SAN FRANCISCO—After CUToday.info reported that Anthropic was withholding public release of Claude Mythos Preview because of its cyber capabilities, Reuters is now reporting the more immediate risk for financial institutions may be how the model could turn the financial industry’s own legacy technology complexity into a force multiplier for AI-powered attacks.
Reuters reported experts now warn Mythos’ ability to rapidly identify and exploit vulnerabilities could be especially dangerous for FIs because they run a mix of modern systems and decades-old infrastructure, creating a broad attack surface that could be exploited faster than many institutions can patch or isolate.
Reuters said that risk is magnified by the banking sector’s shared reliance on a relatively narrow group of vendors and software platforms for functions such as onboarding, KYC and transaction processing. That means an AI model capable of autonomously surfacing and chaining together vulnerabilities across complex environments could make breaches not only more likely, but potentially more scalable across multiple institutions at once, according to experts cited by Reuters.
That marks a notable escalation from the initial CUToday.info report, which focused on Anthropic’s decision to keep Mythos out of general release after the company said the model had already identified thousands of high- and critical-severity vulnerabilities across major operating systems and browsers. Reuters’ new reporting shifts the story from “too dangerous to release” to a more practical concern for financial institutions: whether AI-assisted offensive cyber capability is arriving faster than banks and credit unions can modernize aging infrastructure.
Reuters said government officials in the U.S., Canada and Britain have already met with senior banking officials to discuss the threat, while the U.S. Treasury said the Administration is pushing financial institutions to better understand a range of market developments tied to the issue and plans further meetings. Anthropic, meanwhile, is continuing to restrict access through Project Glasswing, with firms including JPMorgan Chase privately evaluating the model for defensive purposes rather than opening it to the public.
