Which Banks Have Mythos Access And Why Regulators on Three Continents Are Now Scrambling

JPMorgan, Goldman Sachs, Morgan Stanley, and Citigroup have confirmed Mythos access while regulators in the UK, Europe, and Asia scramble to assess what it means for financial sector cyber resilience.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
Global banks and regulators across the US, Europe, and Asia assess cybersecurity risks from Anthropic's Mythos AI model as access remains tightly restricted to select financial institutions

Global banks and regulators across the US, Europe, and Asia assess cybersecurity risks from Anthropic's Mythos AI model as access remains tightly restricted to select financial institutions

Anthropic's Mythos has moved fast from a technical cybersecurity discussion to a boardroom and regulatory crisis one now playing out simultaneously across Washington, Frankfurt, London, and Seoul.

While earlier coverage focused on what Mythos can do to GCC banking infrastructure and why the arms race it represents will not stop at a single model, a new and equally urgent question has emerged: which institutions actually have access to Mythos right now and what are global regulators doing about it?

The answers, reported by Reuters from the IMF spring meetings in Washington, reveal an uneven landscape already generating competitive friction and regulatory urgency at the highest levels of global finance.

Access Is Restricted And Unevenly Distributed

Anthropic has confined Mythos access to participants in Project Glasswing, a controlled evaluation programme involving approximately 40 organisations with roles in building or maintaining critical software infrastructure. Outside Glasswing, access is not publicly available.

Among major financial institutions, the confirmed access list now includes:

  • JPMorgan Chase - the only bank Anthropic has publicly named as a Glasswing participant
  • Bank of America - part of Glasswing from the outset, conducting internal evaluations
  • Morgan Stanley - CEO Ted Pick confirmed access during the bank's earnings call, noting active cyber risk discussions within the Financial Services Forum
  • Goldman Sachs - CEO David Solomon confirmed access during earnings, stating the bank is working closely with Anthropic and its security vendors to assess frontier capabilities
  • Citigroup - confirmed to have access and conducting internal testing

No European financial institution has been confirmed as having Mythos access as of today.

The JPMorgan Advantage Question

The uneven distribution of access has itself become a point of contention. Several institutions without access have raised concerns about whether JPMorgan's early and confirmed Glasswing participation constitutes a competitive advantage a matter expected to be raised directly with the US Treasury, according to sources familiar with the situation.

For GCC financial institutions, this dynamic matters. If access to frontier defensive AI tools becomes a structural differentiator among Tier 1 global banks, the question of when regional institutions including those operating within ADGM and DIFC frameworks alongside international counterparts gain equivalent access becomes a strategic and regulatory matter, not just a technical one.

Regulators Move on Three Continents

The pace and breadth of the regulatory response to Mythos is notable. At last week's IMF spring meetings in Washington, the model was a prominent topic on the sidelines with senior banking executives and supervisors from multiple jurisdictions in active discussion.

United Kingdom: The British government issued an open letter to Anthropic leadership on April 15, citing findings from its AI Security Institute that Mythos demonstrated significantly greater offensive cyber capability than any AI model it had previously assessed.

Europe: The European Central Bank and other European supervisory bodies have been contacting banks directly to assess preparedness asking specifically about institutions' awareness of the Mythos threat and their ability to respond. Deutsche Bank CEO Christian Sewing confirmed that European banks are in close contact with watchdogs and that a German banking association convened specifically to address the issue.

Asia: South Korea's Financial Supervisory Service held meetings with information security officials from domestic financial firms to review Mythos-related risks a clear signal that concern extends well beyond Western financial centres.

What This Means for GCC Financial Institutions

No GCC-equivalent emergency briefings on Mythos have been publicly announced to date. That gap between the pace of international regulatory mobilisation and the public posture of regional supervisors including SAMA and the UAE Central Bank is itself a risk signal that enterprise security leaders should be raising internally.

GCC financial institutions particularly those with correspondent banking relationships with the US and European banks currently navigating Mythos access and risk assessments are not insulated from this threat landscape. The interconnected vendor and platform dependencies that define the region's banking infrastructure mean that an AI-augmented attack on a global counterpart can cascade regionally in ways that are difficult to contain.

For a practical framework on immediate defensive steps, see our briefing on what GCC CISOs must do now in response to AI-driven vulnerability exploitation. For a broader view of how GCC enterprises are strengthening their security posture, see our analysis on Managed Detection and Response in the GCC.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

AI-Driven Cyber ThreatsFinancial Sector Cybersecurity MENAGlobal Threat IntelligenceGCC Banking SecurityEmerging Technology Risk & Regulation