Summary

The European Central Bank is convening an emergency meeting with banks on Tuesday to address cybersecurity risks created by advanced AI models — specifically Anthropic’s Claude Mythos Preview, which has demonstrated the ability to discover thousands of zero-day vulnerabilities across major operating systems and browsers. ECB Executive Board member Frank Elderson told the Financial Times that banks must “deal with [cybersecurity issues] faster” given AI’s rapid progress.

The core problem is an access gap: only 40-50 organizations have been granted access to Mythos through Anthropic’s controlled distribution program (Project Glasswing), including Amazon, Microsoft, Google, JPMorgan Chase, and CrowdStrike. No European bank is on the list. In controlled testing, Mythos produced working exploits on its first attempt more than 83% of the time, often outperforming human cybersecurity specialists. Anthropic has warned that adversaries could replicate the capability within 6-12 months.

Elderson’s message is blunt: AI models can now reverse-engineer software patches within minutes of release, meaning the window between a vulnerability being fixed and being exploited has effectively collapsed. French AI startup Mistral is in discussions with European banks about deploying its own competing cybersecurity model, framing it as a matter of technological sovereignty.

Source

📰 The Next Web — The ECB is convening banks to fix the cybersecurity flaws that AI models like Mythos keep finding

Commentary

This story captures the central tension of AI in cybersecurity: the same technology that dramatically accelerates defense also dramatically accelerates offense, and right now, the offense is winning. When a single AI model can produce working zero-day exploits 83% of the time on the first attempt, the entire concept of “patch Tuesday” becomes dangerously quaint.

The geopolitical dimension is equally significant. European banks are locked out of the most powerful defensive AI tool available, while Anthropic warns that adversarial versions could emerge within a year. Mistral’s pitch for a European alternative makes strategic sense, but building a competitive vulnerability-discovery model isn’t trivial — and the clock is already ticking. The ECB’s move from guidance to direct intervention signals that regulators understand this isn’t a compliance problem; it’s an existential infrastructure risk.

By Allan