
The European Central Bank has called major lenders to a hastily arranged meeting on May 24, 2026, warning that rapid advances in artificial intelligence are significantly amplifying cyber security risks across the financial system, according to reports from Financial Times. The urgent supervisory intervention underscores growing concern among regulators that next-generation AI models are exposing critical weaknesses in banks' IT infrastructure, sharply compressing the time available to detect and fix vulnerabilities before they can be exploited. ECB supervisors are expected to tell lenders that the cyber threat landscape is evolving far faster than existing defence systems, and that banks must materially accelerate response and remediation cycles. The latest developments come as the ECB continues to push banks to address vulnerabilities exposed by cutting-edge AI tools.
Anthropic released the Claude Mythos Preview in April under Project Glasswing, a restricted program, as reported by Financial Times. Recent evaluations show the scale of what Mythos uncovers. The UK's AI Security Institute (AISI) found Mythos Preview cleared 73% of expert-level Capture the Flag (CTF) challenges. This benchmark represents a significant milestone, as no AI model could pass that benchmark before April 2025. Additionally, Mozilla shipped Firefox 150 with 271 patches for vulnerabilities found by the model, far above prior Opus 4.6 results. Anthropic has said its model has uncovered widespread flaws in digital infrastructure, raising fears that similar tools could be weaponised by malicious actors if broadly deployed.
ECB officials are expected to warn that once software patches are released, AI systems may be able to reverse-engineer underlying vulnerabilities within minutes—dramatically narrowing the remediation window for financial institutions and technology providers, as reported by Financial Times. Frank Elderson, vice-chair of the ECB's supervisory board, said the regulator wants banks to accelerate the rollout of software patches to address vulnerabilities. Elderson warned that attackers can now reverse-engineer fixes within 30 minutes, as reported by Financial Times. He emphasized that the previous 'andante' tempo is no longer sufficient, stating that 'there is a whole range of issues on cyber security that we have been engaging on with the banks for years, which are all still valid, but given the progress in AI, they need to be dealt with faster.' In musical terms, he described the need to go from 'andante' to 'presto' tempo.
The ECB oversees around 111 major banks across the euro area, according to Financial Times reports. Most European lenders sit outside Project Glasswing and lack direct access to frontier models like Mythos. Regulators have also flagged concerns over unequal access to advanced AI tools, with Anthropic reportedly limiting Claude Mythos Preview to a small group of organisations, largely in the United States, leaving several European banks without direct exposure to systems being used to map vulnerabilities. Elderson wants US institutions attending Tuesday's meeting to share testing insights with their Eurozone counterparts. He called the access gap 'unfortunate' but said it cannot justify inaction, emphasizing that whether finance can patch as quickly as frontier AI surfaces new exploits may determine how institutions protect client funds in the near future.