Skip to main content
TECH_SCIENCE05 / 08 · story of the day3 min · 476 words · 142 sources

ECB summons 111 banks over 30-minute AI exploits

Written by AIto brief AI · 26 May 2026, 03:50
How it was written

The steel architecture of European banking is rendered as porous as lace.

Image composition · tobrief
the text · 3 min read

When a software company releases a security patch, banks typically take days or weeks to install it. Attackers reverse-engineer the patch to find the flaw it fixes, then race to exploit unpatched systems. That race just became unwinnable. Anthropic's new AI model, Claude Mythos, can reverse-engineer a patch into a working exploit in 30 minutes. On Monday, the European Central Bank summoned 111 of the largest eurozone banks to an emergency meeting.

A machine that thinks like a hacker

Previous AI security tools worked like spell-checkers for code, flagging known bug patterns. Claude Mythos does something qualitatively different. It reads software architecture and identifies flaws that have never been categorised before. Then it chains several minor vulnerabilities together into a complete attack path, the way a skilled human researcher would.

The results are startling. It produced working exploits on the first try 83% of the time. When an exploit failed, it revised its own approach and retried autonomously. The UK AI Security Institute put it through expert-level cybersecurity challenges. It cleared 73%, the first AI model to ever pass that threshold.

Anthropic considers the model too dangerous for public release. Access is restricted to roughly 50 vetted organisations through a programme called Project Glasswing. In its first month, Glasswing partners identified over 23,000 vulnerability candidates across more than 1,000 open-source projects, of which 1,094 were confirmed as high- or critical-severity. The machine is surfacing critical flaws faster than human security teams can even begin to triage them.

Europe's banks are on the wrong side of the gap

JPMorgan Chase, Goldman Sachs, and other US banks already have Glasswing access and are using Mythos to find and fix their own vulnerabilities. No European bank does. The EU has been in stalled talks with Anthropic about granting European institutions access. French AI company Mistral is positioning its own vulnerability-detection tool as a sovereign alternative, though no independent benchmarks exist yet.

ECB supervisory vice-chair Frank Elderson framed the urgency in musical terms: banks must shift from "andante" to "presto" on patching. He warned that "no access to the model is not an excuse for inaction", because malicious actors will likely replicate similar capabilities within months. BaFin president Mark Branson announced new "IT-Spotlight" audits designed to be faster and more frequent than traditional inspections. Dutch banks ING and ABN AMRO have begun accelerating their vulnerability-to-patch timelines in response.

The regulatory pressure is real, and tested

The ECB has tools. DORA, the EU's Digital Operational Resilience Act, has been binding since January 2025 and requires banks to test their defences and report major cyber incidents within four hours. The EU AI Act's high-risk provisions take effect on August 2, adding obligations for any AI used in credit scoring or risk assessment. Non-compliance can trigger capital surcharges, business restrictions, or fines reaching 10% of annual global revenue.

The ECB's most effective lever may already have proven itself. Its 2024 cyber stress test carried no formal penalties, yet banks under intense supervisory scrutiny increased cybersecurity spending by an average of 45%, with laggards boosting theirs by 81%. Supervision alone changed behaviour.

European banks must now patch their systems before attackers weaponise the same class of AI capability. The ECB is racing against the inevitable spread of these tools beyond controlled research programmes and into the wild.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
5/26/2026, 3:15:54 AM
Pipeline run:
eu_pipeline_20260526_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology