In short
Q2 2026 brought frontier AI cyber risk into sharper supervisory focus following Anthropic’s restricted deployment of Mythos through Project Glasswing, which demonstrated that advanced models can identify and chain software vulnerabilities at a pace that may outstrip remediation capacity. Authorities across major markets warned that these capabilities could compress patching windows, lower barriers to sophisticated attacks and amplify system-wide disruption through shared software, cloud and critical third-party dependencies. Supervisory responses largely reinforced existing cyber and operational resilience expectations, but with greater emphasis on speed: current asset and dependency inventories, accelerated risk-based patching, stronger board oversight, tested containment and recovery, and credible third-party fallback arrangements. IOSCO and the Financial Stability Board also advanced practical tools and frameworks for proportionate AI oversight including at the intersection of cyber and third-party risk management.
Project Glasswing places frontier AI cyber capability behind controlled access
On 7 April, Anthropic announced Project Glasswing and began giving selected cybersecurity organisations, critical software providers and infrastructure operators access to Claude Mythos Preview. Anthropic described the unreleased, general purpose model as substantially more capable than its earlier systems at identifying and exploiting software vulnerabilities, including through autonomous vulnerability discovery and exploit chaining. Rather than releasing the model generally, Anthropic used a gated access arrangement under which participants could deploy it for vulnerability detection, penetration testing and other defensive work across first party and open source software.
Initial Project Glasswing results brought the operational implications into sharper focus. Anthropic reported that approximately 50 participants had identified more than 10,000 vulnerabilities of high or critical severity within the first month. The bottleneck had therefore shifted from finding vulnerabilities to fixing them: AI could surface flaws faster than security teams could verify and disclose them, software maintainers could develop patches, and users could deploy the resulting updates. As models with similar capabilities become more widely available, the window between vulnerability discovery and exploitation could narrow further.
In June, Anthropic extended this approach with Fable 5 and Mythos 5, two versions of the same underlying model distinguished by their safeguards and access conditions. Fable 5 was released generally with safety classifiers, while Mythos 5 remained restricted to Project Glasswing participants with some cyber safeguards lifted. Access to both models was however suspended on 12 June following a US government directive linked to a reported safeguard bypass, before the controls were lifted again on 30 June. Fable 5 returned globally on 1 July, while Mythos 5 was initially restored to a set of US organisations.
A global wave of frontier AI warnings sharpens cyber resilience expectations
Within weeks of the Mythos announcement, a small number of early interventions developed into a concentrated cross-regional wave of regulatory communications. From late April through to early July, nearly 20 financial regulatory authorities and bodies across Asia and the Pacific, Europe and the United States issued warning statements, frequently coupled with targeted guidance.
In this new world, weaknesses that once seemed isolated can now have a system-wide domino-effect, enabling new forms of exploitation that were previously out of reach for most malicious actors.
Simone Constant, ASIC Commissioner
The statements shared a common risk message: Frontier models could materially reduce the expertise, cost and time required to conduct sophisticated cyber operations by automating vulnerability discovery and exploit development, identifying previously unknown weaknesses at scale and linking individually lower rated vulnerabilities into higher impact attack paths. More autonomous models could also coordinate multiple stages of an attack across interconnected systems. These capabilities would expand the range of credible threat actors, shorten the interval between vulnerability discovery or disclosure and exploitation, and increase the volume of vulnerabilities and security updates that firms and their providers must process. Entities with legacy systems, weaker baseline controls or more limited specialist capacity were identified as particularly exposed.
European Systemic Risk Board analysis extends the focus to financial stability transmission
In late June, the European Systemic Risk Board equally issued a warning on systemic cyber risks from frontier AI models and an accompanying analysis of their financial stability implications. The work treated the development as a structural increase in systemic cyber risk to the EU financial system and broadened the focus from the resilience of individual institutions to the channels through which disruption could become correlated or system-wide.
The analysis identified several asymmetries. Threat actors may be able to deploy frontier models without the uptime, change management, testing and validation constraints that apply to financial institutions. Less-resourced institutions may face a disproportionate burden because defensive tooling, specialist staffing and regulatory interaction involve costs that do not necessarily scale with institutional size. Differences in access to advanced models may also create jurisdictional asymmetries, particularly given the concentration of leading providers outside the EU and the possibility of export controls or other access restrictions.
A further concern was the potential collapse of existing defensive time buffers. Frontier models could allow released patches to be reverse-engineered and converted into working exploits before all affected institutions can safely test and deploy the updates. This creates a tension between rapid remediation and operational continuity: delaying a patch leaves systems exposed, while compressing testing and change processes increases the risk of outages, failed deployments and rollbacks in critical systems.
The systemic transmission channels arise from common exposures. Financial institutions frequently depend on the same software, open source components, cloud infrastructure, cybersecurity services and other critical providers. A vulnerability in a widely used component could therefore result in clustered attacks or correlated disruption across multiple institutions. Where an incident affects payment, clearing, settlement or other less substitutable operational infrastructure, the impact could extend to the continuity of financial services, public confidence and market volatility.