A confidential April memo alerted Canadian banks to rapid cyber threats posed by Anthropic’s Claude Mythos. Immediate changes to detection and remediation timelines are urged.
In Toronto on July 13, Canada’s financial sector regulator warned the country’s leading financial institutions about the risks of Claude Mythos from Anthropic and other advanced AI models. According to an email sent in April, new technologies may increase cyber threats and reduce the time institutions need to detect and remediate vulnerabilities.
The Office of the Superintendent of Financial Institutions of Canada (OSFI) sent a letter to heads of technology, information security, and risk management in the financial sector, including large banks and insurers, as revealed by documents obtained under an access-to-information request.
Regulators worldwide are attempting to assess cyber risks associated with frontier AI models, notably Mythos. Cybersecurity experts say that Mythos, a model capable of detecting and exploiting vulnerabilities, poses serious challenges for the banking sector and legacy systems.
“Such advanced AI models as Anthropic Claude Mythos significantly shorten the timelines for effective risk mitigation.”
– Office of the Superintendent of Financial Institutions of Canada
“Thus, this bulletin is based on our existing guidance and outlines practices institutions can adopt to increase the speed and effectiveness of risk detection, mitigation, and response.”
– Office of the Superintendent of Financial Institutions of Canada
“OSFI applies a technology-neutral, risk-based approach to new technologies, including advanced AI models such as Mythos. Our focus is not on the technology itself, but on how federally regulated financial institutions manage and govern the risks associated with its use.”
– OSFI
In early April, the heads of Canadian banks met with regulators to discuss Mythos risks, not long after Scott Bessent and the then-chair of the Federal Reserve Jerome Powell called an urgent meeting with bank leaders to warn about cyber risks related to the latest Anthropic AI.
OSFI sent the email to company executives on April 29.
A rapidly changing landscape
OSFI is responsible for regulating and maintaining the stability of Canada’s financial system, covering banks, pension funds, and other regulated institutions, and monitors risks related to external influence, geopolitics, and new technologies.
Some frontier AI cyber tools are considered controlled, with Mythos currently not subject to certain restrictions.
Anthropic also had a rocky relationship with the US government: a judge blocked attempts to place Anthropic on the Pentagon’s blacklist, and after the private release of Mythos, regulator attention to risks intensified.
Three of the six largest Canadian banks – Royal Bank of Canada, TD Bank, and Bank of Montreal – stated plans to profit from their investments in AI, moving from experimental AI projects to applying them in chatbots, building internal tools, and reducing reliance on third-party solutions.
Bank of Nova Scotia, CIBC, and National Bank also announced several AI initiatives.
The Canadian government said it has access to Anthropic’s Glasswing project, which allows companies to access Mythos. It is not known which Canadian banks use it. Some banks declined to comment and referred questions to the Canadian Bankers Association, which said that banks are investing heavily in safeguarding the financial system and comply with OSFI’s cyber risk management and incident reporting requirements.
In June, RBC’s AI group head Bruce Ross said in an interview that Mythos highlights changes in the cyberattack landscape, making rapid response crucial since attack methods can emerge soon after new vulnerabilities are discovered.
“The way we (the industry) deal with this is to build our own AI-based defense systems… we will continue to do just that.”
– Bruce Ross
Canadian regulators continue to monitor AI development in the financial sector and stress the importance of timely and controlled adaptation to protect customers and the financial system from cyber risks.