Banking and Finance Law Daily Wrap Up, FINANCIAL TECHNOLOGY—Rep. Waters seeks briefing from major banks on AI cybersecurity risks, (Jun 9, 2026)
Organizations Mentioned:Bank of America | Chase | Citigroup | Financial Stability Oversight Council | Goldman Sachs | JPMorgan | Morgan Stanley | Superior Telecom, Inc. | Wells Fargo | Wing Nutt Brewing Co., LLC
In a letter, the financial security ranking member raised concerns about growing cybersecurity and financial stability risks posed by AI systems, and a “lack of engagement” and transparency from major Wall Street institutions.
Representative Maxine Waters (D-Calif.), ranking member of the House Financial Services Committee, has sent a letter to the chief executives of the largest U.S. banks, including JPMorgan Chase, Citigroup, Bank of America, Morgan Stanley, Wells Fargo, and Goldman Sachs, requesting a briefing on how their institutions are addressing newly discovered cybersecurity vulnerabilities linked to advanced artificial intelligence. Waters wrote that the lack of engagement by bank leadership on these issues is hampering the committee’s ability to assess and respond to emerging AI-driven risks to the financial system.
The letter follows Anthropic’s announcement of “Claude Mythos Preview,” an “extremely autonomous” artificial intelligence model capable of carrying out sophisticated computer security and coding tasks. According to Anthropic, the system has already identified thousands of high-severity vulnerabilities across major operating systems and web browsers, with the company warning that exploitation of these flaws could pose severe risks to the economy, public safety, and national security.
Anthropic has launched “Project Glasswing,” which allows major banks and other organizations to access the model to identify and remediate vulnerabilities. Several of the recipient banks have indicated participation, and the program recently expanded to include 150 additional organizations. Anthropic has stated that a major cyberattack could affect more than 100 million people.
The Democratic lawmaker expressed concern that the Financial Services committee wasn’t briefed by the banks on their efforts to combat the “heightened risks of cybersecurity vulnerabilities identified by Mythos…” wrote Rep. Waters. “Bank CEOs’ lack of engagement, as these developments come to light, impairs the Committee’s ability to protect the public and the financial system as we know it from novel and existential AI risks.”
Response requested. Waters requested that the banks provide the minority staff of the House Financial Services Committee with a comprehensive briefing and written responses to the following questions in advance of the hearing:
identification of potential gaps in existing regulations, rules, and guidance;
details on banks’ responsible AI frameworks and any revisions following the emergence of the Mythos model;
coordination efforts with federal agencies and financial regulators on vulnerability reporting;
engagement with industry groups such as FSISAC, FSSCC, and CERG;
communications with the Financial Stability Oversight Council regarding systemic risk considerations;
criteria for participation in Project Glasswing and applicable standards; and
steps taken to share identified vulnerabilities and mitigation strategies with other financial institutions.
Companies: Bank of America; Chase; Citigroup; Goldman Sachs; JPMorgan; Morgan Stanley; Wells Fargo
LegislativeActivity: AINews BankingOperations CyberPrivacyFeed DataSecurity FinancialStability FinTech GCNNews