Global Financial Regulatory Highlights ReportQ2 2026

Chapter 01 · Cyber & Artificial Intelligence

Anthropic's Mythos and Project Glasswing bring frontier AI cyber risk into global supervisory focus

In short

Q2 2026 brought frontier AI cyber risk into sharper supervisory focus following Anthropic’s restricted deployment of Mythos through Project Glasswing, which demonstrated that advanced models can identify and chain software vulnerabilities at a pace that may outstrip remediation capacity. Authorities across major markets warned that these capabilities could compress patching windows, lower barriers to sophisticated attacks and amplify system-wide disruption through shared software, cloud and critical third-party dependencies. Supervisory responses largely reinforced existing cyber and operational resilience expectations, but with greater emphasis on speed: current asset and dependency inventories, accelerated risk-based patching, stronger board oversight, tested containment and recovery, and credible third-party fallback arrangements. IOSCO and the Financial Stability Board also advanced practical tools and frameworks for proportionate AI oversight including at the intersection of cyber and third-party risk management.

Project Glasswing places frontier AI cyber capability behind controlled access

On 7 April, Anthropic announced Project Glasswing and began giving selected cybersecurity organisations, critical software providers and infrastructure operators access to Claude Mythos Preview. Anthropic described the unreleased, general purpose model as substantially more capable than its earlier systems at identifying and exploiting software vulnerabilities, including through autonomous vulnerability discovery and exploit chaining. Rather than releasing the model generally, Anthropic used a gated access arrangement under which participants could deploy it for vulnerability detection, penetration testing and other defensive work across first party and open source software.

Initial Project Glasswing results brought the operational implications into sharper focus. Anthropic reported that approximately 50 participants had identified more than 10,000 vulnerabilities of high or critical severity within the first month. The bottleneck had therefore shifted from finding vulnerabilities to fixing them: AI could surface flaws faster than security teams could verify and disclose them, software maintainers could develop patches, and users could deploy the resulting updates. As models with similar capabilities become more widely available, the window between vulnerability discovery and exploitation could narrow further.

In June, Anthropic extended this approach with Fable 5 and Mythos 5, two versions of the same underlying model distinguished by their safeguards and access conditions. Fable 5 was released generally with safety classifiers, while Mythos 5 remained restricted to Project Glasswing participants with some cyber safeguards lifted. Access to both models was however suspended on 12 June following a US government directive linked to a reported safeguard bypass, before the controls were lifted again on 30 June. Fable 5 returned globally on 1 July, while Mythos 5 was initially restored to a set of US organisations.

A global wave of frontier AI warnings sharpens cyber resilience expectations

Within weeks of the Mythos announcement, a small number of early interventions developed into a concentrated cross-regional wave of regulatory communications. From late April through to early July, nearly 20 financial regulatory authorities and bodies across Asia and the Pacific, Europe and the United States issued warning statements, frequently coupled with targeted guidance.

In this new world, weaknesses that once seemed isolated can now have a system-wide domino-effect, enabling new forms of exploitation that were previously out of reach for most malicious actors.

Simone Constant, ASIC Commissioner

The statements shared a common risk message: Frontier models could materially reduce the expertise, cost and time required to conduct sophisticated cyber operations by automating vulnerability discovery and exploit development, identifying previously unknown weaknesses at scale and linking individually lower rated vulnerabilities into higher impact attack paths. More autonomous models could also coordinate multiple stages of an attack across interconnected systems. These capabilities would expand the range of credible threat actors, shorten the interval between vulnerability discovery or disclosure and exploitation, and increase the volume of vulnerabilities and security updates that firms and their providers must process. Entities with legacy systems, weaker baseline controls or more limited specialist capacity were identified as particularly exposed.

Exhibit: Warnings and statements issued by authorities on frontier AI cyber risk

30 Apr 2026

Pacific • Australia

Australian Prudential Regulation Authority

The Australian Prudential Regulation Authority calls for a step-change in AI risk management after finding governance, assurance and operational resilience lag adoption. Boards should build AI literacy, align strategy with risk appetite and oversee third parties. Entities should maintain inventories, human oversight, strong testing and patching, plus fallback and exit arrangements. APRA may escalate supervision or enforcement.

View release

European Systemic Risk Board analysis extends the focus to financial stability transmission

In late June, the European Systemic Risk Board equally issued a warning on systemic cyber risks from frontier AI models and an accompanying analysis of their financial stability implications. The work treated the development as a structural increase in systemic cyber risk to the EU financial system and broadened the focus from the resilience of individual institutions to the channels through which disruption could become correlated or system-wide.

The analysis identified several asymmetries. Threat actors may be able to deploy frontier models without the uptime, change management, testing and validation constraints that apply to financial institutions. Less-resourced institutions may face a disproportionate burden because defensive tooling, specialist staffing and regulatory interaction involve costs that do not necessarily scale with institutional size. Differences in access to advanced models may also create jurisdictional asymmetries, particularly given the concentration of leading providers outside the EU and the possibility of export controls or other access restrictions.

A further concern was the potential collapse of existing defensive time buffers. Frontier models could allow released patches to be reverse-engineered and converted into working exploits before all affected institutions can safely test and deploy the updates. This creates a tension between rapid remediation and operational continuity: delaying a patch leaves systems exposed, while compressing testing and change processes increases the risk of outages, failed deployments and rollbacks in critical systems.

The systemic transmission channels arise from common exposures. Financial institutions frequently depend on the same software, open source components, cloud infrastructure, cybersecurity services and other critical providers. A vulnerability in a widely used component could therefore result in clustered attacks or correlated disruption across multiple institutions. Where an incident affects payment, clearing, settlement or other less substitutable operational infrastructure, the impact could extend to the continuity of financial services, public confidence and market volatility.

Authorities reinforce existing controls for a faster threat environment

Against this risk assessment, most authorities reinforced existing cybersecurity, ICT risk and operational resilience requirements. The main change in emphasis concerned the speed and scale at which established controls may need to operate. Governance arrangements are expected to support faster prioritisation and escalation; asset and dependency inventories have to provide a sufficiently current basis for immediate decisions; vulnerability management processes have to accommodate a larger volume of findings and shorter exposure windows; and third-party oversight has to account for common dependencies and possible constraints on providers’ own remediation capacity.

Governance and oversight

A rapid increase in vulnerabilities or incidents may require faster decisions, cross-functional coordination and the reallocation of resources outside ordinary operating cycles.

Boards and senior management should understand the changing threat environment, establish clear ownership and escalation arrangements, integrate the risk into existing governance and resilience frameworks, and ensure sufficient financial, technical and staffing resources. Firms should identify the services and systems requiring priority protection and remediation.

Asset and dependency visibility

Current information is needed to determine rapidly which systems are affected by newly identified vulnerabilities and where containment or remediation should be prioritised.

Firms should maintain accurate inventories of hardware, software, network infrastructure, cloud services, internet-facing systems, APIs, identities, open-source components and material third-party dependencies. Critical, externally exposed and unsupported assets should be clearly identified.

Vulnerability management

Higher volumes of vulnerabilities and shorter exploitation windows may strain existing patching capacity. Firms may need to process more urgent updates while managing the operational risk associated with accelerated testing and deployment.

Authorities called for more frequent vulnerability assessment and security testing; risk-based prioritisation based on exploitability, exposure, data sensitivity and system criticality; procedures for urgent fixes outside routine cycles; automation where appropriate; virtual patching or other compensating controls; and the replacement or upgrade of unsupported systems. Patch deployment should remain subject to testing, documentation and change controls.

Access and network controls

The controls are framed around the possibility that a user, device, privileged account or network component may be compromised, with particular emphasis on limiting automated exploitation and lateral movement.

Expectations included strong and, for privileged access, phishing-resistant multi-factor authentication; least privilege and privileged account controls; hardened configurations; reduced internet exposure; segmentation or micro segmentation; defence-in-depth and zero trust approaches; secure APIs; and appropriate testing and human validation of AI generated code.

Detection and recovery

AI-enabled attacks may progress more quickly than conventional detection and escalation processes, requiring earlier intervention and, where necessary, the rapid restriction or isolation of systems and services.

