Back to News
Market Impact: 0.35

Canada regulator cited Anthropic’s Claude Mythos in warning to banks on cyber risks, email shows

BMO
BNS
CM
CTRYQ
FISI
LTHO
NBHC
NDAQ
+2
Cybersecurity & Data PrivacyArtificial IntelligenceRegulation & LegislationBanking & LiquidityMarket Technicals & Flows
Canada regulator cited Anthropic’s Claude Mythos in warning to banks on cyber risks, email shows

Nasdaq slipped 1.5% as tech stocks fell. In Canada, OSFI warned major banks and insurers that Anthropic’s Claude Mythos could compress the time available to identify and fix cyber vulnerabilities, urging faster risk mitigation amid generative/agentic AI use. OSFI later posted a public bulletin and Canada’s banks’ stated AI plans (investing heavily in protections while deploying AI tools) suggest near-term compliance and security spend may rise, supporting a cautious risk outlook for the sector.

Analysis

This is more of an expense-line and process-risk story than a balance-sheet story. For RY, BMO, BNS and CM, the first-order hit is incremental cyber and model-governance spend; the second-order hit is that AI-driven efficiency gains get deferred just as investors were beginning to underwrite operating leverage. That matters because Canadian banks are valued on the durability of their efficiency ratios, so even a small step-up in mandatory controls can keep the multiple discount to U.S. peers in place.

The bigger medium-term implication is budget reallocation: every dollar redirected into identity, red-teaming, logging, and vendor oversight is a dollar not spent on customer-facing AI or core modernization. The scale players should absorb this best, but smaller/less diversified institutions are more likely to see a visible opex wobble. The real beneficiary set is cybersecurity software and managed security providers, as regulated financials rarely cut these budgets once a regulator has elevated the issue.

Contrarian view: the market likely already prices frontier-AI cyber risk, so without a concrete incident or an OSFI directive that tightens access/model-use rules, this may not change 2025-26 EPS enough to matter. The bear case only gets real if banks start flagging higher tech expense in upcoming quarters or if OSFI moves from guidance to prescriptive requirements. Falsifier: stable efficiency guidance and no upward revision in security capex over the next 1-2 earnings cycles.