Anthropic frees Mythos partners to share cyber findings

Key Speakers at the India AI Impact Summit
Dario Amodei, CEO of Anthropic
Ruhani Kaur/Bloomberg
  • Key insight: Anthropic's NDA carve-out lets JPMorganChase, the only bank among Project Glasswing's named launch partners, formally share Mythos-surfaced vulnerabilities with community and regional banks for the first time.
  • What's at stake: Smaller banks outside Glasswing depend on partners like JPMorgan to surface Mythos-found vulnerabilities in shared software systems; the carve-out determines whether and how that intelligence now reaches them.
  • Expert quote: Rep. Josh Gottheimer, co-chair of the House Democratic Commission on AI and the Innovation Economy: "No entity should be contractually restricted from warning others, coordinating mitigations, or informing relevant and trusted stakeholders about urgent cyber risks."

Overview bullets generated by AI with editorial review.

Processing Content

Anthropic has reportedly freed partners in its Project Glasswing cybersecurity program, including JPMorganChase , to share vulnerability findings from the company's Mythos model with regulators, industry peers, open-source maintainers and the public.

The carve-out drops a nondisclosure agreement that had kept the findings inside the program since its April 7 launch, according to reporting from Reuters.

The change came the same day Rep. Josh Gottheimer, D-N.J., and co-chair of the House Democratic Commission on AI and the Innovation Economy, released a letter to Anthropic Chief Executive Dario Amodei pressing for exactly that step. Anthropic had told partners about the change in the days prior.

In a related development, the Bank of England, the Financial Conduct Authority (the U.K.'s main financial-services regulator) and HM Treasury (the British government's finance ministry) had told U.K. financial firms three days earlier, in a May 15 statement, to take "active steps" against the cybersecurity risks of frontier AI models.

JPMorgan is the only bank among Glasswing's named launch partners. The program also includes more than 40 additional organizations. With the carve-out, partners can now pass Mythos findings to community and regional banks outside Glasswing.

What Anthropic changed, and what Gottheimer asked for

Gottheimer praised Anthropic for the carve-out.

"No entity should be contractually restricted from warning others, coordinating mitigations, or informing relevant and trusted stakeholders about urgent cyber risks," he wrote.

The letter offered a hospital-and-utility example: A large entity with Mythos access should be free to warn smaller peers running the same systems, he said.

Gottheimer also urged OpenAI to make the same change to its Trusted Access for Cyber program, an invite-only initiative that gives vetted cybersecurity researchers expanded access to OpenAI's most cyber-capable models for defensive work.

UK regulators put expectations on paper

The May 15 statement from U.K. regulators said the "cyber capabilities of current frontier AI models are already exceeding what a skilled practitioner could achieve, and at a significantly higher speed, greater scale and lower cost.

"Firms that have underinvested in core cyber security fundamentals are likely to become progressively more exposed," it warned.

It listed five domains for action: governance and strategy, vulnerability identification and risk management, third-party risk, protection, and response and recovery.

A footnote stresses that the statement does not impose new rules. It pulls together existing operational-resilience guidance.

The authorities pointed firms to a May 1 National Cyber Security Centre blog post warning of an oncoming "patch wave" of software updates driven by AI-aided vulnerability discovery.

No U.S. financial regulator has put comparable expectations on the record.

What Mythos has surfaced

Mythos has identified thousands of previously unknown security flaws (known as zero-days) across major operating systems and browsers, and produces working exploits on the first attempt in more than 83% of cases, according to Anthropic's own red-team testing.

Mozilla disclosed in May that Mythos surfaced 271 Firefox vulnerabilities, all patched in Firefox 150, which Mozilla released April 21.

Palo Alto Networks disclosed 26 vulnerabilities covering 75 individual software defects in a single May 13 advisory. The company's typical monthly volume is fewer than five. It said attackers had not yet exploited any of the vulnerabilities in the wild.

Anthropic's Glasswing launch page committed to "report publicly on what we've learned" from the program within 90 days. The program launched April 7, so that report is due by July 6.


For reprint and licensing requests for this article, click here.
Cyber security Artificial intelligence Regulation and compliance JPMorgan Chase Risk management Technology
MORE FROM AMERICAN BANKER
Load More