Regulators Probe AI Banking Risks From Anthropic's Mythos
Regulators monitor Anthropic’s Mythos AI in Australia and South Korea after concerns its coding power could expose vulnerabilities and stress banks.
Jason Kwon ·

Financial regulators in Australia and South Korea are monitoring Anthropic’s frontier AI model, Mythos, after concerns were raised that it could destabilize banking systems. The scrutiny was reported on Monday, April 20, and is tied to the model’s advanced coding capabilities. Experts have suggested those capabilities could allow unprecedented discovery of cybersecurity weaknesses, increasing the urgency for financial-sector oversight.
In Australia, the Australian Securities and Investments Commission (ASIC) said it is watching developments closely alongside peer regulators to evaluate potential implications for the Australian market. ASIC also said it expects financial services licensees to take proactive steps to protect customers. The statements place responsibility on regulated firms to strengthen safeguards as new technology changes the risk landscape.
The Australian Prudential Regulation Authority (APRA) said it will continue assessing technological developments to support the safety and resilience of the financial system. APRA’s position signals an ongoing review approach focused on system stability, rather than a one-off response. Together, ASIC and APRA’s comments indicate that both market conduct and prudential perspectives are being applied to the same emerging technology risk.
In South Korea, the Financial Supervisory Service (FSS) held a meeting with information security officials from financial firms to examine risks linked to Mythos. Separately, the Yonhap news agency reported that the Financial Services Commission (FSC) convened an emergency meeting with chief information security officers from the FSS, banks, and insurers to discuss those risks.
The meetings underscore that the issue is being treated as a cross-sector concern spanning multiple types of financial institutions.
What remains unclear from the information provided is the specific set of scenarios regulators are prioritizing, the timeline for any follow-up actions, and whether additional supervisory guidance will be issued. It is also not specified how regulators are assessing the model’s capabilities in practice, or what benchmarks they are using to determine whether risks are rising or contained.
For now, the public record described centers on monitoring, evaluation, and coordination with industry security leaders.