The Systemic Risk Has a Name: When the Reserve Bank Called a Frontier Model a Threat to Financial Stability
In May 2026 a New Zealand regulator did something no New Zealand regulator had done before. It named a company's product, by name, as a risk to the stability of the national financial system. The regulator was the Reserve Bank of New Zealand. The product was a frontier artificial intelligence model, Anthropic's Mythos. And the document was not a speech or a blog post. It was the Financial Stability Report, the statutory assessment the Reserve Bank presents to the Minister of Finance twice a year and publishes in full.
The sentence that carries it is careful, and worth reading exactly as written: "From an operational resilience perspective, emerging frontier models, such as Anthropic's Mythos, highlight how increasingly capable AI systems could materially amplify cyber risks from malicious actors." Note what the Reserve Bank does not say. It does not say Mythos has been used against a New Zealand bank. It says that models of this class change the risk calculus for every institution that depends on the same digital infrastructure, whether or not that institution has ever touched the model. And it confirms it "is actively monitoring the risks that Anthropic's Mythos model may pose to the New Zealand financial sector and to its regulated entities."
That word, monitoring, is doing precise work. The Reserve Bank has not found harm. It has identified a risk and taken a supervisory position on it, inside its most formal publication. For a director, the distinction matters, and I will hold to it throughout: this is a regulator watching a threat, not a regulator reporting a loss.
The report did one more thing in the same chapter. It disclosed an outage in the Reserve Bank's own payment system. These are not two items in a busy risk chapter. They are two sides of one argument, and the argument is the reason a finance, insurance, or payments board should read the Financial Stability Report as governance material rather than background.
The naming, and why it is a first
Regulators name categories. They warn about "third-party dependencies" and "operational resilience" and "concentration risk." What they almost never do is name a specific commercial model as a systemic concern in a statutory stability document. The Reserve Bank did, and it is the first instance of it in New Zealand financial regulation.
A note on the name, because precision here is not pedantry. Anthropic's Mythos refers to the model announced as Claude Mythos Preview in April 2026. A later restricted release, designated Mythos 5, emerged from export-control negotiations from June 2026 onwards. The Financial Stability Report predates that episode; when it says "Anthropic's Mythos" it means the capability class, not a specific versioned release, and I use it the same way.
The naming did not arrive alone in the institutional landscape. The Reserve Bank stated it is "engaging with other domestic agencies and Trans-Tasman counterparts to ensure continued alignment on risk assessments and policy responses." Read that as a description of the room. The prudential regulator is in active dialogue with New Zealand's cyber and intelligence agencies and with its Australian counterpart about how this risk should be assessed. A board of a regulated entity is not under the attention of one regulator on this question. It is under several at once.
Why the Reserve Bank is watching this particular model
A regulator does not name a model on a hunch, so it is worth confirming the capability underneath the concern. Anthropic's Claude Mythos Preview scored 83.1 per cent on CyberGym, a benchmark built from 1,507 real-world software vulnerabilities across 188 open-source projects. The prior flagship model scored 66.6 per cent on the same test. That is not an incremental gain. It is a step in the kind of work that used to sit only with skilled human specialists.
The more instructive detail is how the model operates. It reads a codebase, ranks the files by how likely each is to hold an exploitable flaw, forms a hypothesis about where a weakness lives, runs the target software to confirm or reject that hypothesis, and produces a full bug report with a working proof-of-concept exploit and reproduction steps. Anthropic's own red team documented the model building, in hours, exploits that experienced penetration testers estimated would have taken weeks. It turns public vulnerability information into functional attack code without a human in the loop.
This is the point where the dual-use nature of the thing becomes a governance problem rather than a technical curiosity. The same capability that lets a defender find and close a flaw before an attacker reaches it is the capability that lets an attacker find and open it first. The Cyber Guide for New Zealand Boards has a name for this split: the Heaven Vector and the Skynet Vector, the same tool pointed in opposite directions. Mythos is the clearest instance of it the series has met. And here the split has a hard edge that is specific to New Zealand.
