0:00 Speaker A
Andrew Bailey, what is he concerned about? What what worries him?
0:04 Jake
So his real concern is that cyber attacks, cyber crime have evolved with frontier AI, that they can move faster, at bigger scale, more cheaply, more efficiently, more effectively, that one attack could really rattle out into multiple markets, multiple companies, multiple multiple countries. And he points out this is possible because the global financial system has gotten to a point where it really relies on a very small pool of shared tech providers. Think uh the Bloomberg Terminal, think uh the Intercontinental Exchange, think uh a company like Fiserv, or a payments platform like Visa. His point is that if one of these were to be attacked, that could then very quickly ripple out through the rest of the market and cause a widespread instability and panic that would be hard to come back from.
1:02 Speaker A
Criminals have been of course trying to hack very sensitive systems for a long time. What is it about AI specifically that concerns him?
1:11 Jake
So it’s a few things. The first of those is speed. These AI machines, the frontier models especially can just move faster than a human. They can also work at scale. They can do 100 things at once when a human can only do one. They are more efficient and they’ve proven to be really, really effective. You’ve seen the tests over and over again showing that these systems are unbelievably capable, far and above what most humans can do at finding and exploiting vulnerabilities. The problem is that if that’s happening at scale against the financial system, against some of the data that underpins the system we use every day, that could very quickly compromise large swaths of the market.
1:53 Speaker A
So if that’s the worry, what are like what are some of the solutions people talk about? Like that if that’s a concern is it, all right, regulators, I’m sorry, they’re going to have to green light powerful models before they get released. Is it financial institutions, they’re going to have to get smarter and and better at defending themselves. It’s a mix of the two? Like what are people talking about?
2:20 Jake
So his his point, his suggestion is a mix of the two. The first is control of the models. We cannot be, he says, pumping out these frontier advanced models without knowing what they’re doing, without thinking about the consequence, without adequately testing. The second part of this he puts on the tech providers and the financial services institutions and says, look, you guys need to tear this down and rebuild from what he calls base metal. Essentially go back to first principles, rebuild for this new era. You guys built for a very sophisticated human attacker, for a, you know, a hacking group that might be operating with the backing of a nation state, but was still run by humans. You need to rebuild and rethink about this for the era where the most effective hacker, where the most effective cyber security threat is now a frontier AI model that’s moving much faster and more effectively than a human.
3:22 Speaker A
And and you wrote about, Jake, uh Anthropic’s Mythos model. Just explain that. We I mean it’s a pretty remarkable example. Explain what it can do and why that has some security pros worried.
3:38 Jake
So this is the perfect example. We saw Mythos come out a few months ago, um an early release from Anthropic that was not made public, but was shown to a very small select group of governments and major institutional partners under what Anthropic calls a project Glasswing. Essentially letting these companies and these governments take this model their uh Anthropic’s top tier model and test it to see what it could do. And the results were pretty astounding. It was finding vulnerabilities no one had ever found, doing it quickly, doing it in a way that could very quickly exploit highly, highly sensitive systems. The idea here is kind of what Bailey is suggesting, to allow a company like J.P. Morgan, which is a part of this, or the Intercontinental Exchange, which is a part of this, or the U.S. Treasury Department to get in, test it against their systems, and then adapt their systems before a model that powerful is available to the public. It still has not been made publicly available because Dario Amodei, the team at Anthropic and others in the government still evaluate it is just too much of a threat. So these companies are still testing it right now and testing where their vulnerabilities and where they can address those.
4:44 Speaker A
All right, Jake, great stuff as always. Thank you.
4:46 Jake
Thanks, Jack.
















