become a financial stability problem. On April 7, 2026, Anthropic announced an AI model it refused to sell. That decision alone was unusual. What followed was not. Within
[5]
Banks Slash Patch Times as Anthropic's Mythos Exposes Security Gaps | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. One thing the banks have learned is that Mythos can create a high-risk
[6]
SEBI Orders Cybersecurity Overhaul Over Mythos Concerns
The Securities and Exchange Board of India (SEBI) has named Anthropic's Claude Mythos in a circular dated May 5, ordering every regulated entity in Indian securities markets to immediately overhaul their cybersecurity infrastructure. SEBI is the first Indian financial markets regulator to name a
[7]
Anthropic's Mythos sends US banks rushing to plug cyber holes
NEW YORK, May 12 (Reuters) - U.S. banks are rushing to fix scores of IT system weaknesses flagged by Anthropic's powerful but costly Mythos AI tool, prompting urgent repairs, software upgrades and raising the possibility of disruption for customers. A handful of the country's largest lenders
[8]
Australia regulator calls for urgent cybersecurity action to counter Mythos
SYDNEY, May 8 (Reuters) - Australia's corporate regulator has urged the country's financial sector to take urgent action on tackling potential cyber risks from frontier AI systems such as Mythos. The Australian Securities and Investments Commission on Friday published a letter sent to the
Share
Copy Link
Financial regulators across India, Australia, and the US are issuing urgent cybersecurity warnings as Anthropic's Mythos AI model reveals an unprecedented ability to identify security vulnerabilities. The bug-finding AI has uncovered tens of thousands of flaws, some decades old, prompting emergency meetings and forcing banks to slash patch times from weeks to days.
Anthropic's Mythos has triggered an unprecedented global response from financial regulators who warn that cybersecurity has entered a dangerous new phase. India's Securities and Exchange Board of India issued a red alert advisory on Tuesday, directing 19 different classes of financial entities—from venture capitalists to stock exchanges—to immediately revisit their information security systems and practices
1
. The regulator established a taskforce to examine AI-related risks, share threat intelligence, and review cybersecurity at third-party vendors who supply the industry.
Source: The Register
Australia followed with its own urgent warning. ASIC commissioner Simone Constant published a letter to the financial services industry on Friday stating that "cyber risk has entered a new era, the advent of frontier AI models creates opportunity but also materially increases risk, with the ability to expose vulnerabilities faster than many realise"
2
. She emphasized that organizations should not wait for perfect clarity, urging them to "act now, and act with discipline, to strengthen the cyber resilience fundamentals." Her stark warning that "the clock is at a minute to midnight" underscores the urgency regulators feel about these advanced AI models3
.The scale of security vulnerabilities discovered by Mythos is staggering. While an earlier Anthropic model found approximately 20 vulnerabilities in Firefox, Mythos identified nearly 300 in the same browser
4
. Across major operating systems and web browsers, the total now runs into tens of thousands of flaws, many dating back 10, 20, or even 27 years. Anthropic CEO Dario Amodei explained the company's cautious approach: "If we announce something without it being fixed, then the bad guys will exploit it."Banks testing Mythos through Project Glasswing have discovered that the AI can create high-risk vulnerabilities by combining several lower-risk weaknesses. The number of low- to moderate-ranked vulnerabilities found in banks' technology ranges from several hundred to thousands
5
. This capability for identifying complex attack vectors represents a fundamental shift in how cyber threats must be assessed and managed.On April 7, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened an unannounced emergency meeting at Treasury headquarters with CEOs from Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs to discuss Mythos and the cyber threats it represents
4
. The International Monetary Fund issued a formal warning shortly after, citing Mythos by name and cautioning that AI-driven cyberattacks could threaten global financial stability. The IMF raised particular concern about concentration risk—where banks, payment networks, and energy firms share the same cloud providers and software platforms, meaning one exploited vulnerability could cascade across the entire financial system.Bessent stated on May 3 that American banks should take the Mythos model seriously and use it to find holes in their defenses, noting that "what we've had in the past month was a step change in the power of one large language model"
5
.
Source: MediaNama
The threat mitigation timeline has compressed dramatically. Organizations traditionally take 60 days to patch critical vulnerabilities after disclosure, while attackers exploit those same flaws within an average of 4.5 days of a public proof of concept appearing—leaving a 55-day exposure window
4
. According to Mandiant's M-Trends 2026 report, nearly 28% of known vulnerabilities now face active exploitation within 24 hours of public disclosure.In response, banks are patching vulnerabilities in days rather than weeks and upgrading technology at the end of its software support
5
. Some institutions may take systems offline more frequently to handle the increased workload, though they aim to do so in the least disruptive ways possible.Related Stories
Anthropic chose not to release Mythos publicly, instead launching Project Glasswing with roughly 40 organizations receiving monitored access to find and fix vulnerabilities before attackers can exploit them
4
. Partners include Amazon, Apple, Microsoft, Alphabet, Nvidia, Cisco, CrowdStrike, JPMorgan Chase, and Palo Alto Networks. Anthropic committed up to $100 million in usage credits and $4 million in donations to open-source security organizations.
Source: PYMNTS
For organizations without Mythos access, Anthropic offers the Claude Security program, which scans for vulnerabilities and is available to a broader range of entities
5
. However, Dario Amodei warned on May 5 that financial services companies have only six to 12 months to fix vulnerabilities before Chinese AI models develop capabilities equal to Mythos, while other frontier AI systems sit just one to three months behind5
.India's advisory directed financial entities to ensure patches remain current, conduct vulnerability audits, secure APIs, operate serious security operations centers, and adopt zero-trust networking principles
1
. The regulator also instructed IT committees to develop plans for using AI as part of their information security arsenal and to undertake "AI-augmented SOC transformation" and continuous vulnerability management using AI tools.A concerning gap has emerged between financial institutions and their supervisors. Financial institutions are adopting AI at more than twice the rate of their regulators, with just two in 10 financial regulators reporting "advanced AI adoption," according to research published in April by the Cambridge Centre for Alternative Finance
2
. This disparity raises questions about the ability of central banks and financial regulators to monitor and combat AI-related risks effectively, as authorities significantly lag financial firms in AI adoption and lack data on emerging harms.Summarized by
Navi
[1]
[4]
20 Apr 2026•Policy and Regulation

11 May 2026•Policy and Regulation

13 May 2026•Technology

1
Science and Research

2
Technology
3
Technology