Full Breakdown
ECB Urges Eurozone Banks to Accelerate AI-Cyber Defences
5/26/2026, 11:15:40 AM
Emergency Meeting on AI-Powered Cyber Risks
On 26 May the European Central Bank convened an unscheduled session with the 111 largest euro-area banks, including U.S. lenders, to discuss cybersecurity risks linked to Anthropic’s Claude Mythos AI model. Supervisors said the meeting reflects the regulator’s view that AI-enabled attacks have moved from theoretical to urgent.
Background and Threat Profile
Anthropic released the Claude Mythos Preview in April under a restricted Project Glasswing programme. The model autonomously analyses software, discovers unknown flaws and can devise exploits. Independent testing by the UK AI Security Institute showed it cleared 73 % of expert-level Capture-the-Flag challenges, a first for any system. The model has reportedly uncovered thousands of high-severity vulnerabilities across operating systems, browsers and enterprise software, many of which had persisted undetected. Key actors include Frank Elderson, Anthropic, U.S. banks with Mythos access, and the European Commission.
Data and Statistics
U.S. banks have identified “hundreds to thousands” of low-to-moderate vulnerabilities; reverse-engineering a newly released patch can be done within 30 minutes, compressing the remediation window.
Official Statements
Elderson warned that AI’s rapid development shortens the interval between vulnerability disclosure and exploitation, urging banks to treat AI-related flaws as live business risks and to accelerate patch cycles beyond the “andante” tempo. He stressed that lack of direct model access does not excuse inaction, noting that malicious actors could soon obtain comparable capabilities. The ECB also called for immediate sharing of security insights between U.S. and European institutions.
Criticism and Opposition
Observers note that European lenders lack direct Mythos access, limiting their ability to test and mitigate the model’s threat vector. Anthropic’s refusal to grant broader regulator access is seen as a barrier to comprehensive risk assessment.
Conflicting Reports and Gaps
Sources differ on the scale of flaws, citing both “hundreds to thousands” of low-to-moderate issues and “thousands” of high-severity vulnerabilities. Technical specifications of Mythos remain undisclosed, leaving uncertainty about its full exploit capability.
Verbatim Quotes
- “The clock is ticking,” — Frank Elderson, Vice-Chair, ECB Supervisory Board
- “Malicious actors might have access to this technology soon,” — Frank Elderson
- “He warned that "andante" tempo is no longer enough, and that supervisors now need banks moving at "presto" speed.” — Frank Elderson
- “Mythos can autonomously discover and exploit vulnerabilities at scale.” — Frank Elderson
What’s Next
The ECB’s directive coincides with the EU AI Act’s full application on 2 August 2026, suggesting tighter AI regulations for banking. Ongoing talks between the European Commission and Anthropic aim to broaden testing access, while Japanese banks prepare to integrate Mythos into security workflows.
