Regulation

ECB and Japan Mobilize Against Cyber Risks Posed by Anthropic’s Mythos AI

The European Central Bank is developing defensive measures to guard eurozone banks against cyberattacks potentially enhanced by Anthropic’s Mythos model, while Japan has set up a public–private working group to assess and mitigate risks to its financial system.

The European Central Bank (ECB) is preparing defensive measures to address cyber risks associated with Anthropic’s Mythos artificial intelligence model. Christine Lagarde, President of the ECB, spoke at an event in Spain about the issue: Mythos was originally developed to discover vulnerabilities in computer code, but cybersecurity experts warn it could substantially increase the effectiveness of attacks on banking IT systems.

Lagarde noted that access to the model is currently restricted to US companies, a situation she said creates unequal competitive conditions between the United States and the rest of the world. The ECB is therefore working on countermeasures, including planning for scenarios in which a hostile state actor — which would require substantial computing capacity — obtains access to the model.

Bank supervision teams have begun assessing eurozone banks’ preparedness, examining how well institutions can defend against threats posed by new-generation, cybersecurity-focused AI models. The European Commission also said earlier in the week that Anthropic had briefed it on Mythos’s capabilities, and officials are examining how the model could affect EU policies and regulations.

Japan forms public–private working group

Japan has reacted quickly as well. Finance Minister Katajama Szacuki announced the formation of a working group that will include public and private sector participants to address the cybersecurity risks Mythos poses to the financial system. The announcement came on the same day Katajama met in Tokyo with US Treasury Secretary Scott Bessent.

According to the Financial Services Agency (FSA), the working group will hold its first meeting on Thursday with a total of 36 participants. Members include major banks, internet banks, representatives of the Bank of Japan, and the Japanese divisions of Anthropic and OpenAI. The session will be led by Terai Osamu, head of IT security at Mizuho Financial Group.

The group will discuss procedures to follow when vulnerabilities are discovered, necessary defensive measures, and incident-response plans for threats that cannot be fully mitigated. The FSA is also considering sharing information with US and other foreign authorities.

Anthropic limits access and launches Project Glasswing

Anthropic has acknowledged that Mythos could be misused, and has therefore made the model available only in closed test environments to a limited set of users. The company has launched Project Glasswing, offering restricted access to a limited number of organizations for defensive purposes. The FSA says interest in the program is growing among Japanese banks, though no formal participation requests have yet been confirmed.

Why this matters

Notifications about Mythos and the responses from the ECB and Japan highlight how advanced AI tools can rapidly become strategic risks for financial infrastructure. The measures under way — readiness assessments, working groups, international information sharing and limited-access testing programs — aim to reduce the banking system’s vulnerability and ensure coordinated responses.

Related event

The topic will also be covered in detail in the cybersecurity session of the Financial IT conference on May 28.