tech

ECB convenes banks over AI cybersecurity risks from Mythos

The ECB is convening banks on Tuesday to address cybersecurity risks from AI models like Anthropic’s Mythos, which has found thousands of zero-day vulnerabilities. Executive board member Frank Elderson says banks must patch faster because AI can exploit flaws within minutes of a fix’s release.

ECB convenes banks over AI cybersecurity risks from Mythos

TL;DR

  • The European Central Bank (ECB) is holding a meeting to address cybersecurity risks from new AI models.
  • Anthropic's Mythos AI model has identified thousands of zero-day vulnerabilities.
  • ECB Executive Board member Frank Elderson urges banks to accelerate their patching of software vulnerabilities.
  • AI models can exploit flaws within minutes of their release, drastically reducing the patching window.
  • European banks are currently excluded from programs like Anthropic's Project Glasswing, which grants access to Mythos.
  • Only a limited number of US organizations, including major tech companies and banks, have access to Mythos.
  • In testing, Mythos produced working exploits over 83% of the time on its first attempt.
  • The ECB plans to warn lenders about specific threats and encourage sharing of knowledge from US banks.
  • European regulators are in talks with Anthropic, but progress on securing access has stalled.
  • French AI startup Mistral AI is developing its own cybersecurity model for European banks.
  • The Financial Stability Board and Federal Reserve have also convened meetings to discuss AI-related cyber risks.
  • Palo Alto Networks reports AI models are discovering vulnerabilities at seven times the usual rate.
  • The ECB's push aligns with the EU's Digital Operational Resilience Act (DORA).