What actually happened
For the first time, the RBNZ has named a specific AI model as a risk to the financial system. In its May 2026 Financial Stability Report, the Reserve Bank of New Zealand singled out Anthropic's frontier model Mythos as an example of how increasingly capable AI "could materially amplify cyber risks from malicious actors."
That is not a vendor demo. That's our regulator putting a model's name in an official stability document and telling you it is watching.
If you run a New Zealand business, the instinct is to file this under "cyber team's problem." That is the wrong filing. This is an operating logic problem, and it lands on the CEO's desk.
Three things converged in a few weeks, and they are connected.
One. Anthropic built something it won't sell you. Mythos is a general-purpose frontier model that, in Anthropic's own testing, found more than 10,000 high- or critical-severity vulnerabilities across major operating systems, browsers and critical software. Anthropic decided it was too dangerous for general release and instead stood up Project Glasswing, a consortium that now spans roughly 150 organisations in more than 15 countries, giving vetted defenders early access. (Anthropic)
Two. The RBNZ noticed. The Financial Stability Report flagged AI on two fronts: operational resilience (Mythos-class models supercharging attackers) and credit risk (if AI drives job losses, more borrowers struggle to repay). The Bank says it is "actively monitoring the risks that Anthropic's Mythos model may pose to the New Zealand financial sector" and engaging Trans-Tasman counterparts. (interest.co.nz)
Three. The US moved to get models first. On 2 June 2026, President Trump signed an executive order asking AI companies to voluntarily give the federal government up to 30 days of access to "covered frontier models" before wider release, with the NSA, CISA and NIST building a classified benchmark for "advanced cyber capabilities." (CNN, Tom's Hardware)
Read together: the most powerful cyber-capable models now go to governments and vetted critical-infrastructure players first. New Zealand has no equivalent arrangement, no seat at that table, and no domestic frontier capability of its own.
Why this matters for a Kiwi business
The capability gap is no longer theoretical. Anthropic itself warns that within 6 to 12 months, other developers will have Mythos-class models, and some may release them without the safeguards Anthropic chose to apply. Cheap, fast, cyber-capable models are around the corner. (Anthropic)
So the defender's advantage that Mythos represents is temporary and gated. The attacker's version is coming, ungated.
Here is the uncomfortable asymmetry for New Zealand:
- The best defensive AI is being handed to the US government and global critical infrastructure first. We are downstream of that decision.
- Our financial system already showed its fragility this year. A single FMI outage at the RBNZ's own ESAS disrupted around $4.5 billion of transactions and cascaded to at least three other systems before it was resolved in three hours. That was an internal glitch, not an attack. (interest.co.nz)
- APRA across the Tasman has already told banks and insurers it wants "a step-change" in how they manage AI risk, with enforcement on the table. The regulatory direction is one-way.
This is not a reason to panic. It is a reason to get your operating logic right before the cheap attackers arrive.
The four decisions a CEO should make now
This is where most leadership teams reach for a tool. Wrong move. AI doesn't fix a broken process, it accelerates it. The question isn't "which security product do we buy," it's how your business senses, thinks, decides and acts when AI is in the loop, on both sides of the firewall.
1. Own the cyber lever at board level. Name one director or executive accountable for AI-related cyber resilience, with a baseline (your current patch latency, your dependency on third-party AI providers) and a 90-day target. Move a metric, not a use case. If concentration risk is your exposure (everyone leaning on one or two AI vendors), measure it and reduce it.
2. Map your real dependencies. The RBNZ's specific worry is "relying on only a small number of third party AI providers." Most NZ firms have no idea how many critical workflows already route through one model or one cloud. Map it. One source of truth. You cannot manage a dependency you cannot see.
3. Set guardrails on what AI may and may not do. Decide explicitly: what AI drafts, what humans approve; what AI flags, what humans decide; what must never be delegated. Write down the override and escalation paths. AI drafts. Humans approve. That sentence should be policy, not aspiration.
4. Build judgement habits, not just defences. The risk in this era is not only hostile AI. It is your own team uncritically accepting AI output that is confidently wrong. Critical thinking is your competitive moat. Reward the person who spotted what was wrong, not just the person who shipped fast.
A 7-day plan
You can start this week. None of this requires a big budget.
- Day 1-2: Ask your CISO or IT lead one question: "If a Mythos-class model in hostile hands targeted us tomorrow, where would it get in first?" Write down the top three answers.
- Day 3: List every business-critical workflow that already depends on an external AI provider. Note which vendor, and what happens if that vendor goes down or is breached.
- Day 4: Name your accountable owner for AI cyber resilience. One person. Real authority.
- Day 5: Draft your three-line AI guardrail: what AI drafts, what it flags, what it must never decide alone.
- Day 6: Check your cyber-security framework against the RBNZ's Cyber Resilience Guidance if you're a regulated entity, or against a recognised baseline if you're not.
- Day 7: Brief your leadership team. Not on the technology. On the operating logic.
The bottom line
A central bank naming a model is a signal, not a scare. The capabilities that let Mythos find 10,000 critical flaws are the same capabilities that will, before long, be available cheaply to people who do not have Anthropic's caution. New Zealand will not be first in line for the defensive version. We will be very much in line for the offensive one.
The firms that come through this well won't be the ones with the flashiest security tool. They'll be the ones that decided, deliberately, how their business senses, thinks, decides and acts with AI in the loop.
AI commoditises answers. Human judgement becomes premium.
That's not a cyber project. That's an operating system. That's the move.
Sources
- Reserve Bank of New Zealand, Financial Stability Report (May 2026), reported via interest.co.nz and RBNZ
- Anthropic, "Expanding Project Glasswing" (2 June 2026)
- CNN, "Trump signs executive order asking for access to new AI models before they launch" (2 June 2026)
- Tom's Hardware, "Trump signs AI executive order seeking 30-day government access to frontier models" (2 June 2026)
This briefing reflects publicly reported information as at 9 June 2026. The 6 to 12 month timeline for Mythos-class models becoming widely available is Anthropic's own stated expectation, not a certainty.
Power up your potential with practical AI skills.
Contact us to discuss how Artificial Intelligence could boost your business.