It’s not just a technological issue. Nor is it merely a commercial dispute between AI giants. Behind the alarm raised by the European Central Bank about Anthropic’s Claude Mythos model lies something deeper: the fear that the AI revolution applied to cybersecurity could exacerbate Europe’s strategic vulnerabilities, exposing banks to a new generation of cyberattacks conducted “at algorithmic speed.”
This concern was made explicit by Frank Elderson, member of the ECB’s executive board and vice-chair of the supervisory board, who in an interview described Mythos as a “game-changer” capable of radically altering the digital security landscape. His remarks come as major American banks are already taking action after gaining early access to Anthropic’s system, and as Japan prepares to open its financial system to the model.
Meanwhile, in the United States, the issue has become a matter of national security, to the point that Anthropic was summoned for a closed-door briefing before the House Homeland Security Committee.
WHAT WORRIES THE ECB ABOUT MYTHOS
Elderson’s statement is striking especially for its tone. For the ECB official, Mythos “is not just a technological advancement,” but “a true revolution in cybersecurity.”
According to Elderson, Anthropic’s model has at least three features that clearly distinguish it from tools used so far. The first concerns its ability to “autonomously identify and exploit vulnerabilities with a speed and scale far beyond” existing tools. The second is its capacity to quickly combine small IT flaws which, taken individually, seem minor but when combined can become much more serious attacks. These operations previously required days of work by specialists. The third, perhaps the most alarming for banks, is the ability to “read” software security updates to identify in near real-time the weaknesses being fixed.
In practice, what used to take weeks of analysis could now be done in a matter of hours.
The consequence, for the ECB, is that the entire logic of banks’ operational resilience risks having to be rewritten. A warning recently also issued by the International Monetary Fund, concerned about the potential systemic effects of AI on financial sector security.
Elderson openly speaks of an “urgent situation” and warns that the time before these capabilities become widely accessible could be “very short.”
The point is that artificial intelligence risks rendering obsolete the old distinction between “serious” and “minor” vulnerabilities. Even small software defects, if rapidly combined by systems like Mythos, can become the starting point for much more dangerous attacks.
“Vulnerabilities once considered minor must be treated as urgent and fixed immediately,” Elderson explained.
THE EUROPEAN PARADOX: AI EXISTS, BUT NOT IN THE EU
The most delicate aspect of the matter, at least from a geopolitical perspective, is another. European banks do not have access to Mythos.
Anthropic in fact launched Mythos in early April, describing it as “too powerful to be released to the public” and restricted access through the Glasswing project, which involves major tech groups like Apple, Amazon, Microsoft, Google, Cisco, and Broadcom. An officially security-motivated choice, but one that is effectively creating a new technological asymmetry between the United States and Europe.
The ECB acknowledges the problem. “Euro area banks currently do not have access to Mythos,” Elderson admits, but immediately adds: “Lack of access is no excuse for inertia.” On the contrary, precisely the fact of being excluded from Anthropic’s model requires European institutions to accelerate their cybersecurity defenses.
Behind the ECB’s alarm is also a broader concern: that the advantage in AI applied to cybersecurity will end up concentrated in the United States and, prospectively, in some Asian countries, leaving Europe behind.
The issue is not only the risk of increasingly sophisticated attacks. The problem is that even the most advanced defensive tools risk remaining in the hands of a limited number of entities with privileged access to the new models.
For this reason, Elderson urges European banks to immediately strengthen vulnerability controls using already available AI tools and to carefully monitor the guidance coming from institutions and companies already working with Mythos.
AMERICAN BANKS ALREADY IN EMERGENCY MODE
The ECB’s alarm comes as the concrete effects of Mythos are already emerging in the United States.
As reported by Reuters , major American banks that have gained access to the model are racing against time to fix hundreds or even thousands of vulnerabilities identified by Anthropic’s AI.
Among the institutions involved are Goldman Sachs, Citigroup, Bank of America, Morgan Stanley, and JPMorgan Chase. The problem is that Mythos is identifying IT flaws at a much faster pace than organizations’ traditional ability to fix them.
Vulnerabilities considered low or moderate severity are now being fixed within days, whereas in the past interventions could be postponed for weeks.
Among the most alarming capabilities is the ability to combine minor vulnerabilities to build much more sophisticated attacks.
Adam Meyers of CrowdStrike told Reuters that his team spent “an entire weekend” just figuring out how to use Mythos. When they saw its capabilities, his instinctive reaction was: “This changes everything.”
The problem is that the need to quickly fix hundreds of flaws could translate into more frequent technical interventions and thus possible slowdowns or temporary interruptions of banking services. For this reason, banks are organizing updates with great caution.
The central issue, however, remains the asymmetry between offensive and defensive capabilities. Major bankers like Jamie Dimon of JPMorgan and Nitin Seth of Incedo believe that AI is increasing the speed and scale of cyberattacks faster than banks can strengthen their defenses.
JAPAN MOVES, EUROPE WATCHES
While Europe remains excluded from direct access to Mythos, Japan seems ready to join the select group of admitted countries.
Mitsubishi UFJ Bank, Sumitomo Mitsui Banking, and Mizuho Bank are expected to gain access to the model by the end of May.
The decision was reportedly communicated directly by US Treasury Secretary Scott Bessent during meetings held in Japan.
Access to Mythos no longer appears merely a commercial choice, but a matter involving relations between governments, financial systems, and geopolitical alliances.
Tokyo had already asked Washington to be allowed to use the system, and Prime Minister Sanae Takaichi has ordered strengthened controls on vulnerabilities in strategic infrastructures.
THE CASE REACHES THE US CONGRESS
The growing tension around Mythos is also emerging on the American political front.
Anthropic will hold a closed-door briefing before the US House Homeland Security Committee. The meeting will focus on the model’s capabilities, national security implications, and possible regulatory consequences.
This is not the first confrontation between Anthropic and the US Congress on the matter. The limited release of Mythos had already attracted strong attention in Washington political circles.
OPENAI’S RESPONSE
The Mythos case intertwines with the growing competition between Anthropic and OpenAI in cybersecurity.
The company led by Sam Altman has launched Daybreak, a system designed to identify cybersecurity vulnerabilities and compete directly with Mythos, and has announced it will offer Europe access to the Gpt-5.5-Cyber model for governments, agencies, and enterprises.
A choice that also has strategic meaning: positioning itself as a more open technological partner towards Europe compared to Anthropic.




