The ECB asks banks for contingency plans regarding Anthropic’s new AI model

The ECB asks banks for contingency plans regarding Anthropic's new AI model

All of Europe trembles before the earthquake felt from the United States. This tremor shares its name with the stories that founded the civilization of the Old Continent, in ancient Greece, although it has the aroma of Terminator. It is Mythos, the new artificial intelligence (AI) model being developed by the American multinational Anthropic, whose outstanding ability to detect flaws in business software threatens to put the entire system at risk. Even the engine room of banking. Faced with this threat, the European Central Bank (ECB) has asked eurozone entities to detail their contingency plans and the cybersecurity vulnerabilities they detect in their systems, according to internal sources from the entities.

Read more Latest news on the US and Israel war against Iran, live | Trump orders his advisers to prepare for a prolonged blockade of Iran

Anthropic has a weapon that, if it falls into the wrong hands, has the potential to destroy everything. Mythos is an AI model that initially had a generalist character (like, for example, its popular Claude, OpenAI’s Chat GPT, or Microsoft’s Copilot), but due to its great capacity to work and learn, it has gained an enormous ability to scrutinize the vulnerabilities of software used for activities as critical as national defense, energy supply, or the already fully digitized banking activity. For the moment, it has put this company back on the map, after the conflict with Trump that closed the doors to contracts with the administration in the United States.

The new model has not yet reached Europe, and neither banks nor other large companies have yet had access. But they want to be prepared. Two weeks ago, the ECB summoned the risk managers of the main eurozone banks, among which the four Spanish entities considered significant (Santander, BBVA, CaixaBank, and Sabadell) stand out, as revealed by Bloomberg. At the meeting, as this newspaper has learned from internal sources at the banks, the European supervisor has asked them to detail their cybersecurity contingency plans and vulnerability detection in their systems, to face the emergence of Mythos.

“Companies and cybercriminals have worked for many years with vulnerability screeners [programs to scrutinize software flaws]. The difference now is the enormous capacity to exploit those vulnerabilities,” explains Miguel Ángel Thomas, head of cybersecurity at NTT DATA, a consultancy that works with large companies as an advisor on technology matters.

This is what Anthropic itself has called “zero-day” vulnerability hunting. That is, previously unknown to software developers and hidden from cybersecurity tests for years, with zero days to solve them, and which can be a gold mine for hackers. The company itself has warned that its system has the potential to pose a national defense problem.

This system can also represent a great improvement for companies and banks to effectively shield themselves against possible cyberattacks. But, if the model falls into the wrong hands, such as those of hackers or Governments openly opposed to the West, it can also expose so many and such deep cybersecurity flaws that they could bring down large corporations. It could cause, for example in the case of banks, massive data theft or the evaporation of customers’ money in a second. For this reason, the company has chosen an exclusive group of American companies (among which Amazon, Apple, Alphabet, and JP Morgan stand out) to test, sparingly, the new functionality.

“The development we’ve seen with Anthropic and Mythos is a good example of a responsible company that suddenly thinks: ‘This could be really good, but if it falls into the wrong hands, it could be really bad,’” admitted ECB President Christine Lagarde herself in an interview with Bloomberg. A spokesperson for the supervisor declined to comment for this article.

Read more The IFAB approves sanctioning with a red card players who cover their mouths when confronting an opponent

The ECB has also followed the White House’s stance here. Treasury Secretary Scott Bessent has held various meetings with the US financial sector to address the consequences of the new system and the threat of it leading to large waves of cyberattacks. The difference is that large US banks like JPMorgan and Goldman Sachs have already had access to the model and may have a clearer picture of its effects. European banks expect to have access to the tool soon, as Lagarde recently demanded, and Anthropic itself has announced that it will open it to British companies imminently.

Beyond the issue with Mythos, AI is one of the key focuses for the ECB. It has placed it on the list of priorities for supervision in the coming years and will be a key element in its annual banking inspection process (known as SREP).

This concern also extends to the national financial supervisor, the Banco de España. The institution led by José Luis Escrivá already requested information from Spanish entities about their plans for adopting this technology, insofar as the Preliminary Draft Law for the good use and governance of artificial intelligence designates the Banco de España and the National Securities Market Commission (CNMV) as the supervisors responsible for monitoring the market. For the banking supervisor, its main concern is to prevent this technology from making key decisions, determining risk assumption, credit granting, or operating in banks without due human supervision.

It is possible that the ECB, the White House, and Anthropic itself will get their way, so that Mythos remains far from the hands of its enemies. But, as Thomas points out, it is only a matter of time before other companies, China or Russia, develop models with similar firepower, given the rapid development of AI on all fronts. And for this reason, it is perhaps time to make a Copernican shift in cybersecurity in companies.

This will cause, according to the expert, large companies like banks to be forced to significantly increase their investments in fighting cybercrime, with the need to act much faster than before. And it will make the larger entities with greater investment capacity winners, while medium-sized ones will suffer.

Read more Disney’s broadcast licenses to be reviewed by the Government after Jimmy Kimmel’s joke about Melania Trump

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *