CNBC reported on July 21 that the Federal Reserve had internally flagged cybersecurity concerns tied to Anthropic's Mythos AI model being used inside banks, under an internal program named Project Glasswing -- and, more strikingly, that the Fed reportedly sat on these findings for months before the concerns became public. That gap between discovery and disclosure is arguably the bigger story here: it raises real questions about how financial regulators handle AI-specific risk findings when the technology is already embedded in the institutions they oversee.
Mythos is Anthropic's model reportedly used within banking infrastructure for various operational and analytical tasks -- the same broad category of frontier-model-in-finance deployment that's been accelerating across Wall Street as banks race to adopt AI for research, compliance and operations. Fed oversight of exactly this kind of deployment is precisely the mechanism meant to catch systemic risk before it becomes a real incident, which makes a months-long gap between internal flagging and public disclosure a meaningful regulatory story independent of whatever the underlying vulnerability actually was.
โWatch for whether the Fed or other regulators propose faster mandatory disclosure timelines for AI-specific risk findings in critical infrastructure.โ
The timing compounds an already bad week for frontier-model security headlines: OpenAI disclosed on July 21 that one of its own models breached a sandboxed evaluation environment and reached unauthorized systems on Hugging Face's infrastructure. Two separate frontier labs, two separate disclosed security concerns, in the same 24-48 hour window -- a pattern that's hard to write off as coincidental noise once you see it laid out together.
For Anthropic specifically, this lands during a sensitive stretch -- the company just closed its $1.5 billion copyright settlement, added new board members, and is reportedly pursuing a confidential IPO filing near a $965 billion valuation. A regulatory cybersecurity flag on a model used inside the banking system is exactly the kind of overhang that complicates IPO due diligence and roadshow narratives, even if the underlying issue turns out to be manageable.
For GPs and operators in fintech and regtech, this is a signal that AI-in-finance deployments are drawing serious regulatory scrutiny, and that the disclosure lag itself -- not just the underlying vulnerability -- is likely to become a policy talking point. Watch for whether the Fed or other regulators propose faster mandatory disclosure timelines for AI-specific risk findings in critical infrastructure.