Economy May 13, 2026 06:26 AM

ECB official urges euro-area banks to harden defences against AI-guided cyberattacks

Frank Elderson warns institutions and their contractors to close vulnerabilities as access gaps to Anthropic's Mythos widen internationally

By Jordan Park

An ECB supervisory vice chair has called on banks across the euro area to act swiftly to shore up IT systems against cyberattacks assisted by advanced AI tools such as Anthropic's Mythos. The official said limited regional access to Mythos increases the urgency for banks to remediate weaknesses, while noting that even more capable AI models could arrive quickly and intensify the threat.

ECB official urges euro-area banks to harden defences against AI-guided cyberattacks

Key Points

  • ECB board member and supervisory vice chair Frank Elderson urged euro-area banks to prepare rapidly for cyberattacks aided by Anthropic's Mythos or similar AI tools - impact: banking sector, IT services.
  • Elderson warned that lack of access to Mythos in the euro area increases the urgency for banks to act now, rather than delay remediation - impact: financial institutions, regulators.
  • Officials caution that even more capable AI models could be released quickly, requiring ongoing preparedness from banks and their contractors - impact: cybersecurity firms, software vendors.

Frank Elderson, a member of the European Central Bank's board and vice chair of its bank supervision function, has urged banks in the euro area to accelerate preparations for cyberattacks that could be launched with the help of Anthropic's Mythos model or comparable AI systems.

In an interview published in the ECB's Supervision Newsletter, Elderson stressed that the absence of direct access to Mythos among many euro-area lenders should not be seen as a reason to delay action. "Lack of access is not an excuse for inaction. On the contrary, it makes it even more critical that banks step up and act now," he said.

Recent reporting has indicated that some large U.S. banks which obtained early access to Mythos are racing to correct numerous weaknesses in their data systems that the tool highlighted. Cybersecurity specialists view Mythos as a major challenge to the banking sector and to data technology infrastructures more broadly, and its emergence has prompted warnings from regulators and policymakers.

Elderson cautioned that the industry must prepare not only for the current capabilities of AI tools but also for successors that may enable more aggressive attacks. "We need to be able to deal with ever more capable future models that could be released in relatively quick succession," he said.

ECB president Christine Lagarde has said the central bank is examining potential defences against cyberattacks guided by Mythos, while also noting that the ECB is at a disadvantage because it does not have access to the model. It has also been reported that in April ECB supervisory teams planned to ask the banks they oversee about their readiness for this new risk source.

The uneven global distribution of access to Mythos may become more pronounced: reporting suggests Japan's three largest banks could soon be cleared to begin working with Mythos, potentially within about two weeks. Elderson warned that banks and the third-party contractors they depend on must act quickly to remedy even minor vulnerabilities - issues that have often been addressed only within longer software update cycles.

The message from the ECB supervisor was clear: limited regional access to an AI tool that can both identify and potentially help exploit system weaknesses increases the onus on financial institutions and their service providers to accelerate patching and tighten operational security. While specifics of any coordinated defensive measures were not detailed in the interview, the call to expedite remediation underscores a regulatory focus on operational resilience in the face of rapidly evolving AI capabilities.


Contextual note: The interview and subsequent comments reflect supervisory concern about emerging AI-driven cyber risks and the need for swift technical responses by banks and their vendors.

Risks

  • AI-assisted cyberattacks could exploit unpatched vulnerabilities in bank data systems, posing operational and data-security risks to the banking sector.
  • A widening global access gap to powerful AI models may leave some regions disadvantaged in both offensive and defensive capabilities, increasing systemic resilience concerns in finance.
  • Protracted software update cycles and dependence on third-party contractors could slow remediation of minor weaknesses, extending exposure windows for cyber intrusions in IT and vendor-dependent services.

More from Economy

Economists See ECB Raising Rates in June and Again Later This Year as War-Driven Energy Shock Lifts Inflation May 13, 2026 JPMorgan Signals It Could Reassess London Tower if Starmer Loses Power May 13, 2026 Warsh’s First Fed 'Dot' Decision Could Hide His Rate Views or Reveal Them to the Public May 13, 2026 Samsung and Union Fail to Reach Pay Accord, Raising Prospect of Major Strike May 13, 2026 Kuroda: Yen Unlikely to Slide Past 160 as Authorities Seem to Intervene May 13, 2026