Citi CEO Says AI Has Triggered a “Tsunami” of Patching. Mythos Changed the Cybersecurity Race

Citigroup CEO Jane Fraser says companies around the world are racing to strengthen their cyber defenses as increasingly capable AI models make vulnerability discovery faster and more scalable.

When Anthropic introduced Claude Mythos Preview in April 2026, the significance was not simply that another powerful AI model had arrived.

The bigger issue was what the model could do with software security.

Anthropic said Mythos Preview had already found thousands of high-severity vulnerabilities, including vulnerabilities in major operating systems and web browsers. The company responded by creating Project Glasswing, a restricted initiative designed to put the model in the hands of organizations that could use it to find and fix vulnerabilities before attackers could exploit them.

Months later, the consequences are becoming clearer.

Citigroup CEO Jane Fraser said companies are now engaged in a race to strengthen their digital defenses, describing the scale of patching as a “tsunami.” She also characterized the arrival of Mythos as “not a good day” in the evolution of AI-driven cyber risk.

And the response has gone far beyond Silicon Valley.

The Mythos Problem: AI Can Find Vulnerabilities at a Different Scale

Traditional cybersecurity has always involved a race between defenders and attackers.

Security researchers discover vulnerabilities.

Companies patch them.

Attackers attempt to exploit them.

Then the cycle repeats.

AI changes the economics of that process.

Anthropic’s own research says Mythos Preview demonstrated unusually strong capabilities in finding and reproducing software vulnerabilities. Project Glasswing was created partly because the company believed increasingly capable models could eventually allow those capabilities to spread beyond organizations committed to defensive use.

That creates a particularly uncomfortable situation:

The same technology that can help defenders find vulnerabilities can potentially help attackers find them faster.

The race therefore isn’t simply between hackers and security teams anymore.

It is increasingly becoming a race between AI-assisted offense and AI-assisted defense.

Why Wall Street Was Warned About Mythos

The financial sector was among the organizations that received an early warning about the implications.

On April 7, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened an urgent meeting with CEOs of major U.S. banks to discuss cybersecurity risks associated with Mythos and similar AI systems, according to reporting summarized by Sullivan & Cromwell.

Other reporting said executives were encouraged to take the technology seriously and consider using AI capabilities defensively against their own systems.

The concern was not that Mythos had already demonstrated the ability to bring down the financial system.

The concern was that the barrier to discovering exploitable weaknesses could fall dramatically.

That distinction matters.

AI does not need to autonomously destroy a bank to create a major cybersecurity problem.

If it allows thousands of vulnerabilities to be discovered substantially faster than humans can inspect, verify and patch them, defenders can suddenly face a capacity problem.

And that is exactly what Anthropic reported during Project Glasswing.

Anthropic Says Thousands of Vulnerabilities Were Found

In its May update, Anthropic said Project Glasswing participants had identified more than 10,000 high- or critical-severity vulnerabilities across important software during the initiative’s early weeks.

The company said the bottleneck was beginning to shift: finding vulnerabilities was becoming faster, while verifying, disclosing and patching them became the harder problem.

That is perhaps the most important detail in the entire story.

Because cybersecurity normally assumes that discovering a vulnerability is difficult.

What happens when discovery becomes cheap?

You can end up with a completely different security equation:

AI finds vulnerabilities → humans verify them → organizations patch them → AI finds more.

The speed of the first step could eventually overwhelm the rest of the pipeline.

India Has Already Responded

The Mythos story has also reached India’s financial markets.

In May, India’s Securities and Exchange Board of India (SEBI) established a dedicated task force called cyber-suraksha.ai to examine cybersecurity risks associated with rapidly advancing AI systems, including vulnerability-identification tools such as Claude Mythos.

SEBI’s advisory called for measures including system patching, vulnerability assessments, stronger API security, threat intelligence sharing and enhanced security monitoring.

That is significant because it shows that the issue is no longer being treated purely as a technology-company problem.

Financial regulators are now considering what happens when AI dramatically changes the speed at which vulnerabilities can be discovered.

Europe Wanted to Test Mythos Too

The European Union has taken a similar approach.

On September 10, the European Commission confirmed that the EU’s cybersecurity agency, ENISA, had gained access to Anthropic’s Mythos 5 and was testing the model.

ENISA also had access to OpenAI’s GPT-5.6-Cyber, while the EU was additionally granted access to OpenAI’s newer GPT-6-Astra model, according to the European Commission.

The significance is bigger than simply another government receiving access to an AI model.

It represents a shift toward independent evaluation.

Instead of relying entirely on AI companies to explain what their models can do, regulators and cybersecurity organizations increasingly want the ability to test those capabilities themselves.

Project Glasswing Is the Other Side of the Story

There is an important detail that can easily get lost in the headlines.

