Economy April 16, 2026 05:41 AM

German banks and regulators probe security implications of Anthropic’s Mythos model

Industry and authorities coordinate testing and patching as concerns mount over potential vulnerabilities affecting legacy banking systems

By Jordan Park
German banks and regulators probe security implications of Anthropic’s Mythos model

German banking industry representatives and national authorities are coordinating reviews of Anthropic's new AI model, Mythos, amid cybersecurity concerns that the model could expose vulnerabilities in banks' legacy technology. The German Banking Association is working with member bank cyber specialists, the finance ministry, the Bundesbank and financial regulator BaFin, and expects prompt software updates as firms test and close potential weaknesses. European Central Bank supervisors are also preparing to question banks about the model's risks. Anthropic has limited distribution of its current Claude Mythos Preview and launched Project Glasswing to allow selected institutions to evaluate and harden defences privately.

Key Points

  • German banks and national authorities, including the finance ministry, Bundesbank and BaFin, are coordinating reviews of Anthropic's Mythos model - impacts banking and cybersecurity sectors.
  • BaFin warned that vulnerabilities may be found soon and would require prompt remediation - affecting operational resilience across financial firms.
  • Anthropic is not releasing Claude Mythos Preview broadly and has launched Project Glasswing to allow selected technology firms, cybersecurity vendors and banks, including JPMorgan Chase, to privately test the model and prepare defences.

German banks and national authorities have initiated a coordinated review of the security risks connected to Anthropic's latest artificial intelligence model, according to statements released on Thursday. The move follows concerns within cybersecurity circles that the model, known as Mythos, could create new avenues for cyberattacks on financial institutions and their legacy technology stacks.

Kolja Gabriel, who sits on the executive board of the German Banking Association and oversees technology and innovation, said the banking industry association is engaging its members' IT security experts while consulting with Germany's finance ministry and other relevant authorities. In an emailed statement, Gabriel said Mythos is currently being applied in a controlled way by IT security firms to identify and seal possible weaknesses as quickly as possible.

"Mythos is being used in a controlled manner by IT security firms to close potential vulnerabilities as quickly as possible. We expect a series of software updates shortly and are closely monitoring developments," Gabriel said in the statement.

The discussions on the German side also include the Bundesbank and the Federal Financial Supervisory Authority, BaFin. The finance ministry declined to comment. The central bank did not immediately respond to a request for comment.

BaFin said it maintains regular exchanges with relevant national, European and international stakeholders. In its own statement, the regulator warned that financial firms must be prepared for the possibility that vulnerabilities could be discovered in the near future, and that any such issues would need to be addressed promptly and efficiently.

At the European level, supervisors at the European Central Bank are set to question bankers about the risks presented by Mythos, a development that underscores how regulators across jurisdictions are taking the issue seriously.

Anthropic has indicated that the current iteration, Claude Mythos Preview, will not be made widely available. Instead, the company has announced Project Glasswing. Under that initiative, Anthropic has invited major technology firms, cybersecurity vendors and financial institutions, including JPMorgan Chase and several dozen other organisations, to privately test the model and prepare defences.

The coordination among banks, national authorities and European supervisors reflects a focus on rapid detection and remediation. Industry participants are running controlled tests and expect follow-up software updates as they work to mitigate any exposures identified during those reviews.


Key points

  • German banks, the finance ministry, the Bundesbank and BaFin are coordinating work to assess security risks tied to Anthropic's Mythos model - sectors affected include banking and cybersecurity.
  • BaFin cautioned that vulnerabilities could emerge in the near term and would need quick remediation - this affects operational resilience in financial services.
  • Anthropic will not broadly release Claude Mythos Preview, and has launched Project Glasswing to allow select companies and banks, including JPMorgan Chase, to evaluate the model privately and prepare defences - this involves technology and cybersecurity vendors as well as major financial institutions.

Risks and uncertainties

  • Potential discovery of vulnerabilities in Mythos that could be exploited - risk primarily to banking infrastructure and legacy IT systems.
  • Uncertainty over the timing and effectiveness of forthcoming software updates and fixes - operational risk for financial firms while patches are developed and deployed.
  • Regulatory scrutiny, including questions from European Central Bank supervisors, could increase compliance and oversight demands on banks testing and deploying defences - risk to bank operational processes and compliance teams.

Risks

  • Discovery of vulnerabilities in Mythos that could be exploited - primarily affects banking infrastructure and legacy IT systems.
  • Uncertainty over the timing and success of software updates and patches - operational risk for financial institutions during remediation.
  • Heightened regulatory scrutiny from European Central Bank supervisors and national regulators - increases compliance and oversight burdens for banks.

More from Economy

Bahrain Bond Yields Tighten as Regional Support Cushions War Shock Apr 16, 2026 German Manufacturers Pull Back Investment Plans for U.S., Turn Toward Asia Amid Tariff-Driven Uncertainty Apr 16, 2026 Turkey Calls for Constructive Stance as U.S. and Iran Resume Peace Talks Apr 16, 2026 Fed succession faces mounting hurdles as Powell’s term nears May 15 deadline Apr 16, 2026 Volatile Markets Drive Trading Gains While Deal Activity Remains Uncertain Apr 16, 2026