ECB tells 111 banks to patch faster

The steel architecture of European banking is rendered as porous as lace.
Cumadóireacht íomhá · tobriefBanks have long lived with a narrow but manageable delay. A software company issues a security patch, attackers pull it apart to see what flaw was fixed, and banks try to install the update before anyone turns that flaw into a working attack. That window used to be measured in days or weeks. Anthropic's new AI model, Claude Mythos, can turn a patch into a working exploit in 30 minutes. On Monday, the European Central Bank called 111 of the largest eurozone banks into an emergency meeting.
A machine that thinks like a hacker
Earlier AI security tools worked much like spell-checkers for software, spotting familiar bug patterns and warning engineers where to look. Claude Mythos goes further. It reads software architecture, finds weaknesses that have never been categorised before, and links several small vulnerabilities into a single attack path, much as an experienced human researcher would.
The numbers explain why supervisors are worried. It produced working exploits on the first attempt 83% of the time. When an exploit failed, it changed its approach and tried again on its own. The UK AI Security Institute tested it against expert-level cybersecurity challenges; it cleared 73%, the first AI model to pass that mark.
Anthropic regards the model as too dangerous for public release. Access is limited to about 50 vetted organisations under Project Glasswing. In its first month, Glasswing partners found more than 23,000 possible vulnerabilities across over 1,000 open-source projects. Of those, 1,094 were confirmed as high- or critical-severity. The practical problem is simple: the machine is finding serious flaws faster than security teams can sort them.
Europe's banks are on the wrong side of the gap
JPMorgan Chase, Goldman Sachs and other US banks already have Glasswing access and are using Mythos to find and fix their own weaknesses. No European bank does. The EU has been in stalled talks with Anthropic about access for European institutions. France's Mistral is presenting its own vulnerability-detection tool as a sovereign alternative, though it has not yet been tested against independent benchmarks.
ECB supervisory vice-chair Frank Elderson put the point in musical terms: banks must move from "andante" to "presto" on patching. He warned that "no access to the model is not an excuse for inaction", because hostile actors are likely to reproduce similar capabilities within months. BaFin president Mark Branson announced new "IT-Spotlight" audits, intended to be quicker and more regular than traditional inspections. Dutch banks ING and ABN AMRO have already started shortening the time between finding vulnerabilities and patching them.
The regulatory pressure is real, and tested
The ECB is not relying on persuasion alone. DORA, the EU's Digital Operational Resilience Act, has been binding since January 2025. It requires banks to test their defences and report major cyber incidents within four hours. The EU AI Act's high-risk provisions take effect on August 2, adding obligations for AI used in credit scoring or risk assessment. Failure to comply can mean capital surcharges, business restrictions or fines of up to 10% of annual global revenue.
The ECB's strongest lever may be supervision itself. Its 2024 cyber stress test carried no formal penalties, yet banks under close scrutiny increased cybersecurity spending by an average of 45%. The weakest performers raised theirs by 81%. Being watched changed behaviour.
European banks now have to patch systems before attackers weaponise the same kind of AI capability. The ECB is trying to move the sector while these tools are still mostly inside controlled research programmes, because the more difficult moment comes when they are not.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/26/2026, 3:15:54 AM
- Pipeline run:
- eu_pipeline_20260526_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication