US officials and banking chiefs met over Mythos AI. They discussed cyber risks to the financial system.
What happened in Washington
Scott Bessent, US Treasury secretary, called a meeting at Treasury headquarters this week to discuss cyber threats tied to Anthropic’s new Mythos model. Jerome Powell, chair of the Federal Reserve, and the leaders of the biggest American banks were among those in the room.
The guest list focused on executives from systemically important banks — firms regulators say could endanger the wider economy if their systems were disrupted. David Solomon, chief executive of Goldman Sachs; Brian Moynihan, chief executive of Bank of America; Jane Fraser, chief executive of Citigroup; Ted Pick, chief executive of Morgan Stanley; and Charlie Scharf, chief executive of Wells Fargo, attended. Jamie Dimon, chief executive of JPMorgan Chase, was invited but couldn't make the meeting.
Officials held the meeting after Anthropic revealed internal analysis showing Mythos had found many software flaws. The session followed a public warning from Anthropic and an earlier leak of Claude's code that raised alarm in security circles.
What Mythos has revealed
Anthropic claims Mythos finds code vulnerabilities faster and more extensively than most human researchers.
In a public post, the company warned that AI models now beat all but the top experts at spotting and exploiting software flaws, which could seriously impact economies, public safety, and national security.
The startup restricted access to Mythos to a small group of corporate partners while it weighs the risks. Companies given early access include Amazon, Apple and Microsoft; networking and hardware firms Cisco and Broadcom also gained access, along with the Linux Foundation — the organisation that supports the open-source Linux operating system.
Anthropic told partners it had identified vulnerabilities going back decades — some reportedly as old as 27 years — that had not been previously flagged by their original creators or by outside monitors.
Why finance chiefs are on edge
Banks run vast, interconnected IT systems. They're also heavy users of widely deployed software libraries and cloud services — the same parts of the technology stack Mythos has been used to probe. That overlap makes the financial sector particularly sensitive to the discovery of previously unknown faults.
Jamie Dimon warned in his annual letter to shareholders that cybersecurity "remains one of our biggest risks", and wrote that "AI will almost surely make this risk worse". The tone of that message helps explain why regulators and bank leaders treated the Mythos findings as a potential systemic issue this week.
At the meeting, bank executives and regulators talked through various possible outcomes. Some worried that attackers could use AI tools to automate the search for credentials, reverse-engineer encryption protections, or chain multiple software flaws together to penetrate critical systems. Others focused on the potential for sudden, widespread failures if a widely used package were shown to contain deep, exploitable faults.
And they debated how to limit harm while allowing firms to develop and deploy artificial intelligence. The trade-off is clear: limiting models might slow innovation and hurt some firms, but releasing them without limits could give powerful cyber tools to bad actors.
State action and supply-chain concerns
US authorities have already taken steps. In recent weeks the US government designated Anthropic as a supply-chain risk, a move that signals official concern about how a single technology supplier could affect critical infrastructure.
Anthropic is contesting that designation in court, arguing its work is being unfairly framed as a security threat. The legal dispute runs alongside the private-sector effort to decide how much access to give AI systems and under what safeguards.
Economic and political implications
At stake is more than tech policy. A sustained wave of exploitable vulnerabilities could force banks to spend heavily on fixes, audits and new defensive tools. Those costs would hit profitability. They could also prompt lenders to re-evaluate their dependence on third-party software and cloud providers — a shift that could reshape vendor relationships and squeeze margins across the sector.
Regulators could push banks into tougher resilience standards, more frequent security testing, and more burdensome reporting rules. Central banks and finance ministries could ask the same of major technology providers, adding layers of oversight and possibly slowing product rollouts.
Politically, this episode has increased scrutiny on AI companies and their links to critical services. Governments want technology that helps growth and jobs. They also don't want tools that can be weaponised against infrastructure. These conflicting goals are sparking public debate, and the Mythos case has made the issue more urgent.
Global ripple effects and what it means for Australia
Although the meeting in Washington was US-focused, the implications are global. Large banks and cloud services operate across borders. Software vulnerabilities uncovered by an AI model don't respect national frontiers.
Australian banks and regulators rely on many of the same international vendors and software ecosystems named by Anthropic's tests. If Mythos points to previously hidden faults in widely used code, Australian financial institutions could face the same types of risk as their US peers. That would have operational consequences, and could raise costs for customers if institutions need to reinforce their defences.
Markets might also react. If investors see higher cyber risk for systemically important institutions, they could demand higher returns on bank bonds and equity. That would make it more expensive for banks to raise capital and could influence lending decisions over time.
Finally, the political conversation in Canberra may shift. Lawmakers and regulators overseas are already weighing new controls around AI and supply chains.
Australian policymakers will be looking at how foreign approaches influence domestic regulation and whether additional guidance for local firms is necessary.
Paths regulators and firms are considering
Attendees at the Washington meeting discussed a mixture of immediate and longer-term steps. Short-term measures include tighter access controls around sensitive systems, accelerated patching programmes, and cooperative information-sharing between banks and tech vendors.
Longer term: officials flagged the need for clearer rules on releasing powerful models, stronger vendor oversight, and possibly industry-wide standards for AI safety testing. How governments balance those measures against the desire to keep innovation moving will be a central policy question.
There's also the prospect of industry-led responses. Some firms may adopt voluntary moratoriums on using the most powerful models for security-sensitive tasks until defensive tools catch up. Others may push vendors for stronger proof-of-safety before adopting new AI capabilities.
What matters now is the speed and coordination of those responses. The banking system's resilience depends on both private firms and public authorities acting in concert to identify faults, fix them, and limit exploitation.
Related Articles
- Sweden retreats from digital learning
- War with Israel upends daily life in Lebanon
- Could the US Leave NATO?
Anthropic limited access to Mythos to Amazon, Apple, Microsoft, Cisco, Broadcom and the Linux Foundation.
This article was created with AI assistance.