Following an export-control suspension in mid-June 2026, the United States Commerce Department authorised Anthropic, on approximately 26 to 27 June 2026, to release Mythos to a trusted ring of roughly one hundred United States companies and federal agencies for vulnerability identification and defensive use. Bloomberg reported in July 2026 that international institutions, United Kingdom banks among them, remain outside that ring. No source retrieved for this article confirms access for any New Zealand financial institution. So the structure is this: the Skynet side of the capability, the version that amplifies an attacker, is loose in the threat landscape; the Heaven side, the version a defender would hold, sits behind an export-control line that New Zealand institutions are on the wrong side of. That is the shape of an export-control regime built for national security, not a judgement about anyone's intent, and I frame it as structure, not grievance.
The fragility was already in the building
If Mythos is the threat the Reserve Bank named, the outage it disclosed in the same chapter is the proof of fragility it already had on file. In the first quarter of 2026, the Exchange Settlement Account System, known as ESAS, experienced a material outage. ESAS is the high-value payment rail that the Reserve Bank operates itself, and it settles an average of NZ$29.8 billion a day.
The outage disrupted approximately NZ$4.5 billion in transactions, around 15 per cent of that daily balance. It affected every ESAS participant, including one in Australia, and it cascaded across at least three further financial market infrastructures. The cause was a latent defect that had sat in the system since 2020, undetected for years, until a rare combination of circumstances triggered it. Incident response protocols were activated and it was resolved within three hours.
One caution has to be stated plainly, because conflating it would be both a factual error and unfair. The ESAS outage was not caused by artificial intelligence. It was a technical residue from earlier system design. Its place in this argument is not as an AI incident. It is as a demonstration, from the Reserve Bank's own infrastructure, of what concentration fragility looks like when it moves: the settlement rail that every New Zealand bank depends on stops for three hours, and the disruption ripples across interconnected infrastructure immediately.
The Reserve Bank presents the outage as both a warning and a reassurance. The warning is the six-year-old defect nobody found. The reassurance is the three-hour recovery. For a board, both halves are the lesson. The Cyber Guide argues that the board's job is the Audit of Intent: not confirming that a control exists, but knowing what it is actually capable of and whether it would hold under pressure. A latent defect present since 2020 is precisely the kind of undetected system state an Audit of Intent is built to surface, and the fact that it took a rare event to expose it is the argument for looking before the rare event arrives. The three-hour recovery is the Hour-Zero Protocol working as designed. But notice who else was in the incident: the three further infrastructures that felt the cascade each faced their own hour zero, on a clock they did not start. The Hour-Zero Protocol is not preparation for the incident you expect. It is preparation for the incident that begins when the system upstream of you fails.
Three layers, all offshore
The Reserve Bank's concentration warning is not abstract, and it is the part of the report most specific to New Zealand. The report observes that the sector is "already running on overseas cloud providers and overseas core banking software" and is now "layering an overseas AI dependency on top of it." It warns that heavy reliance on a small handful of overseas AI providers concentrates "technical, legal and reputational exposure into a very small number of upstream bottlenecks," and that "relying on only a small number of third party AI providers could create dependencies and increase the risk that models produce biased, misleading or fraudulent outputs."
Set that against the structure of the New Zealand market and it sharpens. The four major banks, ANZ, ASB, BNZ, and Westpac, are all Australian-owned. So the ownership layer sits offshore. The cloud and core-banking layer, the Reserve Bank confirms, sits offshore. And the new AI layer, drawn substantially from United States providers, sits offshore too. Four layers, each substantially governed from outside New Zealand, stacked one on the other.
The compounding is the risk. A single failure at one United States AI provider does not stay in the AI layer. It can propagate through the cloud layer and the core-banking layer into the New Zealand financial system at speed, because at each layer New Zealand holds limited regulatory reach over the dependency above it. This is where the Cyber Guide's Cultural Security Envelope earns its place in a financial article. The Envelope treats the protection of a community's data and economic fabric, including Te Tiriti obligations, as a governance responsibility, not a compliance afterthought. When the ownership, the infrastructure, and now the intelligence layer of the system that intermediates New Zealanders' money all sit offshore, the sovereignty question the Envelope raises stops being philosophical. It is the same concern the Reserve Bank has now expressed in the prudential register.
