Two weeks ago, U.S. Treasury Secretary Bessent and Federal Reserve Chair Powell held a closed-door meeting with Wall Street executives — a clear sign of how real the Mythos threat has become.
But that meeting was not the end. What followed was on a much larger scale.
What central bank governors are saying
Bank of England Governor Andrew Bailey called it "a very serious challenge for all of us" and demanded an immediate regulatory assessment.
European Central Bank President Christine Lagarde was more direct: "if it falls in the wrong hands, it could be really bad."
IMF Deputy Managing Director Dan Katz said cybersecurity threats would be "absolutely essential on the international agenda" in the coming months.
These are people whose daily job is managing global financial stability. They do not normally say things like "if it falls in the wrong hands it could be really bad" in public. That they did means what they have seen internally is genuinely troubling.
The background is straightforward: Anthropic found that Mythos can autonomously discover and chain together software vulnerabilities at a speed and scale beyond human capability. Tests showed it "found thousands of high-severity vulnerabilities, including some in every big operating system and web browser." Nearly every major operating system and browser contained previously unknown security flaws that it uncovered.
Anthropic's approach was to lock access to about 40 companies — including Amazon, Apple, and JPMorgan Chase — so these organizations could test and patch vulnerabilities first. The logic is reasonable. The question is what happens to everyone else.
Asia reacted fastest
Singapore: The Monetary Authority of Singapore and the Cyber Security Agency jointly directed financial institutions to "redouble efforts to strengthen their security defenses, pro-actively identify and close vulnerabilities." Not waiting for assessments — immediate action.
South Korea: Financial regulators and industry bodies held an emergency joint meeting specifically to address cyber threats from AI technology. Security Committee Chair Lee Won-tae delivered the most direct statement of the period:
"We have entered an era where AI, not humans, holds the initiative in hacking."
The offense-defense relationship has flipped. Previously humans led vulnerability discovery; now AI is ahead. This is not a metaphor — it is a literal description of Mythos's actual capability.
Australia: More low-key, but it also required financial services firms to maintain "sufficient safeguards" and coordinate with other regulators to assess emerging technology.
Europe's problem: wants to test, but cannot
There is a strange dilemma here.
European regulators know Mythos poses a threat and want to independently assess the risk. But Anthropic's list of 40 access recipients includes very few European institutions.
European Banking Authority (EBA) Chair François-Louis Michaud described the assessment work as "a process that is starting" — still in its early stages. By comparison, the U.S. has already held its closed-door meeting, Singapore is acting, and South Korea has convened an emergency session.
This is an information asymmetry problem. European regulators cannot independently judge the threat level because they have no first-hand access to the model. They must either trust the information Anthropic provides or rely on speculation.
Anthropic's "limited access" strategy has an unintended side effect: the organizations with the most first-hand information — Amazon, JPMorgan, and others — either have strong security teams or deep partnerships with Anthropic, while the governments and international bodies that truly need independent regulatory oversight are left out.
JPMorgan's two-sided view
JPMorgan CEO Jamie Dimon offered a relatively balanced take: AI increases the risk of cyberattacks, but also provides better defensive tools.
That assessment is partly correct. Both offense and defense will be upgraded by AI.
But the critical question is whether the speed is symmetrical. If attackers can get Mythos-level models faster — through state actors or underground channels — while defenders wait in line for Anthropic approval, the offense-defense balance breaks. Anthropic's current strategy is "give it to trusted institutions first, let them patch vulnerabilities." Whether this chain can move faster than attackers is the real question.
Without a global coordination framework, what can be done
The current state: each country or region uses its own framework to address a global threat, information sharing is fragmented, and geopolitical tensions make international coordination harder.
Some regulators have already acknowledged that building a unified global AI safety response mechanism is nearly unrealistic — interests are misaligned, transparency requirements vary, and political sensitivities differ.
The financial system is one of the most systemic targets. Banks are highly interconnected; a vulnerability in one node can cascade. That is why central bank governors are taking this more seriously than typical AI news.
They are not talking about the future of AI. They are discussing a model that already exists, a capability that has already been verified, and a threat for which there is currently no complete response plan.
Sources: Latest AI models could threaten world banking system, financial officials warn (The Irish Times); CocoLoop, Asia Regulators Raise Scrutiny on Banks Amid Mythos AI Fears (Insurance Journal)