The Setup: A Warning Without a Weapon
In April, the Fed and Treasury Department convened an extraordinary meeting with the CEOs of the nation’s top banks. The message: Anthropic’s new model, Claude Mythos Preview, is exceptionally good at finding software vulnerabilities — and that makes it a serious cybersecurity threat to financial institutions.
Anthropic had already released Mythos to roughly 50 organizations through a cybersecurity initiative called Project Glasswing. JPMorgan Chase, Amazon, Apple, and Google were among the named participants. Those institutions could use Mythos to find and patch their own weaknesses.
The Fed could not. It didn’t have access.
Three Months Behind
For at least three months after that April warning, the Federal Reserve — arguably the most systemically important financial institution on the planet — was working without the tool it had just told everyone else to worry about.
As of July 15, Fed Chairman Kevin Warsh was still trying to secure access. In Senate testimony, he put it plainly:
“We are not the deciders as to who has access, but I have not been shy in sharing my views with authorities across the government about the vulnerabilities.”
Warsh was careful to note that Mythos wasn’t the only model in question. The Fed needs access to a range of cutting-edge AI systems to assess and patch its own vulnerabilities — not just one.
How This Happened
The access gap isn’t purely a technical problem. It’s a policy and coordination problem with several moving parts.
Anthropic’s rollout was selective by design. Project Glasswing launched with ~50 organizations and expanded to 150+ across 15 countries in June. Government agencies weren’t prominently on the early list, even as Anthropic noted “ongoing discussions” with CISA and the Center for AI Standards and Innovation.
Export controls added turbulence. In June, Anthropic had to temporarily disable access to Mythos 5 and a broader release called Fable 5 to comply with a federal export control directive citing national security. Commerce Secretary Howard Lutnick later granted permission to restore access for “trusted partners.” The controls were eventually lifted entirely — but the episode added confusion to an already fragmented rollout.
Leadership instability didn’t help. Chris Fall, head of the Center for AI Standards and Innovation, resigned just three months into the role. David Sacks, the White House AI and crypto czar, stepped down in March. The people who might have coordinated government access to models like Mythos kept leaving.
The Competitive Pressure in the Background
While the Fed was still trying to get a seat at the table, the table itself was getting more crowded.
Chinese startup Moonshot AI released Kimi K3 in July, a model that outperforms leading U.S. offerings on some benchmarks. Even David Sacks — who left his AI policy role — posted on X that the performance gap is “concerning” and that “America is tying itself in knots.”
Daniel Newman, CEO of research firm Futurum Group, put the Fed’s situation bluntly: the central bank “certainly is going to play catch up.” Every week without access to frontier models is a week where vulnerabilities go unpatched and the gap between public institutions and private ones widens.
What This Actually Signals
The Fed’s access gap isn’t just an embarrassing footnote. It points to a structural problem: AI policy in the U.S. is currently being made in pieces, by different actors, with no clear coordination layer.
Anthropic decides who gets into Project Glasswing. Commerce decides what export controls apply. The White House AI czar position sits empty. And the Fed — which sets monetary policy for the global economy — is left asking politely for access to a tool it already warned others about.
For anyone tracking AI tools and their real-world deployment, this is a useful reminder: access to frontier AI isn’t just a product decision. It’s increasingly a geopolitical and regulatory one. And right now, the rules for who gets in — and when — are still being written in real time.
The smarter move, for any institution, is to not assume access will come automatically just because the need is obvious.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!