Washington, D.C. | July 22, 2026 

For three months, the Federal Reserve warned the country’s largest banks about a cybersecurity threat it could not fully assess itself. The Fed Anthropic Mythos alarm was real, urgent, and public. What was not public until now is that the regulator issuing the warning did not have direct access to the very model it was concerned about. 

This gap is central to the story of Claude Mythos banks’ cybersecurity risk. It shows how even the world’s most powerful financial regulator can fall behind when new artificial intelligence develops faster than the institutions designed to oversee it. 

What Happened in April 

The episode began with an emergency summons. In April, the Federal Reserve and the Treasury Department convened an extraordinary meeting with the chief executives of the country’s largest banks. Then-Treasury Secretary Scott Bessent and then-Fed Chair Jerome Powell called that meeting specifically to warn bank leaders about cyber risks tied to Anthropic’s newest AI model. The trigger was Anthropic Mythos Preview April, the model’s public debut, which the company paired with a cybersecurity initiative called Project Glasswing. 

Anthropic designed the model to find weaknesses in software before criminals could exploit them. The company said the tool could spot vulnerabilities in operating systems and browsers more quickly than any human security team. Anthropic revealed that about 50 organizations had access to the model at launch but only named a few publicly. Among those named were JPMorgan, Amazon, Apple, and Google, who received early access. This put some of the world’s largest financial and technology firms ahead of the regulator that oversees several of them. 

Project Glasswing Banks Got In. The Fed Did Not 

That imbalance is the most striking part of the story. Project Glasswing banks, including JPMorgan Chase, started using Mythos on their own systems almost right away, fixing flaws the model found before attackers could exploit them. Meanwhile, the institution responsible for the stability of the entire U.S. banking system had to wait. 

Financial-sector cybersecurity teams pointed out the irony: banks in Project Glasswing were actively fixing vulnerabilities the model found, while the Fed was locked out of the same tool. Industry observers sum up the situation: “Fed rang alarm Anthropic Mythos model” describes the warning phase, while “Claude Mythos banks months delay access”describes what happened next. The regulator raised the flag, then had to watch from outside the room. 

The Fed AI Model Access Delay, By the Numbers 

The Fed AI model access delay stretched at least three months past the April meeting. CNBC reported the central bank was still trying to secure access to Mythos as recently as July 15, and neither the Fed nor Anthropic offered further comment on whether access has since come through. New Fed Chairman Kevin Warsh, who took over from Powell earlier this year, told lawmakers the central bank had been actively seeking access to Mythos and other frontier models so it could repair vulnerabilities in its own systems and in those connected to the wider financial sector. Warsh put it: the Fed needs to “do all we can to patch any vulnerabilities that we have.” 

The timing is important. Anthropic briefly suspended access to Mythos in June to comply with export-control rules. The Commerce Department later lifted those restrictions, and the company restored access to trusted partners on July 1. This months-long gap also overlapped with a time when even outside partners with credentials could not reach the model. 

Why the Access Gap Matters Beyond One Model 

It may have been a simple bureaucratic issue, such as a paperwork delay or a problem with onboarding a vendor. But that view misses the bigger problem. Regulators are being asked to supervise institutions that already have tools regulators themselves do not have. For example, a bank examiner reviewing JPMorgan’s cyber defenses this summer could ask what vulnerabilities Mythos found and whether they were fixed. Until the Fed gained access, it had no independent way to check those answers against the model itself. 

This is not simply a hypothetical concern for one agency. Frontier AI models are now often seen as dual-use tools. The same ability that helps defenders find flaws can also help attackers if misused. Anthropic’s decision to limit Mythos’ access to about 50 vetted organizations reflected this risk. The company trusted banks, cloud providers, and some government contacts with early access. It took longer to extend that trust, or finish onboarding, for the regulator whose job is to oversee all of them. 

Warsh’s testimony suggests the Fed sees this as a repeated problem, not merely a one-time event. He described the Mythos episode as proof that financial regulators need to build ongoing relationships with AI labs before the next model is released, instead of rushing for access after a warning. Congress has also shown more interest in whether banking regulators have the technical skills to supervise AI-driven risks. The Mythos timeline now gives that debate a real-world example. 

The Forward-Looking Question 

Delays like this rarely affect only one institution or one model. As more banks start using AI-driven vulnerability scanning as a standard practice, the agencies that supervise them will need quicker and more reliable ways to access the tools to mold these risks. It is still unconfirmed whether the Fed has since gained access to Mythos. What is clear is that this episode has become a test case for how financial regulators can keep up with an industry that moves faster than Washington’s usual pace.

Source: Politics The Fed rang the alarm about Anthropic’s Mythos AI model — but had to go months without it 

Amazon

Leave a Reply

Your email address will not be published. Required fields are marked *