Big News: Kosli’s achieves Series A milestone with Deutsche Bank as an investor - Read the announcement
New: Kosli Answers is here! AI-powered insights for compliance and security. Learn more →
Mythos SDLC governance

Here’s what Mythos is really exposing inside banking and financial services

Bruce Johnston
Published July 30, 2026 in features
clock icon 4 min read

In April, Anthropic disclosed that its new AI model, Claude Mythos, had found a vulnerability in OpenBSD that survived 27 years of human review. Mozilla used the same model to find 271 security flaws in Firefox in a single evaluation pass.

Anthropic says Mythos has identified “thousands of high-severity vulnerabilities, including some in every major operating system and web browser.” Bank of England governor Andrew Bailey put it more bluntly: Anthropic “may have found a way to crack the whole cyber risk world open.”

Within hours of these disclosures, the US Treasury Secretary and the Federal Reserve chair convened bank CEOs. JPMorgan was the only bank in the initial 40-company Glasswing consortium given early access to the Mythos, but Morgan Stanley, Goldman Sachs and BNY Mellon confirmed on earnings calls that they gained access soon after.

Since then, the general advice has been as you might expect - scan continuously, invest in detection, strengthen response and recovery.

All of this is - of course - correct, but one line from the coverage points to a deeper problem. ENISA, the EU’s cybersecurity agency, warned that Mythos has shown existing approaches to vulnerability disclosure and patching “can potentially becomestructurally inadequate.”

Not under-resourced, or too slow. Structurally inadequate.

The mismatch in speed between AI and Governance

Banks with Mythos access are reportedly being handed hundreds to thousands of findings. Patches that once waited weeks now land in days. ING told S&P Global Market Intelligence it is working to compress “the time between discovery and remediation.”

But, every one of those fixes is a production change and production changes move through governance built for a slower world.

One engineering leader at a major European bank told us this pressure was real long before Mythos appeared. In his bank, as with most banks, every deployment already has to clear a long chain of separate approval stations before it reaches production.

In his experience, technology is the easy part. “You can quite easily change technology,” he said. “It’s the processes, and the process owners behind them, that are the hardest things in the organisation to change.”

If AI means 10x or 100x more changes, from emergency patching today to AI-assisted development tomorrow, does anyone have a plan to 10x or a 100x their change advisory board?

Obviously, nobody is going to do that. The way we approach governance has to change.

An industry view from inside a tier one bank

Another technology executive in financial services told us their department maintains well over a hundred development tools, each of which has to be patched, managed and kept compliant.

AI-assisted discovery is not his bottleneck - his teams already have a backlog of thousands of known, deterministic vulnerabilities waiting to be fixed, including low-severity findings that can be chained together into serious exploits. Exactly the technique Mythos has proven can now be automated.

Their real problem is more basic. The bank holds hundreds of terabytes of build artifacts, with no central record of which ones are actually running in production. Application registers are so coarse that a single entry can cover hundreds of components. When a new vulnerability lands, answering “are we exposed?” means asking teams, one by one, and waiting.

That gap exists whether the machine-speed change comes from an attacker’s model, an emergency patching programme, or your own developers shipping AI-written code. The common failure is governance designed for a world where a person looked at every change before it moved.

Automated governance is needed to answer these questions

What banks need is not a faster change advisory board. It’s a continuous, provable record of what has been built, what has been checked, and what is running - so that “are we exposed, and has the fix actually shipped?” has an answer in minutes, from evidence, rather than a scramble through tickets and screenshots.

Anthropic committed to publishing its Glasswing findings and security recommendations within 90 days of the April disclosure. That report is due shortly, and the commentary around it will once again be about scanning and patching.

The harder question is the one it won’t answer: six months from now, can you prove what’s running in production?


ABOUT THIS ARTICLE

Published July 30, 2026, in features

AUTHOR
Get started

Ready to ship at
AI speed, safely?

See how Kosli automates SDLC Governance inside your environment.

Governing 14,383,047 compliance events across the world's largest banks and regulated enterprises