Evgueni Ivantsov is the chair of the European Risk Management Council and Tim Roberts is a managing director at AlixPartners
News of Anthropic’s most advanced AI model, Claude Mythos, has sent shockwaves through the cyber security community — and landed squarely on the desks of central banks and banking regulators.
Bank of England governor Andrew Bailey, for example, made his concerns clear:
“It would be reasonable to think that the events in the Gulf are the most recent challenge to us in this world, until . . . you wake up to find that Anthropic may have found a way to crack the whole cyber risk world open.”
The IMF also weighed in, warning that Mythos “foreshadows how fast-moving, AI-driven cyber risks could destabilise the financial system if not managed carefully”.
According to Anthropic, Mythos has identified thousands of high-severity vulnerabilities, including previously unknown weaknesses in every major operating system that had gone undetected for years.
Why banks face a disproportionate threat
For banks, this demands immediate attention. Their advanced security architectures and sophisticated cyber defences mean their risk profile shifts significantly when attackers gain access to a tool capable of finding vulnerabilities that no human had previously detected.
AI is already being put into the hands of fraudsters and other malicious actors. Mythos introduces a new dimension: the systematic, automated discovery of software vulnerabilities at a scale and speed that no human security team is likely to match.
The most immediate risk for banks is unauthorised access to their networks by threat actors seeking to steal customer or other sensitive data, deploy ransomware, or execute fraudulent transactions.
What CROs should do now
Mythos’s capabilities call for a clear and urgent shift in priorities. Four actions stand out.
First, banks should become more proactive in vulnerability scanning. If an AI system can identify thousands of previously unknown weaknesses in major operating systems, banks cannot afford to rely on periodic or reactive scanning cycles. Continuous, AI-assisted vulnerability assessment should become the baseline, not the exception.
Second, they should invest more heavily in detecting unauthorised or suspicious activity — including log-ins, data movements, payments and transactions. Prevention can no longer be treated as the primary line of defence.
Third, and perhaps most importantly, banks should increase investment in response and recovery. Incident response exercises should become more frequent and realistic. Backup systems should be tested rigorously. Recovery plans should be well rehearsed.
Fourth, banks must meet rising regulatory expectations. Regulators already expect lenders to undertake penetration testing and so-called “red team” exercises. They are now likely to expect more sophisticated testing and more frequent rehearsals of recovery procedures.
The problem of blind spots
There is, however, a more optimistic takeaway — one that speaks directly to the longer-term strategic question of AI’s role in risk management.
By identifying thousands of cyber vulnerabilities that had gone undetected for years, Mythos did not merely retrieve existing knowledge. It created new knowledge. That is a fundamental distinction, and its implications for risk management extend far beyond cyber security.
One of the most persistent weaknesses in risk management is the problem of blind spots: the “unknown unknowns” that precede major shocks and that conventional tools and processes often fail to surface.
AI may be able to address precisely this weakness: identifying missed signals, illuminating risks that organisations have not yet thought to look for, and enabling intervention while mitigation is still possible and effective.
That is a qualitatively different capability. Chief risk officers should be exploring it, investing in it and advocating for it at board level.
Mythos’s emergence is, in the short term, a warning. In the longer term, it may prove to be one of the most important demonstrations yet of what AI can contribute to the future of risk management.