Japan's FSA Convenes Mythos Risk Meeting With MUFG, SMFG, Mizuho, Bank of Japan, and Tokyo Stock Exchange
Japan’s Financial Services Agency is convening meetings with MUFG, SMFG, Mizuho, the Bank of Japan, and the Tokyo Stock Exchange to discuss Claude Mythos, Reuters reported on April 22. The regulatory posture represents a shift in how national-level supervisors categorise frontier AI: not as an emerging technology to watch, but as an operational risk to manage now, alongside liquidity stress, system outages, and cyberattacks.
The meeting follows similar sessions in the US and UK — the Fed and Treasury convened closed-door sessions with major American bank CEOs, the Bank of England’s CMorg coordinated briefings across British financial institutions — but Japan’s convening is notable for its specificity. The FSA is bringing the operational arms of both private banking (MUFG, SMFG, Mizuho) and market infrastructure (Bank of Japan, Tokyo Stock Exchange) into the same room.
The Core Risk Calculation
The model that triggered this response was designed for defensive cybersecurity. That framing is both accurate and beside the point for regulators.
Mythos can scan large codebases, identify unknown vulnerabilities, and chain exploits autonomously. The UK AI Security Institute confirmed it achieves 73% on expert-level CTF tasks and completed a full 32-step simulated enterprise network attack without human assistance. The FSA’s concern is not that Anthropic will attack Japanese banks. It is that a model with these capabilities changes the time arithmetic of a cyberattack.
Conventional intrusions are bottlenecked by human attention. A threat actor finds bugs one at a time, escalating through a system at human pace. A Mythos-class model — whether accessed legitimately, leaked, or replicated — can identify critical flaws across an entire codebase in the time it takes a human analyst to read the incident report. The discovery-to-exploitation window, which has historically given defenders time to patch, compresses to near-zero.
Japanese banking infrastructure — and financial market plumbing generally — runs on software stacks that include decades of legacy code. Payment rails, settlement systems, exchange matching engines, and core banking platforms are densely interconnected and slow to patch. A single exploitable weakness in that stack can halt trading, break settlement, or leak data. The FSA’s risk framing reflects that reality.
What Regulators Can Actually Do
No regulatory body has the technical capability to assess Mythos independently at the speed the model operates. The FSA’s likely outputs are procedural: updated incident reporting requirements, guidance on AI risk exposure classification, stress-testing scenarios that include AI-accelerated intrusion as a threat vector.
Anthropic has kept Mythos restricted to 40 vetted partners under Project Glasswing. That controlled distribution was breached by an unauthorized group on launch day, through a vendor environment gap — a separate development that gives regulators additional cause for concern about whether partner-based access controls are sufficient.
The structural issue the FSA is grappling with is not Mythos-specific. It is that defensive deployment of AI-capable vulnerability research tools and offensive exploitation of equivalent tools are not separable at the technical level. What a security team uses to find weaknesses, an attacker can use to exploit them. Managing that double-use problem through distribution controls is now, demonstrably, not enough on its own.
Anthropic has not announced a timeline for broader Mythos access. Japan is the third major jurisdiction after the US and UK to treat this as a supervisory matter requiring immediate institutional response.