Cybersecurity: UK Regulators Plan to Meet to Assess Risks of Anthropic’s New AI Model Mythos
Anthropic, the company the US government branded a ‘national security threat’ last month is now the company both Washington and London are relying on to protect their financial systems from the next generation of cyberattack.
Anthropic's Claude Mythos Preview, withheld from public release because of its ability to find and chain together software vulnerabilities across every major operating system and browser, has prompted the Bank of England, FCA, Treasury and NCSC to convene urgent talks with UK banks, insurers and exchanges. The meeting follows the US Treasury Secretary and Fed Chair pulling Wall Street CEOs into a room over the same model last week.
Anthropic's head of offensive cyber research says comparable capability from other labs, including Chinese ones, is six to eighteen months away. Anthropic has speculated that those labs won't be running coordinated disclosure programmes or briefing regulators and big tech so defensive action can be taken.
The regulatory scramble is aimed at the company that volunteered its findings. The ones that don't volunteer are the a bigger problem, and nobody's convening emergency meetings about them yet.
If UK financial regulators are serious about this, the question isn't what Mythos can do. It's what happens when the next model with the same capability arrives from a lab with no Glasswing to coordinate big tech's response, no ethical red lines, and no interest in picking up the phone.
We'd like your views:
- Anthropic found vulnerabilities in critical systems that survived decades of human review. Should regulators require financial institutions to submit to AI-led security audits, and if so, who decides which AI model gets access to your infrastructure? What does this mean for customer privacy?
- Anthropic estimates comparable offensive cyber capability will be widely available within six to eighteen months. If UK financial institutions haven't hardened their systems by then, who carries the liability, the banks, the regulators, or the software vendors whose decades-old vulnerabilities were never found until an AI looked?
- The UK's compensation architecture was designed for individual firm failures and individual fraud cases. It was never designed for a scenario where AI-driven cyberattacks hit multiple institutions simultaneously, exploiting the same class of vulnerability across the sector. How can/should clients be compensated?
- Mythos Preview's own safety evaluation revealed the model appeared to deliberately underperform to seem less capable. If AI systems can now manage how they present themselves under evaluation, what does that mean for every compliance and audit framework the financial sector currently relies on?


