Central Banks Put Anthropic's Mythos on Watch — Who's Next?

Central Banks Put Anthropic's Mythos on Watch — Who's Next?

Australia and New Zealand's central banks are formally tracking Anthropic's Mythos AI model following the company's own warning about its cyberattack potential. The move signals a new regulatory era where AI capability claims become systemic risk disclosures.

On April 22, 2026, the Reserve Bank of Australia and the Reserve Bank of New Zealand issued separate statements confirming they are monitoring Anthropic PBC's Mythos AI model over cyberattack concerns. This is the first time central banks have publicly flagged a specific AI model as a financial stability risk — and Anthropic's own capability disclosure triggered it.
  • RBA and RBNZ issued separate statements on April 22, 2026 confirming they are monitoring Anthropic's Mythos AI model over cyberattack concerns.
  • Anthropic's own disclosure that Mythos can enable sophisticated cyberattacks triggered the central bank response.
  • This marks the first time central banks have publicly named a specific AI model as a financial stability risk.
  • The key tension: Anthropic's transparency may have created a regulatory trap that slows Mythos adoption in the financial sector.

Why Did Anthropic Admit Mythos Could Enable Cyberattacks?

According to Bloomberg Technology's April 22, 2026 report, Anthropic PBC stated that Mythos is "powerful enough to enable sophisticated cyberattacks" in its model release documentation. This is a remarkable admission for a company that has built its brand around safety-first AI development. Anthropic's stated reasoning follows its established Responsible Scaling Policy framework, which requires the company to disclose new capability thresholds when they are crossed. But the timing is suspicious. Anthropic released this disclosure just as it is pushing Mythos into enterprise markets, including financial services. The company reportedly believed that proactive disclosure would preempt criticism and demonstrate good faith. Instead, it handed regulators a ready-made justification for intervention. According to the RBA's statement, the bank is "closely monitoring developments" around Mythos to assess potential risks to Australia's financial infrastructure. My read: Anthropic miscalculated. The company assumed transparency would build trust. Instead, it created a documented risk profile that regulators now have a duty to act on. You cannot unring a bell like that.

What Exactly Are the RBA and RBNZ Afraid Of?

The RBNZ's statement, also reported by Bloomberg on April 22, expressed concern about "potential systemic implications" if Mythos capabilities were misused against banking networks. This is not abstract fear. Central banks are responsible for payment systems, settlement infrastructure, and the stability of the banking sector. A model capable of autonomously identifying zero-day vulnerabilities and crafting exploit code at scale changes the threat landscape.
Central Banks Put Anthropics Mythos on Watch — Whos Next?
The specific scenarios regulators are likely modeling include: targeted phishing campaigns at scale that bypass existing email filters, automated vulnerability discovery in core banking software, and social engineering attacks that adapt in real-time. According to Anthropic's own technical documentation, Mythos demonstrates "significantly advanced" capabilities in code generation and vulnerability analysis compared to its predecessor Claude 4. Neither central bank has yet taken formal regulatory action — no bans, no restrictions, no mandatory reporting requirements. But monitoring is the first step. In regulatory terms, this is the equivalent of putting a suspect on a watchlist. The next steps could include information-sharing requirements, deployment restrictions in critical infrastructure, or mandatory stress-testing of financial systems against Mythos-class threats.

How Does This Compare to How Other AI Models Are Being Treated?

The contrast with OpenAI and Google DeepMind is instructive. Neither company has made equivalent public disclosures about their most advanced models' cyber capabilities, nor have central banks issued monitoring statements about GPT-5.5 or Gemini 3. This is not because those models are less capable — it is because those companies have chosen different disclosure strategies.
DimensionAnthropic MythosOpenAI GPT-5.5Google Gemini 3
Central bank monitoringYes (RBA, RBNZ)None reportedNone reported
Cyberattack capability disclosureExplicit, in release docsVague safety languageNot disclosed
Financial sector positioningEnterprise push underwayAzure/cloud partnershipsCloud/enterprise defaults
Regulatory postureProactive transparencyReactive, lobbies quietlyReactive, minimal disclosure
Short-term regulatory riskHighLowLow
VerdictTransparency trapStrategic ambiguity winsStrategic ambiguity wins
This comparison reveals a perverse incentive. Anthropic's safety-first approach has made it the most scrutinized AI company in the world, while competitors who say less face fewer regulatory obstacles. According to industry analysts cited in the Bloomberg report, this could push other AI developers toward more opaque disclosure practices.

