Why Global Banks Are Worrying Over Anthropic’s Latest AI Model
The notorious American bank robber Willie Sutton spent 40 years in the business of bank heists, asserting in his autobiography that his motives were purely for enjoyment. When asked why he specifically targeted banks, he is famously quoted as saying, “Because that’s where the money is.”
In 2017, I wrote a book predicting that not only charming criminals like Sutton would partake in bank robberies, but also artificial intelligence (AI).
That day appears to be approaching. Financial institutions around the globe are deeply worried that cybercriminals will soon harness the latest advancements in AI to conduct heists.
The digital back door into the vault
The concerns within the finance sector largely stem from the formidable capabilities of a product called “Mythos,” the latest and most advanced AI model developed by Anthropic, the creators of the renowned Claude chatbot.
Currently, members of the public cannot access or utilize this model. Anthropic, among others, believes that Mythos is too powerful to be released publicly.
Internal evaluations of Mythos have indicated thousands of severe security flaws across all prominent operating systems and web browsers.
Some of these vulnerabilities have gone unnoticed for decades, and many are classified as “zero-day” threats — issues so critical that immediate rectification by developers is necessary.
ADVERTISEMENT
CONTINUE READING BELOW
Not for public use
Moreover, the company has allocated US$100 million (approximately A$140 million) in usage credits and US$4 million (around A$5.6 million) in open-source grants to identify and rectify these security flaws.
Additionally, over 40 organizations, including several U.S. banks, have received access. However, it is concerning that Anthropic has yet to grant access to any banks in Australia, the United Kingdom, or Europe.
To intensify fears, Anthropic confirmed on Wednesday that it is investigating allegations from a Bloomberg report revealing that a small group of unauthorized users accessed Mythos. Currently, there is no indication that this access was intended for malicious use.
Should you be worried?
Last week, global regulators and policymakers met at the International Monetary Fund spring meeting in Washington. While the conflict in Iran was a significant focus, attendees also expressed concerns about the impending cybersecurity threat to the banking sector.
ADVERTISEMENT:
CONTINUE READING BELOW
Banks are not only attractive targets as sources of money, but they also rely on many outdated systems that may be particularly vulnerable to these types of attacks.
As an individual, there’s likely no need to panic. Many countries have robust protections in place for bank customers. For example, in Australia, the first A$250,000 of a customer’s deposits are protected by the government-backed Financial Claims Scheme.
The Australian Securities and Investments Commission also mandates that banks investigate and reimburse fraudulent transactions that occur without the customer’s fault.
Therefore, withdrawing your cash and stashing it under your mattress is probably not a wise approach. However, banks are certainly moving quickly to address these vulnerabilities.
I recommend that you regularly update your computer and smartphone to ensure you have the latest operating systems and banking applications. Anticipate many more updates soon as new vulnerabilities are identified and fixed.
Additionally, stay alert for phishing attempts via email and SMS that aim to obtain your banking information.
The evolving threat landscape
In the long run, Mythos underscores the challenges of defense versus attack. Software is among the most complex products crafted by humans, making it nearly impossible to ensure it is entirely free of bugs.
ADVERTISEMENT:
CONTINUE READING BELOW
This places us in a constant battle against the “bad guys” to discover and fix flaws before they can be exploited.
For instance, the European Union recently launched its age verification app, designed to support new laws regarding access to social media, adult content, and other age-restricted materials. Yet, within hours, security experts identified vulnerabilities that underage users could easily exploit.
In critical situations, we can aim to mathematically verify that our software is bug-free. For example, the Beneficial AI Foundation recently announced an ambitious project to demonstrate that the popular messaging app Signal is, in fact, without bugs and protects privacy as claimed.
However, such efforts remain the exception rather than the rule at present. Future AI advancements may help in reversing this trend.
Toby Walsh, Professor of AI, Research Group Leader, UNSW Sydney
This article is republished from The Conversation under a Creative Commons license. Read the original article.