Consider the audit committee chair who says her organisation runs on reputable providers and has never used Mythos, so why would the report apply. The answer is in the layering. The Reserve Bank's concern was never whether you use the model. It is whether the providers you depend on are themselves exposed to models of that class, and whether, if one of them suffers a breach that this capability made faster or cheaper, your own exposure is mapped and your response is ready. Not using the model is not the same as not being exposed to it.
New Zealand is early, not alone
It would be easy to read a small country's central bank naming a frontier model as an outlier moment. The international record says the opposite. In July 2026 the Bank of England's Financial Policy Committee published its own Financial Stability Report and went further in its language: recent advances in frontier AI, it said, "have increased financial stability risks related to cyber and operational resilience," and the cyber capabilities of current frontier models are "already exceeding what a skilled practitioner could achieve, and at a significantly higher speed, greater scale, and lower cost." Two central banks in the English-speaking world, within three months of each other, naming frontier AI capability as a financial-stability risk in a statutory report. The Reserve Bank of New Zealand published first. This is convergence, not New Zealand following a trend.
The convergence runs wider than two central banks. The Financial Stability Board, of which the Reserve Bank is a member, published a consultation on 10 June 2026 setting out twelve sound practices for responsible AI adoption in finance, with two of them addressing AI-related cyber, technology, and third-party risk directly. The final version goes to the Group of Twenty finance ministers and central bank governors in October 2026, and it will shape the supervisory expectations the Reserve Bank applies here afterward. In the same month the Bank for International Settlements named an AI investment bust and the circular financing behind it as one of its three top threats to global financial stability, warning that a sharp repricing of that risk could hit credit markets with a force it compared to the 2008 crisis. That is a different channel from the cyber one, the money side rather than the operations side, but it points the same direction: the institutions whose job is to watch systemic risk are watching AI.
Two domestic instruments sit alongside the report. The Financial Markets Authority is running a thematic review of AI use in financial advice, focused on the conduct layer, on how firms actually use these tools and what safeguards they hold, with cyber security and operational resilience named among its concerns. And the proposed New Zealand Cyber Security Strategy 2026 to 2030 designates finance as one of seven essential services, and contemplates, at the most serious end of its penalty regime, personal criminal liability for directors of up to NZ$100,000 for a serious breach and up to NZ$500,000 for a critical one. That strategy is proposed, not enacted. Consultation closed on 19 April 2026 and Cabinet is reviewing the feedback. I describe the proposal and its status, and I make no forecast about whether or how fast it becomes law. But the combined picture is unambiguous for a finance-sector director: the prudential regulator has named the threat, and the national cyber strategy has named the proposed penalty.
What a board actually does with this
The Reserve Bank has handed boards an unusually clear instrument. A statutory publication that names a specific technology as a risk, discloses its own infrastructure's fragility, and states its monitoring posture is, in the language of the Cyber Guide, a Crisis Compass: the reading that tells a board which way the landscape has shifted. Boards that were waiting for an authoritative signal that AI cyber risk had reached the financial-stability level now have one. The Compass then asks the only question that matters, which is what the next governance decision is.
There is a further channel in the report that most board risk registers have not yet mapped, and it is worth naming even though it is not the headline. The Reserve Bank draws a direct line from AI to credit risk: "If AI leads to job losses in some sectors, more borrowers may struggle to pay their mortgages." That is a chain, from capability deployment, to employment disruption, to mortgage stress, to portfolio risk, that requires no cyber incident at all. It belongs in the supporting register rather than the front of the argument, but it makes the same point the rest of the report makes: AI reaches financial stability through more than one door.
