UK Banks Excluded from Anthropic’s Advanced AI Security Programme, Offered OpenAI Alternative

Major UK financial institutions denied access to Mythos Preview model despite critical infrastructure status, raising questions about geopolitical AI access controls.

AI-generated illustration depicting incident for the story: UK Banks Excluded from Anthropic's Advanced AI Security Programme, Offered OpenAI Alternative

Major UK financial institutions denied access to Mythos Preview model despite critical infrastructure status, raising questions about geopolitical AI access controls.

Summary

  • UK banks including HSBC, Lloyds and Nationwide excluded from Anthropic’s Project Glasswing expansion, which grants access to advanced cybersecurity AI model Mythos Preview
  • Only JPMorganChase named among financial institutions receiving Glasswing access despite banking sector’s critical infrastructure classification
  • OpenAI offering GPT-5.5 Cyber access to nine UK banks as alternative, with NatWest and Santander already testing under separate agreements
  • Bank of England governor suggests US political considerations may be driving access restrictions to advanced AI security tools

Access Denied

UK banks have been largely shut out of Anthropic’s Project Glasswing expansion, despite the financial sector’s critical infrastructure designation. The programme provides early access to Mythos Preview, an AI model designed to help organisations prepare for advanced cyber threats. While Anthropic expanded Glasswing from 50 to 200 members across 15 countries, only JPMorganChase was named among participating financial institutions.

Political Undercurrents

Bank of England governor Andrew Bailey has been vocal about the exclusion, suggesting US political processes may be influencing access decisions. Bailey told Bloomberg TV that despite pushing for access to protect the UK financial system, Anthropic has not granted the keys to Mythos Preview. Liam Salsi from Talion suspects the decision is political, noting that “the US government wants to control who has access to the platform” to prevent it falling into the wrong hands.

OpenAI Steps In

In response to the Glasswing exclusions, OpenAI has offered its competing GPT-5.5 Cyber model to nine UK banks. HSBC, Lloyds Banking Group and Nationwide are among those set to receive access, while NatWest and Santander are already testing the platform under separate agreements. It remains unclear whether this count includes the Bank of England.

Mixed Model Performance

Early feedback on Mythos Preview shows varied results. Cloudflare’s CISO described it as “a real step forward” for chaining low-severity bugs into working exploits. However, other security experts have been less impressed. cURL’s Daniel Stenberg called it “an amazingly successful marketing stunt” after it found just one vulnerability in his software, while security expert Kevin Beaumont said the model “is not great” beyond finding bugs in basic applications.

Safeguards Still Missing

Anthropic acknowledges that safeguards to prevent abuse of Mythos-level capabilities don’t yet exist. The company states it’s “working as quickly as we can to safely release Mythos-level capabilities in general access” but needs “highly robust safeguards that prevent the model’s cyber capabilities from being misused.” Anthropic expects other AI companies will develop similar capabilities within 6-12 months, potentially forcing difficult decisions about wider release.

Why it matters

The exclusion of UK banks from advanced AI security tools creates potential defensive gaps while geopolitical considerations appear to be driving access to critical cybersecurity capabilities. This fragmentation could leave some financial institutions more vulnerable to sophisticated attacks, while reliance on competing AI platforms may introduce new risks around standardisation and single points of failure across the banking sector.

What to do now

  • Evaluate your organisation’s eligibility for OpenAI’s GPT-5.5 Cyber programme if you’re in the UK financial sector
  • Consider diversifying AI security tool vendors to avoid over-reliance on single platforms
  • Monitor developments in AI security model availability and access criteria
  • Assess current vulnerability management capabilities against potential AI-powered attack scenarios

Sources