The Bank of Canada, alongside the nation's major banks and financial institutions, convened a meeting on Friday to address cybersecurity risks stemming from the latest artificial intelligence model developed by Anthropic. A spokesperson for Canadian Finance Minister François-Philippe Champagne confirmed the meeting took place on Friday.
This meeting follows similar action taken by US policymakers earlier in the week. Reports on Thursday indicated that US Treasury Secretary Janet Yellen and Federal Reserve Chair Jerome Powell had urgently summoned Wall Street executives to discuss Anthropic's "Mythos" model and similar AI systems.
The Canadian meeting involved members of the "Canadian Financial Sector Resiliency Group," which includes representatives from Canada's six largest banks, such as Royal Bank of Canada and Toronto-Dominion Bank. Other participants included the parent company of the Toronto Stock Exchange, the federal finance department, and financial regulators, including the Office of the Superintendent of Financial Institutions (OSFI).
The Canadian Financial Sector Resiliency Group, led by the Bank of Canada, is a public-private partnership with a mission to "enhance the operational resilience of Canada's critical financial system." A Bank of Canada spokesperson stated, "We are aware of this issue and take cybersecurity seriously."
The Canadian Bankers Association, an industry group representing dozens of institutions including the six largest banks, did not provide specific comments on the Anthropic model or the meeting. An association spokesperson noted that banks are managing AI-related risks through "long-standing, sector-specific regulatory requirements and internal frameworks."
An OSFI spokesperson said in an emailed statement, "We are actively engaging with institutions to raise awareness of this issue and assess its potential implications for financial system resilience." The regulator is maintaining contact with banks regarding "recent developments in advanced artificial intelligence models and their potential cybersecurity impacts."
The meeting and OSFI's comments further highlight growing concern among global regulators that more powerful AI models could facilitate new forms of cyberattacks targeting the financial sector.
While banks are increasingly forming specialized teams to use AI for reducing costs and identifying business opportunities, they are also grappling with managing the risks associated with the rapidly advancing technology. Since 2023, OSFI has been tasked with assessing whether banks and insurers have adequate policies to guard against security threats and has issued guidance on technology and cyber risk management.
The spokesperson added, "OSFI does not currently plan to adjust existing guidance in the short term due to this emerging threat," but will continue to coordinate with the Canadian Centre for Cyber Security to share threat information and mitigation measures while continuously monitoring associated risks.
Anthropic stated that its Mythos model is a highly sophisticated new system capable of identifying and exploiting vulnerabilities in mainstream operating systems and web browsers. Due to its significant capabilities, the company decided not to release the model to the public. Instead, it formed a group called "Project Glasswing" to provide test access to select large technology companies and JPMorgan Chase.
These companies will use the model to test their own products, identify potential vulnerabilities that could be exploited, and report their findings. Anthropic will use this feedback to determine what safety guardrails are necessary for the technology. In the United States, several Wall Street banks, including Goldman Sachs, Citigroup, and Bank of America, are conducting internal tests.