ECB calls in 111 banks over AI exploits

The steel architecture of European banking is rendered as porous as lace.
Image composition · tobriefWhen a software company issues a security patch, banks usually need days, sometimes weeks, to install it across complex systems. Attackers study the patch, identify the weakness it fixed, and then move against institutions that have not yet updated.
That gap is closing fast. Anthropic's new AI model, Claude Mythos, can turn a patch into a working exploit in 30 minutes. On Monday, the European Central Bank called 111 of the largest eurozone banks into an emergency meeting.
A machine that thinks like a hacker
Older AI security tools worked mainly as code checkers, spotting familiar bug patterns. Claude Mythos goes further. It reads the structure of software, finds flaws that have never been categorised before, and links small weaknesses into a full attack path, much as an experienced human researcher would.
The numbers explain why supervisors are alarmed. The model produced working exploits on the first attempt 83% of the time. When an attempt failed, it adjusted its method and tried again on its own. The UK AI Security Institute tested it on expert-level cybersecurity challenges. It passed 73%, the first AI model to cross that threshold.
Anthropic says the model is too dangerous for public release. Access is limited to roughly 50 vetted organisations through Project Glasswing. In its first month, Glasswing partners identified more than 23,000 vulnerability candidates across over 1,000 open-source projects, with 1,094 confirmed as high- or critical-severity. The machine is finding serious flaws faster than human teams can sort them.
Europe's banks are on the wrong side of the gap
JPMorgan Chase, Goldman Sachs and other US banks already have Glasswing access and are using Mythos to find and fix their own weaknesses. No European bank does. The EU has been in stalled talks with Anthropic over access for European institutions. France's Mistral is presenting its own vulnerability-detection tool as a sovereign alternative, though it has not yet been tested against independent benchmarks.
For Malta, this is not a distant banking story. The island's financial services sector sits inside the same eurozone supervisory system, and its reputation still carries the memory of FATF grey-listing. A faster cyber patching regime is another cost of operating in a financial model that depends on trust, cross-border access and regulatory credibility.
ECB supervisory vice-chair Frank Elderson put the urgency in musical terms: banks must move from "andante" to "presto" on patching. He warned that "no access to the model is not an excuse for inaction", because hostile actors are likely to copy similar capabilities within months. BaFin president Mark Branson announced new "IT-Spotlight" audits, intended to be quicker and more frequent than traditional inspections. Dutch banks ING and ABN AMRO have started shortening the time between finding a vulnerability and applying a patch.
The regulatory pressure is real, and tested
The ECB has levers it can use. DORA, the EU's Digital Operational Resilience Act, has been binding since January 2025. It requires banks to test their digital defences and report major cyber incidents within four hours. The EU AI Act's high-risk provisions take effect on 2 August, adding obligations for AI used in credit scoring or risk assessment. Failure to comply can lead to capital surcharges, business restrictions, or fines of up to 10% of annual global revenue.
The ECB's strongest tool may already have been tested. Its 2024 cyber stress test carried no formal penalties, but banks under the closest supervisory scrutiny increased cybersecurity spending by an average of 45%. The weakest performers lifted spending by 81%. Supervision changed behaviour even without fines.
European banks now have to patch systems before attackers weaponise the same class of AI capability. The ECB is trying to narrow the window before tools like Mythos move beyond controlled research programmes and into open use.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/26/2026, 3:15:54 AM
- Pipeline run:
- eu_pipeline_20260526_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication