(CNA reporter Su Szu-yun, Taipei, April 14) The Financial Supervisory Commission (FSC) today issued a warning that Anthropic, a U.S.-based AI company, has revealed a next-generation AI model called Claude Mythos Preview (Mythos) in April this year, capable of rapidly identifying cybersecurity system vulnerabilities. This capability could drastically reduce the time financial institutions have to patch such vulnerabilities. The FSC is urging the industry to quickly assess and prioritize internal vulnerability remediation and consider adopting AI tools to strengthen cybersecurity defense planning—what it calls 'fighting AI with AI.'

Lin Yu-tai, Director of the FSC's Information Services Division, stated that in the past, when financial institutions discovered cybersecurity vulnerabilities, they would often prioritize operational stability by conducting tests and scheduling patch deployments, only applying fixes after ensuring system stability. However, the advanced model Mythos—referring to an AI model with capabilities at the forefront of the industry—publicly disclosed by Anthropic possesses AI agent capabilities that enable it to quickly identify cybersecurity system vulnerabilities, posing a significant challenge to the financial sector. Financial regulators worldwide have already begun holding meetings to discuss response strategies.

Lin emphasized that AI-powered attacks are already underway, and advanced AI models could drastically shorten the window for financial institutions to patch vulnerabilities. Financial institutions must first assess which vulnerabilities are most critical and which are relatively minor, establishing clear remediation priorities. The FSC has proposed three key strategic recommendations.

First, accelerate the implementation of the 'Financial Cybersecurity Resilience Development Blueprint' introduced by the FSC at the end of last year. Lin stated that this includes implementing zero-trust architectures to minimize the impact of single-point breaches and enhancing continuous monitoring to improve threat detection and real-time response effectiveness.

Second, establish short-term preparedness and resilience drills within 3 to 6 months. Lin noted that financial institutions should not only conduct internal self-audits but also review their external exposure, such as dormant accounts or unpatched vulnerabilities. For items that cannot be immediately patched, measures such as isolation, privilege reduction, and traffic restrictions should be implemented concurrently.

Third, proactively plan for defensive AI and automated governance capabilities. Lin stated that information and cybersecurity units should consider introducing AI tools to strengthen cybersecurity defense planning. Defensive AI should be integrated into medium- to long-term capability building and governance frameworks, such as in vulnerability detection and patching, security monitoring, and incident response.

The FSC stated it will continue to monitor the evolving capabilities of cutting-edge AI models, international regulatory approaches, and practical needs in the financial sector. It will periodically review and adjust its guidance to build industry-wide consensus and practices for mitigating risks from advanced AI attacks, ensuring the safety and stability of financial services. (Edited by Pan Yi-ching) 1150714

FACT BOX

  • Source: CNA (Central News Agency)
  • Category: Taiwan
  • Organizations: Anthropic
  • Products / services: Claude Mythos Preview