Canada's federal banking regulator issued a warning in an April email to the country's banks, stating that advanced artificial intelligence (AI) models, such as Anthropic's Claude Mythos, could present significant risks. The agency indicated that this new technology may intensify cyber threats and shorten the time financial institutions have to identify and address system vulnerabilities. Global regulators are currently working to evaluate the cybersecurity risks associated with cutting-edge AI systems like Mythos.
Cybersecurity experts have noted that the Mythos model possesses exceptional capabilities in discovering and exploiting security weaknesses, posing a major challenge to the banking sector and its legacy technology infrastructure. The Office of the Superintendent of Financial Institutions (OSFI) stated in its email, "Advanced AI models like Anthropic's Claude Mythos significantly compress the window of time available to effectively respond to risks."
On Monday, the agency further clarified its stance to the media, saying, "OSFI takes a technology-neutral, risk-based approach to emerging technologies, including advanced AI models like Mythos. Our focus is not on the technology itself, but on how federally regulated financial institutions manage and control the risks associated with its use."
In early April, senior Canadian bank executives met with regulators to discuss the range of risks presented by the Mythos model. This followed an emergency meeting convened by U.S. Treasury Secretary Scott Besson and then-Federal Reserve Chair Jerome Powell with bank leaders to warn them about the cyber risks stemming from Anthropic's latest AI model.
Reports indicate that three of Canada's six largest banks—Royal Bank of Canada, Toronto-Dominion Bank, and Bank of Montreal—have developed plans aiming to generate millions of dollars through AI investments. These banks are shifting from experimental AI projects to applying AI in areas like chatbots, internal tool development, and reducing reliance on third-party software.
Other major institutions, including Bank of Nova Scotia, Canadian Imperial Bank of Commerce, and National Bank of Canada, have also announced various AI initiatives. The Canadian government has stated it has secured access to Anthropic's Project Glasswing, which grants enterprises access to the Mythos system. It remains unclear which Canadian banks are currently participating in this project.
The Canadian Bankers Association emphasized that banks have made substantial investments to protect the financial system and adhere rigorously to OSFI's high standards for cybersecurity risk management and incident reporting.
In June, Bruce Ross, head of the AI unit at Royal Bank of Canada, commented that Mythos underscores the evolving landscape of cyber attacks, forcing organizations to react swiftly as new exploits can emerge almost immediately upon the discovery of a vulnerability. He stated, "The industry's current approach involves building our own AI defense systems... and we will continue to do so."