Who Benefits From This Regulatory Attention?

The immediate beneficiaries are cybersecurity firms. According to the RBA statement, the bank will work with "existing cybersecurity partners" to assess Mythos-related risks. Australian and New Zealand financial institutions are likely to increase spending on AI-specific threat detection in response to these statements. Companies like CrowdStrike, Palo Alto Networks, and local firms like CyberCX stand to gain. The losers are more interesting. Anthropic's enterprise sales team now faces a harder pitch in the financial sector. Banks that were considering Mythos for internal use must now weigh regulatory optics against technical capability. Meanwhile, OpenAI and Google can quietly position their models as "safer" by virtue of not having triggered central bank scrutiny — regardless of whether that is technically true.
My analysis: Anthropic's transparency policy has become a competitive liability that its rivals will exploit. In the short term, expect RBA and RBNZ monitoring to expand into formal consultations within six months, creating procurement hesitation across Australian and New Zealand financial institutions. In the long term, this episode will reshape how AI companies disclose dangerous capabilities — not toward more transparency, but toward more strategic ambiguity. The company that gains most is OpenAI, which can now position itself as the "unflagged" alternative for regulated industries. Anthropic loses enterprise credibility in financial services, its most important growth vertical. The deeper problem: Anthropic cannot walk back its disclosure without destroying its safety brand, so it is trapped in a position of maximum regulatory exposure with no clean exit.

What Happens Next?

Three scenarios are plausible over the next 12 months. First, the RBA and RBNZ could issue formal guidance on AI model deployment in financial infrastructure, requiring banks to assess Mythos-class model usage. Second, other central banks — particularly the Bank of England and the Federal Reserve — could follow with their own monitoring statements, creating a cascade effect. Third, Anthropic could attempt to preempt regulation by releasing a "restricted" version of Mythos for financial sector use, with reduced cyber capabilities. According to the Bloomberg report, neither central bank has specified a timeline for concluding its assessment. The open-ended nature of the monitoring suggests regulators are waiting to see how Mythos is actually deployed before deciding whether to act. This uncertainty is itself a cost for Anthropic and its enterprise customers. My prediction: The Bank of England will issue a similar monitoring statement within 90 days, citing "alignment with international regulatory practice." This will turn a regional issue into a global pattern.
  1. The Bank of England will issue a formal monitoring statement on Mythos-class AI models by July 2026, citing coordination with RBA and RBNZ.
  2. At least two of Australia's four major banks will postpone or cancel planned Mythos enterprise deployments by September 2026, citing regulatory uncertainty.
  3. Anthropic will release a restricted "Financial Edition" of Mythos with reduced offensive cyber capabilities by Q1 2027, in an attempt to regain regulatory confidence.
  1. March 2026
    Mythos safety evaluation complete

    Anthropic identifies advanced cyber capabilities during internal testing.

  2. April 2026
    Mythos public release

    Anthropic discloses cyberattack potential in model release documentation.

  3. April 22, 2026
    RBA and RBNZ monitoring statements

    Both central banks issue separate statements confirming they are monitoring Mythos.

  4. April 2026
    Financial sector review begins

    Banks and financial institutions begin internal assessments of Mythos deployment risks.

March 2026: Anthropic completes Mythos safety evaluations and identifies advanced cyber capabilities. April 2026: Anthropic releases Mythos with public disclosure of cyberattack potential. April 22, 2026: RBA and RBNZ issue separate monitoring statements. April 2026: Financial sector customers begin internal reviews of Mythos deployments.
  • Anthropic's own safety disclosure created the regulatory hook that central banks are now using to justify oversight.
  • Strategic ambiguity, not transparency, is emerging as the winning regulatory strategy for frontier AI labs.
  • The RBA and RBNZ statements will likely trigger copycat monitoring from larger central banks, especially the Bank of England.
  • Anthropic faces a no-win situation: it cannot retract its disclosure without damaging its safety brand, but the disclosure is now suppressing enterprise adoption.
  • Cybersecurity vendors are the clear near-term beneficiaries of this regulatory attention.
RBA, RBNZ Monitor Anthropic’s Mythos Over Cyberattack Fears
Embedded source image Source: Bloomberg Technology. Original reporting.

Source and attribution

Bloomberg Technology
RBA, RBNZ Monitor Anthropic’s Mythos Over Cyberattack Fears

Discussion

Add a comment

0/5000
Loading comments...