Rep. Maxine Waters [D-Calif.], the ranking member of the House Financial Services Committee, has demanded a formal briefing from the chief executives of six of the nation’s largest financial institutions on how they are managing cybersecurity risks tied to a powerful new artificial intelligence model developed by Anthropic.
The letter, addressed to the CEOs of JPMorgan Chase, Citigroup, Bank of America, Morgan Stanley, Wells Fargo, and Goldman Sachs, centers on Claude Mythos Preview, an AI system Anthropic describes as extraordinarily capable at identifying software vulnerabilities. According to Anthropic, the model has already flagged thousands of high-severity security flaws across major operating systems and web browsers, with the company warning that exploitation of those weaknesses could carry severe economic, public safety, and national security consequences.
Anthropic established Project Glasswing to give major financial institutions and other organizations access to Mythos for defensive security purposes. All six banks named in Waters’ letter have confirmed participation in the program. Anthropic expanded Project Glasswing on June 2 to include 150 additional organizations, noting that a major cyberattack targeting participants could affect more than 100 million people.
Waters expressed frustration that the Committee has received no briefings from the banks on how they are responding to the vulnerabilities Mythos has identified. She raised concerns that the lack of transparency is limiting Congress’s ability to protect consumers and the broader financial system from what she characterized as novel and potentially existential AI risks.
The questions posed by Rep. Waters in her letter cover a wide range of topics, including how banks are evaluating existing regulatory frameworks for gaps, what responsible AI governance standards they had in place before Mythos, how they are coordinating with Treasury, the Federal Reserve, and other federal agencies, and what engagement they have had with industry bodies such as FS-ISAC and the Financial Services Sector Coordinating Council.
Waters also asked how the banks are sharing vulnerability data and remediation strategies with other U.S. financial institutions, a question with direct implications for the broader credit and collection industry, which relies heavily on the same financial infrastructure and software systems that Mythos has been scanning for weaknesses.
.




