Central Banks Put Anthropic's Mythos on Watch — Who's Next?
Australia and New Zealand's central banks are formally tracking Anthropic's Mythos AI model following the company's own warning about its cyberattack potential. The move signals a new regulatory era where AI capability claims become systemic risk disclosures.
- RBA and RBNZ issued separate statements on April 22, 2026 confirming they are monitoring Anthropic's Mythos AI model over cyberattack concerns.
- Anthropic's own disclosure that Mythos can enable sophisticated cyberattacks triggered the central bank response.
- This marks the first time central banks have publicly named a specific AI model as a financial stability risk.
- The key tension: Anthropic's transparency may have created a regulatory trap that slows Mythos adoption in the financial sector.
Why Did Anthropic Admit Mythos Could Enable Cyberattacks?
According to Bloomberg Technology's April 22, 2026 report, Anthropic PBC stated that Mythos is "powerful enough to enable sophisticated cyberattacks" in its model release documentation. This is a remarkable admission for a company that has built its brand around safety-first AI development. Anthropic's stated reasoning follows its established Responsible Scaling Policy framework, which requires the company to disclose new capability thresholds when they are crossed. But the timing is suspicious. Anthropic released this disclosure just as it is pushing Mythos into enterprise markets, including financial services. The company reportedly believed that proactive disclosure would preempt criticism and demonstrate good faith. Instead, it handed regulators a ready-made justification for intervention. According to the RBA's statement, the bank is "closely monitoring developments" around Mythos to assess potential risks to Australia's financial infrastructure. My read: Anthropic miscalculated. The company assumed transparency would build trust. Instead, it created a documented risk profile that regulators now have a duty to act on. You cannot unring a bell like that.What Exactly Are the RBA and RBNZ Afraid Of?
The RBNZ's statement, also reported by Bloomberg on April 22, expressed concern about "potential systemic implications" if Mythos capabilities were misused against banking networks. This is not abstract fear. Central banks are responsible for payment systems, settlement infrastructure, and the stability of the banking sector. A model capable of autonomously identifying zero-day vulnerabilities and crafting exploit code at scale changes the threat landscape.How Does This Compare to How Other AI Models Are Being Treated?
The contrast with OpenAI and Google DeepMind is instructive. Neither company has made equivalent public disclosures about their most advanced models' cyber capabilities, nor have central banks issued monitoring statements about GPT-5.5 or Gemini 3. This is not because those models are less capable — it is because those companies have chosen different disclosure strategies.| Dimension | Anthropic Mythos | OpenAI GPT-5.5 | Google Gemini 3 |
|---|---|---|---|
| Central bank monitoring | Yes (RBA, RBNZ) | None reported | None reported |
| Cyberattack capability disclosure | Explicit, in release docs | Vague safety language | Not disclosed |
| Financial sector positioning | Enterprise push underway | Azure/cloud partnerships | Cloud/enterprise defaults |
| Regulatory posture | Proactive transparency | Reactive, lobbies quietly | Reactive, minimal disclosure |
| Short-term regulatory risk | High | Low | Low |
| Verdict | Transparency trap | Strategic ambiguity wins | Strategic ambiguity wins |
Who Benefits From This Regulatory Attention?
The immediate beneficiaries are cybersecurity firms. According to the RBA statement, the bank will work with "existing cybersecurity partners" to assess Mythos-related risks. Australian and New Zealand financial institutions are likely to increase spending on AI-specific threat detection in response to these statements. Companies like CrowdStrike, Palo Alto Networks, and local firms like CyberCX stand to gain. The losers are more interesting. Anthropic's enterprise sales team now faces a harder pitch in the financial sector. Banks that were considering Mythos for internal use must now weigh regulatory optics against technical capability. Meanwhile, OpenAI and Google can quietly position their models as "safer" by virtue of not having triggered central bank scrutiny — regardless of whether that is technically true.What Happens Next?
Three scenarios are plausible over the next 12 months. First, the RBA and RBNZ could issue formal guidance on AI model deployment in financial infrastructure, requiring banks to assess Mythos-class model usage. Second, other central banks — particularly the Bank of England and the Federal Reserve — could follow with their own monitoring statements, creating a cascade effect. Third, Anthropic could attempt to preempt regulation by releasing a "restricted" version of Mythos for financial sector use, with reduced cyber capabilities. According to the Bloomberg report, neither central bank has specified a timeline for concluding its assessment. The open-ended nature of the monitoring suggests regulators are waiting to see how Mythos is actually deployed before deciding whether to act. This uncertainty is itself a cost for Anthropic and its enterprise customers. My prediction: The Bank of England will issue a similar monitoring statement within 90 days, citing "alignment with international regulatory practice." This will turn a regional issue into a global pattern.- The Bank of England will issue a formal monitoring statement on Mythos-class AI models by July 2026, citing coordination with RBA and RBNZ.
- At least two of Australia's four major banks will postpone or cancel planned Mythos enterprise deployments by September 2026, citing regulatory uncertainty.
- Anthropic will release a restricted "Financial Edition" of Mythos with reduced offensive cyber capabilities by Q1 2027, in an attempt to regain regulatory confidence.
- March 2026Mythos safety evaluation complete
Anthropic identifies advanced cyber capabilities during internal testing.
- April 2026Mythos public release
Anthropic discloses cyberattack potential in model release documentation.
- April 22, 2026RBA and RBNZ monitoring statements
Both central banks issue separate statements confirming they are monitoring Mythos.
- April 2026Financial sector review begins
Banks and financial institutions begin internal assessments of Mythos deployment risks.
- Anthropic's own safety disclosure created the regulatory hook that central banks are now using to justify oversight.
- Strategic ambiguity, not transparency, is emerging as the winning regulatory strategy for frontier AI labs.
- The RBA and RBNZ statements will likely trigger copycat monitoring from larger central banks, especially the Bank of England.
- Anthropic faces a no-win situation: it cannot retract its disclosure without damaging its safety brand, but the disclosure is now suppressing enterprise adoption.
- Cybersecurity vendors are the clear near-term beneficiaries of this regulatory attention.
Source and attribution
Bloomberg Technology
RBA, RBNZ Monitor Anthropic’s Mythos Over Cyberattack Fears
Discussion
Add a comment