Pulse

Political risk / Jul 14, 2026 / 4 min

Regulators Stopped Speaking in Metaphors

On July 13, Reuters revealed that Canada's banking regulator named Anthropic's Claude Mythos in an April email to the country's biggest lenders — three months after Bessent and Powell summoned Wall Street CEOs over the same model, and days before OSFI posted its first public AI bulletin.

Thesis OSFI's July disclosure just turned Canada's April Mythos email into a global template — regulators who usually write about emerging technologies are now naming frontier models in bank inboxes, compressing the patch window while Ottawa keeps Glasswing access and the Big Six pitch AI as revenue.

Canada's banking regulator named Anthropic's Claude Mythos in a private April email to the country's biggest lenders — and the disclosure on July 13 proves frontier AI has stopped being an abstract risk regulators discuss in euphemisms.

What's new: Reuters reported that the Office of the Superintendent of Financial Institutions emailed chief technology officers, chief information security officers, and chief risk officers across Canada's banks and insurers on April 29. The message surfaced through an access-to-information request — three months late, and only after Reuters questioned OSFI last week.

On July 13, OSFI posted its first public bulletin on generative and agentic AI. The sequencing is not subtle.

The quote:

"Advanced artificial intelligence models, such as Anthropic Claude Mythos, significantly compress the timeframe for effective risk mitigation," OSFI wrote. The email said the bulletin outlined "sound practices that institutions can adopt to enhance the speed and effectiveness of risk identification, mitigation and response."

Asked about the disclosure, OSFI told Reuters it takes a "technology‑neutral, risk‑focused approach" — in a response that names Mythos twice.

Regulators do not usually name products. They write about "emerging technologies" and leave the reader to guess the vendor. The Next Web noted the break from form.

The cascade:

  • April 7: Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened an urgent meeting at Treasury with CEOs from Bank of America, Citi, Goldman, Morgan Stanley, and Wells Fargo — the same week Anthropic launched Mythos. Jamie Dimon could not attend.
  • Early April: Canadian bank executives met regulators on Mythos shortly after the Washington session, per Reuters.
  • April 29: OSFI sent its email — three weeks later.
  • Since then: The European Central Bank, Bank of England, and Australia's ASIC have all flagged the model, per TNW.

Why banks:

Mythos can identify and exploit zero-day vulnerabilities in every major operating system and web browser, Anthropic says — including flaws ten to twenty years old. Banks run some of the oldest software in any industry.

The traditional patch cycle assumes defenders get days or weeks between discovery and exploitation. Mythos collapses that window — which is why Project Glasswing gives vetted partners restricted access to find flaws before attackers do. Anthropic says Mythos has already found thousands of high-severity vulnerabilities.

The access gap:

  • Canada's government says it has Glasswing access. Whether any Canadian bank does is unclear — none would say when Reuters asked.
  • Several referred questions to the Canadian Bankers Association, which cited compliance with OSFI cyber requirements instead of answering.
  • Euro zone banks appear excluded from Mythos access, per Reuters.
  • JPMorgan is a Glasswing launch partner. Dimon missed the Bessent-Powell briefing.

What banks say:

Bruce Ross, Royal Bank of Canada's group head of AI, told interviewers in June that Mythos marks a shift because "attack methods can emerge as soon as new vulnerabilities are identified."

His prescription: "The way we're dealing with it is building our own AI defenses... we'll continue to do that."

The defense, in other words, is more of the thing causing the problem.

Meanwhile RBC, TD, and BMO are pitching AI as a revenue line — chatbots, internal tools, less third-party spend. Scotiabank, CIBC, and National Bank have disclosed initiatives of their own.

The Carney frame:

Prime Minister Mark Carney — a former Bank of Canada and Bank of England governor — told reporters in June that over-reliance on a handful of frontier models creates fragility comparable to the systemic linkages exposed in 2008.

"We have similar things in terms of model risk," Carney said, calling for redundancy and diversity. OSFI's email suggests regulators have stopped treating that as a metaphor.

The IMF backdrop:

IMF Managing Director Kristalina Georgieva told CBS's Face the Nation that "time is not our friend on this one" and warned the world lacks guardrails to protect the monetary system from AI-driven cyber risk.

A May IMF blog post framed Mythos as a systemic stability threat — correlated failures across shared cloud, payments, and confidence — not an operational nuisance at individual firms. U.S. supervisors still have not published their own guidance months after the Bessent-Powell meeting, per American Banker.

Convina's view: Mythos was built to harden critical software. OSFI just proved the transitional period will hurt anyway — because regulators now measure risk in patch windows, not press releases, and naming a model in a bank inbox is what you do when euphemisms stop working. The uncomfortable question is whether Glasswing's defensive access becomes a competitive moat for the banks already inside the tent while everyone else patches on human speed — and whether "build our own AI defenses" is a strategy or a confession that the arms race already moved faster than the compliance calendar.

Research Signals

https://www.channelnewsasia.com/business/canada-regulator-cited-anthropics-claude-mythos-in-warning-banks-cyber-risks-email-shows-6251836 https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational https://thenextweb.com/news/osfi-canada-banks-claude-mythos-warning https://www.cnbc.com/2026/04/10/powell-bessent-us-bank-ceos-anthropic-mythos-ai-cyber.html https://www.anthropic.com/research/mythos-preview https://www.anthropic.com/glasswing https://financialpost.com/technology/carney-says-anthropic-ban-risk-relying-big-ai-models https://www.imf.org/en/blogs/articles/2026/05/07/financial-stability-risks-mount-as-artificial-intelligence-fuels-cyberattacks https://www.cbsnews.com/news/kristalina-georgieva-imf-ai-anthropic-face-the-nation/ https://www.americanbanker.com/news/imf-calls-mythos-a-systemic-risk