OpenAI Opens Cybersecurity AI Access to UK Banks as Anthropic Keeps Mythos Restricted

OpenAI Opens Cybersecurity AI Access to UK Banks as Anthropic Keeps Mythos Restricted

OpenAI has moved to expand access to its advanced cybersecurity-focused artificial intelligence model, GPT-5.5 Cyber, to several major UK banks, creating a sharp contrast with rival Anthropic, which continues to limit availability of its highly scrutinised Claude Mythos platform.

The development comes as financial institutions increasingly seek access to next-generation AI tools capable of identifying software vulnerabilities, testing digital infrastructure and strengthening cyber resilience. Both GPT-5.5 Cyber and Claude Mythos have been designed specifically for advanced cybersecurity applications, with industry testing suggesting they can outperform human experts in certain vulnerability discovery and security assessment tasks.

Banks Seek Access to Advanced Cybersecurity AI

The debate around access to these tools intensified after Anthropic unveiled Claude Mythos earlier this year. The company claimed the model had uncovered a security flaw in a legacy system that had remained undetected for nearly three decades, highlighting the potential for AI to transform vulnerability detection across critical infrastructure.

However, the announcement also triggered concern among regulators, policymakers and financial industry leaders. Some warned that AI systems capable of identifying sophisticated weaknesses could present significant risks if deployed irresponsibly or accessed by malicious actors.

The UK’s banking sector has been particularly vocal about gaining access to these technologies to assess and strengthen their own systems. Bank of England Governor Andrew Bailey recently highlighted concerns that UK banks had been unable to obtain access to Claude Mythos despite its potential value for cyber defence testing.

OpenAI Expands Access While Maintaining Controls

In response, OpenAI has offered GPT-5.5 Cyber access to nine major UK banking institutions, including Lloyds Banking Group, HSBC and Nationwide. NatWest and Santander were already using the technology through existing arrangements.

OpenAI maintains that access will remain carefully controlled rather than broadly available. The company argues that powerful cybersecurity AI tools should be reserved for organisations focused on defence, resilience and public safety rather than released openly.

The approach reflects a growing industry consensus that advanced cyber AI models require strict governance due to their dual-use nature. While they can significantly improve security testing and threat detection, they could also be exploited to identify weaknesses if deployed without safeguards.

Anthropic Maintains More Cautious Rollout

Anthropic has adopted a more restrictive strategy, initially making Claude Mythos available to a limited group of organisations, primarily technology companies in the United States.

The company reportedly believes Mythos possesses capabilities beyond those of competing systems and therefore warrants additional oversight before wider deployment. Anthropic is said to be working to broaden access, but continues to proceed cautiously as demand from financial institutions and critical infrastructure operators grows.

AI Security Institute Finds Comparable Performance

Independent testing by the UK’s AI Security Institute found that GPT-5.5 Cyber and Claude Mythos demonstrated broadly similar levels of performance across cybersecurity tasks evaluated during assessments.

The findings suggest that while competition between AI developers continues to intensify, multiple frontier models are now reaching a level where they can materially assist organisations in identifying vulnerabilities, strengthening defences and improving cyber resilience.

What this means for the industry

  • Banks are increasingly viewing advanced AI as a core cybersecurity tool rather than a future innovation.
  • Access to powerful cyber AI models may become a competitive advantage for financial institutions seeking stronger security postures.
  • Regulators and AI developers are likely to introduce stricter governance frameworks around cybersecurity-focused AI systems.
  • The debate highlights the growing challenge of balancing AI-driven security benefits against potential misuse risks.
  • Controlled access models could become the standard approach for the most capable cybersecurity AI platforms.

Image Source: Pexels.com

Notice an error or have additional information about this story? Contact the Finnoex newsroom: newsroom [at] finnoex [dot] com.

Discover more from Finnoex

Subscribe now to keep reading and get access to the full archive.

Continue reading