Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Bank of England, banks assess Anthropic AI cyber risk

UK financial regulators are holding urgent talks with the National Cyber Security Centre, and major banks to assess risks from Anthropic’s latest AI model, Claude Mythos Preview, according to a report.

Officials from the Bank of England, the Financial Conduct Authority, and HM Treasury are involved, with briefings planned for financial institutions in the coming weeks.

The discussions follow a similar meeting convened by US Treasury Secretary Scott Bessent with major Wall Street banks, as authorities examine potential cybersecurity threats from advanced AI systems.

Anthropic said select organisations are testing the model under a controlled programme, where it has identified vulnerabilities in widely used software.

🔗 Source: Reuters

🧠 Food for thought

Implications, context, and why it matters.

### The model can autonomously find and exploit decades-old software flaws

  • Claude Mythos Preview can find vulnerabilities and build working exploits without human help 1.
  • It produced a remote code execution exploit, which lets an attacker run code on another machine, for a 17-year-old flaw in FreeBSD’s NFS server, a file-sharing service built into the operating system kernel 1.
  • It also uncovered a separate bug in OpenBSD, an open-source operating system, that had gone unnoticed for 27 years 1.
  • Anthropic says these skills were not directly trained and came from broader gains in coding and reasoning. The run that found the OpenBSD bug cost under $50, though Anthropic says that number “only makes sense with full hindsight” 1.

### The era of automated exploit generation changes the rules for everyone

  • AI that quickly turns vulnerability disclosures into working exploits makes the monthly patch cycle, the routine schedule many companies use to install security fixes, too slow for many threats 1.
  • This shift can widen the pool of capable attackers since work once reserved for elite cybersecurity teams becomes easier to reproduce 1.
  • The model is currently limited to Project Glasswing, Anthropic’s controlled testing program, with access through Amazon Bedrock, Amazon’s cloud service for building with foundation models, in a gated research preview 2.
  • US officials have urged systemically important banks, meaning large financial institutions whose disruption could threaten the wider financial system, to use the model to hunt flaws in their own systems before attackers do 3.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.