Senior financial officials from major economies left the IMF and World Bank spring meetings in Washington this week with a shared concern: a new generation of AI models can find and chain together software vulnerabilities in banking systems faster than any human, and faster than existing safeguards can contain.
At the center of the discussion was Claude Mythos, an advanced AI model developed by Anthropic. The model identified thousands of critical zero-day vulnerabilities across major operating systems and web browsers, according to the company’s April 7 statement.
This isn’t entirely new. Engineers have long designed AI and automated systems to perform tasks faster than humans. What makes this moment different is that, while AI improves efficiency, it also introduces a new layer of risk within the same field.
The Emergency Meeting
On April 8, U.S. Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell summoned the CEOs of America’s largest banks to an emergency meeting at Treasury headquarters.
Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs were all present. The agenda focused on a single issue: an AI-driven cybersecurity threat that regulators now consider a potential systemic risk to the global financial system.
JPMorgan CEO Jamie Dimon said the model “creates additional vulnerabilities” and warned that “AI’s made it worse, it’s made it harder,” according to Observer.
Goldman Sachs CEO David Solomon said the firm is “hyper-aware of the enhanced capabilities of these new models,” the report said.
What Makes Mythos Different
Anthropic’s internal red team confirmed that Mythos can chain three, four, or even five separate vulnerabilities into a single autonomous attack. It can scan millions of lines of code, identify hidden weaknesses, verify exploitability, and turn them into working attack paths in hours rather than weeks.
Officials in Washington described this as a shift in the balance between attackers and defenders. The concern is not just capability, but scale. The model can connect multiple vulnerabilities in ways that exceed human capacity.
The Regulatory Gap
Kristalina Georgieva told CBS News: “We don’t have the ability to protect the international monetary system against massive cyber risks,” according to a BankInfoSecurity report citing IMF warnings on AI cyber threats.
Andrew Bailey, who also chairs the Financial Stability Board, called it “a very serious challenge for all of us.” He warned that regulators face a narrow window: act too early and risk misjudging the threat, act too late and lose control, according to The Irish Times.
For now, access to Mythos remains tightly restricted. Anthropic has limited the model to roughly 40 companies, including Amazon, Apple, and JPMorgan Chase, allowing them to test its capabilities and begin addressing identified vulnerabilities.
Is Mythos as Powerful as Claimed?
It is important to note that Mythos is not publicly available. This raises a key question: does the model truly deliver the capabilities described, or does early-stage hype shape part of the narrative?
Earlier AI systems, including ChatGPT, followed a similar path. Companies introduced them as breakthroughs, but over time they became normalized as everyday tools.
At this stage, independent verification of Mythos remains limited, and observers should treat many of the claims with caution.
The tech industry often follows this pattern: companies frame a tool as revolutionary while restricting access for security reasons, a dynamic that amplifies both anticipation and hype.
The Broader Stakes
Banking infrastructure processes billions of dollars in transactions daily through payment networks, SWIFT messaging, and core systems. The concern is not only that AI could be used to exploit these systems, but that the speed of vulnerability discovery is now outpacing the speed of defense.
The issue is no longer purely technological. It has become a governance question. The same institutions that drive AI’s commercial expansion now confront, measure, and manage the risks that come with it.