Firms should maintain comprehensive logging, anomaly detection, security event monitoring and threat intelligence capabilities. Incident arrangements should provide for rapid escalation, pre-planned containment, isolation of affected systems, tested response and recovery plans, reliable backups and regular exercises, including simulated attacks and red team testing.

Third-party risk management

Common providers and software components can transmit the same weakness across multiple institutions, while a sector-wide surge in remediation demand may constrain providers’ ability to meet agreed timelines.

Firms should map material third- and fourth-party dependencies, clarify vendor responsibilities for vulnerability assessment and patching, assess providers’ capacity to respond to simultaneous demand, and maintain appropriate notification, information and audit rights. Authorities also highlighted concentration risk, service level arrangements and credible substitution, portability, exit or fallback options.

These national developments coincided with two broader international initiatives addressing both sides of the supervisory relationship. In May, IOSCO issued its final Supervisory Toolkit for AI Use in Capital Markets, giving authorities non-binding tools for risk-based oversight of AI systems including from a cyber and third-party risk management and outsourcing perspective. In June, the Financial Stability Board (FSB) opened a consultation on sound practices for responsible AI adoption, setting out how financial institutions should design and operate AI controls including those for cyber and Information and Communication Technology (ICT) risk management and third-party AI risk.

IOSCO’s central proposition is that AI oversight should be evidence-based and proportionate. Supervisors should establish whether firms know where and how AI is used, have assigned clear responsibility, and can demonstrate that controls remain effective throughout the system lifecycle. For cyber and operational resilience, the question is whether a firm can prevent, detect, contain and recover from AI-related disruption. For third-party arrangements, supervisors should assess whether the firm retains accountability, understands its dependencies and concentration exposures, and has sufficient information, assurance and contractual rights to monitor providers or exit safely. Inventories, test results, incident logs, recovery exercises and contractual records can provide part of the evidence for making those judgements.

The FSB's proposed approach is to retain existing cyber, ICT and third-party frameworks, but recalibrate them for AI’s speed, autonomy and opacity. For cyber risk, this means tightly controlling what AI agents can access and do, reducing the attack surface and using layered defences to limit the consequences of compromise. It also means shortening remediation cycles without dispensing with testing and change controls, and using virtual patching or other temporary safeguards where permanent fixes cannot be deployed immediately. Resilience testing should cover AI-enabled attacks and agent failures, while defensive AI tools and information sharing should increase the speed and scale of response. For third-party AI, the core principle is that outsourcing does not transfer accountability. Firms should secure meaningful information and audit rights, compensate for provider opacity through additional testing or tighter controls, and not use a service where residual risk cannot be brought within appetite. Concentration and substitutability should be treated as continuity issues, supported by tested alternatives, data portability and manual fallback where necessary.

Authorities support controlled adoption of AI for cyber defence

A growing number of authorities also positioned AI as part of the response to AI-enabled cyber risk. Their central proposition is that, as attackers gain machine speed capabilities, defenders need comparable tools to scan code and infrastructure, uncover attack paths, strengthen threat hunting and monitoring, and accelerate vulnerability triage and remediation. Bank for International Settlement (BIS) staff describe swift adoption of frontier models to review code and fix vulnerabilities as essential, while the IMF and UK authorities similarly argue that defensive capabilities should operate closer to the speed and scale of AI-enabled attacks. South Korea translated this approach into a controlled access model, easing network separation rules for selected, higher capability firms to test advanced models and security tools, with the results intended to inform sector-wide guidance and support.

The support is conditional, however. Authorities expected defensive AI to remain embedded in existing governance, secure development, change management and operational resilience frameworks, with tightly bounded permissions, testing and human validation of AI-generated changes, and credible fallback arrangements. Several authorities including the Australian Prudential Regulation Authority (APRA), India's Securities and Exchange Board (SEBI) and the New York Department of Financial Services stressed that automation should not introduce unreviewed code, configuration changes or operational instability. They also highlighted a collective action dimension: trusted defenders need timely access to advanced tools, while vulnerabilities and remediation lessons should be shared across institutions and common suppliers, including to narrow capability gaps for smaller firms. Defensive AI is therefore being framed as a force multiplier for cyber hygiene and resilience, not a substitute for them.

Key sources