Anthropic did not initially release Mythos as a normal consumer chatbot.

Project Glasswing was specifically designed to give vetted organizations controlled access so they could use the model defensively. Anthropic’s launch partners included organizations such as AWS, Apple, Cisco, Google, JPMorganChase, Microsoft, NVIDIA and Palo Alto Networks.

Anthropic later expanded the program.

By June, the company said approximately 150 additional organizations were being added, bringing the program to roughly 200 organizations across more than 15 countries.

So there is a paradox at the center of Mythos.

The technology is dangerous enough to worry about — but valuable enough that defenders urgently want access to it.

💡 Wisdom Imbibe Insight

The most important part of Jane Fraser’s warning may not be the “tsunami” metaphor.

It is what that metaphor reveals about the changing economics of cybersecurity.

For decades, defenders could generally assume that finding and exploiting sophisticated vulnerabilities required considerable expertise, time and resources.

AI threatens to weaken that assumption.

If an advanced model can discover vulnerabilities at machine speed, then organizations may have to defend against a much larger volume of potential weaknesses.

That creates a strange new race:

Attackers want AI to discover vulnerabilities faster.
Defenders want AI to discover them first.
And everyone is running out of time.

The challenge is that defensive AI does not automatically eliminate the problem.

If attackers improve at roughly the same time as defenders, companies may simply end up in a permanent acceleration cycle — discovering, testing and patching vulnerabilities faster than ever before.

Jane Fraser’s “tsunami of patching” comment therefore points to something bigger than one Anthropic model.

It suggests that cybersecurity itself may be entering an AI-speed era.

The question is no longer only:

Can companies patch their vulnerabilities?

It is increasingly:

Can they patch them faster than AI can find new ones?

The U.S. Government Has Been Pulled Into the Debate

The Mythos story also illustrates how quickly AI cybersecurity has moved from corporate security teams into government policy.

In June, the U.S. government imposed export controls affecting Anthropic’s Fable 5 and Mythos 5 models, citing national-security concerns. Anthropic said the directive required it to suspend access for foreign nationals and temporarily disabled access more broadly.

Anthropic disputed the government’s characterization of the cybersecurity finding that triggered the action.

The company said the reported jailbreak involved a relatively narrow technique and argued that comparable capabilities were available in other models.

The dispute eventually ended with the controls being lifted June 30, after Anthropic implemented additional safeguards and worked with the government on testing and standards.

The episode demonstrated something important:

AI cybersecurity is no longer just a question for CISOs and engineers.

It is becoming a national-security and regulatory issue.

The New Cybersecurity Race

The emerging picture looks something like this:

None of this means that AI has made cybersecurity defenses obsolete.

In fact, the opposite may be happening.

AI could become one of the most powerful defensive technologies available.

But it also means organizations cannot assume that yesterday’s security assumptions will remain valid.

The Bigger Question: Who Wins the AI Cyber Race?

This may ultimately be the most consequential part of the Mythos story.

AI does not inherently belong to attackers.

It can help security researchers discover vulnerabilities.

It can analyze enormous codebases.

It can accelerate patch development.

It can continuously monitor systems.

It can help organizations respond to attacks.

But the same capabilities can potentially be used offensively.

That creates an arms race where speed becomes a security variable.

The companies that patch vulnerabilities quickly gain an advantage.

The attackers who discover them first gain an advantage.

And increasingly capable AI systems could accelerate both sides simultaneously.

That is why Fraser’s comments matter.

Her “tsunami of patching” description is not merely a warning about one Anthropic model.

It is a glimpse of what cybersecurity could look like when software vulnerabilities can be discovered at AI speed.

Bottom Line

Claude Mythos did not single-handedly create the cybersecurity threat.

The underlying vulnerabilities, insecure software and criminal infrastructure already existed.

What Mythos demonstrated was something potentially more consequential:

AI can change the speed and scale at which those weaknesses are discovered.

Anthropic’s own research, Project Glasswing, SEBI’s cyber-suraksha.ai task force, ENISA’s testing of Mythos 5 and the emergency discussions involving major U.S. banks all point toward the same broader development: institutions are preparing for a world where AI becomes deeply embedded in both cyberattacks and cyber defense.

And Jane Fraser’s warning captures the race in one image:

The patching has become a tsunami.

The question now is whether defenders can stay ahead of the wave.


Read Next :

Dario Amodei Wants to Slow AI. China Could Make It Impossible

Leave a Comment

All You Need to Know About Arjun Tendulkar’s Fiance. Neeraj Chopra’s Wife Himani Mor Quits Tennis, Rejects ₹1.5 Cr Job . Sip This Ancient Tea to Instantly Melt Stress Away! Fascinating and Lesser-Known Facts About Tea’s Rich Legacy. Natural Ayurvedic Drinks for Weight Loss and Radiant Skin .