The U.S. Federal Reserve convened an emergency meeting to warn banks about Anthropic's Claude Mythos Preview — then spent three months without access to the model it was flagging.
The U.S. Federal Reserve convened an emergency meeting to warn banks about Anthropic's Claude Mythos Preview — then spent three months without access to the model it was flagging.

The Federal Reserve lacked access to Anthropic's Claude Mythos Preview AI model for at least three months after convening an extraordinary meeting with bank chief executives to warn the technology could pose a major cybersecurity risk, according to people familiar with the matter.
"Advanced artificial intelligence models, such as Anthropic Claude Mythos, significantly compress the timeframe for effective risk mitigation," Canada's Office of the Superintendent of Financial Institutions said in an April email to chief technology officers and chief risk officers across the financial sector, according to documents obtained by Reuters.
The access gap meant the Fed's own examiners could not directly test or evaluate the model's capabilities during a period when U.S. Treasury Secretary Scott Bessent and then-Fed Chair Jerome Powell were holding urgent meetings with bank CEOs about the same threat. Canada's OSFI separately alerted its regulated institutions — including Royal Bank of Canada, TD Bank and BMO — that Mythos could increase cyber threats and reduce the time available to detect and patch vulnerabilities.
The episode raises questions about the ability of financial regulators to oversee risks from frontier AI systems that are evolving faster than the government's own access protocols. Authorities in several jurisdictions are now examining cybersecurity concerns tied to Mythos, which has been described as highly capable of identifying and exploiting software vulnerabilities in legacy banking infrastructure.
The Fed's delayed access highlights a structural challenge for financial oversight: regulators are being asked to police risks from technologies they cannot fully observe. The central bank ultimately obtained access to Claude Mythos Preview, though the exact date remains unclear, and the three-month gap has prompted internal reviews of how the Fed procures and evaluates advanced AI tools, the people said.
OSFI's April bulletin did not impose new rules but directed institutions to adopt "sound practices" for enhancing the speed of risk identification and response. "OSFI takes a technology-neutral, risk-focused approach to emerging technologies, including advanced artificial intelligence models such as Mythos," the regulator said in a statement. "Our focus is not the technology itself, but how federally regulated financial institutions govern and manage the risks associated with its use."
Three of Canada's six largest banks — RBC, TD and BMO — have outlined plans to generate millions of dollars in revenue from AI investments, moving from pilot projects to production uses including chatbots, internal tools and reducing reliance on third-party software. That growing dependence on AI creates a dual exposure: the same technology that powers efficiency gains may also introduce new vectors for cyber attacks.
The cyber capabilities of some frontier AI systems are considered so advanced that access has been restricted, with some institutions currently excluded from Mythos entirely, according to the Reuters report. The U.S. government has also been exerting control over global access to the world's most powerful AI models, raising questions about how oversight frameworks can keep pace with proprietary technology developed by private companies.
For banks, the regulatory scrutiny arrives as they balance AI-driven cost savings against rising cybersecurity spending. The Fed's warning — delivered without hands-on access to the model in question — shows the information asymmetry between frontier AI developers and the regulators tasked with containing their risks.
This article is for informational purposes only and does not constitute investment advice.