The European Central Bank (ECB) is calling on banks on Tuesday to address cybersecurity risks from AI models such as Anthropic’s Mythos, which has identified thousands of zero-day vulnerabilities. Executive board member Frank Eldersonsaid banks need to patch vulnerabilities more quickly, as AI can exploit loopholes within minutes of a patch being released.
See also: Anthropic's Claude Mythos identified 10,000 critical vulnerabilities in one month

The ECB meeting comes amid growing concerns in the European financial sector about AI models that can identify and exploit software vulnerabilities faster than human teams. Elderson said banks need to accelerate their cybersecurity efforts, which have been underway for years, because of advances in AI.
The central bank plans to educate lenders about the specific threats posed by Mythos and similar AI systems. It will also encourage US banks that have access to the technology, through Anthropic’s Project Glasswing, to share their knowledge with their European counterparts that do not.
Only about 40 to 50 organizations, including major companies like Amazon, Microsoft, Google, Nvidia, CrowdStrike, Palo Alto Networks, and JPMorgan Chase, have gained access to Mythos, with no European banks on the list. In controlled tests, Mythos produced functional exploits more than 83 percent of the time, often outperforming human cybersecurity experts. Anthropic has warned that adversaries could replicate this capability within six to twelve months.
See also: NSA uses Anthropic's AI despite ban

Elderson’s message to banks is clear: they need to patch vulnerabilities faster. AI models can reverse engineer software patches almost immediately after they are released, reducing the time window between patching a vulnerability and its exploitation. European banks cannot use their lack of access to Mythos as an excuse for inaction, as malicious actors may soon gain access to similar technology.
The ECB’s intervention is part of a broader regulatory effort in Europe. Eurozone finance ministers have requested access to Mythos, and European Commissioner Valdis Dombrovskis confirmed that the EU is in talks with Anthropic about testing companies and banks for the vulnerabilities the model identifies. However, those negotiations have made little progress, with reports suggesting that the talks have stalled.
See also: Anthropic's Mythos Preview creates functional exploits

This situation has opened up opportunities for competitors. French AI startup Mistral AIis in talks with European banks to develop its own cybersecurity model, which aims to detect vulnerabilities similar to Mythos. CEO Arthur Mensch has positioned the effort as a matter of technological dominance, leveraging existing bank clients such as HSBC and BNP Paribas. The model is still under development and has no confirmed release date.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