The risk manager at an insurer might reasonably say the ESAS outage happened to the Reserve Bank, so surely the onus for concentration risk sits with the infrastructure providers, not with her. The Reserve Bank's own disclosure answers her. Its outage resolved in three hours because its incident response worked. The three further infrastructures caught in the cascade each had to run their own response. The Reserve Bank has published its hour-zero test. The governance question is not whether the provider's protocol worked. It is whether yours would.
So the exercise for the next board meeting is not a briefing on artificial intelligence. Your people know AI is changing the threat. The exercise is to answer three questions with evidence rather than assurance. First, have we mapped where our providers, across cloud, core banking, and AI, are themselves exposed to frontier-model capability, or do we only know the names of our vendors. Second, if a provider we depend on suffered a breach that this capability made faster to run, is our exposure documented and our response tested, or does it live untested in a shared drive. Third, if the Reserve Bank, or a shareholder, or a court asked what this board did after the prudential regulator named this risk in a statutory report, what could we actually produce.
What this means for sovereign capacity
The report is, in the end, a document about dependency, and dependency is where financial stability meets sovereign capacity. The same restricted release that put Mythos-class defensive capability inside roughly one hundred United States companies and federal agencies left institutions in allied jurisdictions, United Kingdom banks among them by Bloomberg's account, outside the perimeter, and New Zealand institutions are not confirmed inside it. That is the structure of an export-control regime built for national security, not a verdict on any government's intent. But it leaves a settlement system clearing an average of NZ$29.8 billion a day exposed to a class of capability its defenders cannot yet hold, while the Financial Stability Board readies the framework it will hand the Group of Twenty in October. Financial market infrastructure is national infrastructure. Until sovereign access catches up to sovereign exposure, that gap is a board's to manage, not a regulator's to close.
The Reserve Bank has done the analytical work. It has taken the frame it reserves for systemic threats and applied it, in a statutory report, to a named model and to its own payment rail in the same breath. The threat and the proof of fragility arrived in one document, from one regulator. What it asks of a board is not alarm. It is a record.
If someone asked your board, next week, to show what it did after the Reserve Bank named a frontier model a threat to financial stability, what would it hand over?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] Reserve Bank of New Zealand. "Financial Stability Report, May 2026 (B.33)." 8 May 2026. https://www.rbnz.govt.nz/hub/publications/financial-stability-report/2026/may-2026
[2] interest.co.nz (Gareth Vaughan). "RBNZ 'monitoring the risks' Anthropic's Mythos could pose to NZ's financial sector." 8 May 2026. https://www.interest.co.nz/
[3] NewsWire. "Reserve Bank warns concentrated AI providers and frontier models like Anthropic's Mythos could test New Zealand's financial system." May 2026. https://www.newswire.co.nz/
[4] Central Banking. "AI poses financial stability risks, says RBNZ report." May 2026. https://www.centralbanking.com/
[5] Contrast Security. "What Is Mythos AI? Autonomous Exploits and AppSec Defense." 2026. https://www.contrastsecurity.com/glossary
[6] Labellerr. "Claude Mythos: Benchmark-Dominating AI with Real Risks." 2026. https://www.labellerr.com/blog/
[7] CNBC. "Trump admin allows Anthropic to release Mythos AI model to some companies, government agencies." 26 June 2026. https://www.cnbc.com/
[8] Bloomberg. "Anthropic's Mythos 5 AI Model Remains Restricted for International Users." July 2026. https://www.bloomberg.com/
[9] Bank of England. "Financial Stability Report, July 2026." July 2026. https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026
[10] Financial Stability Board. "Sound Practices for the Responsible Adoption of Artificial Intelligence (consultation report)." 10 June 2026. https://www.fsb.org/2026/06/fsb-consults-on-sound-practices/
[11] Bank for International Settlements. "Annual Economic Report 2026." 28 June 2026. https://www.bis.org/publ/arpdf/ar2026e.htm
[12] Department of the Prime Minister and Cabinet. "New Zealand Cyber Security Strategy 2026-2030 (consultation; proposed critical-infrastructure regime)." Released 10 March 2026; consultation closed 19 April 2026. https://www.dpmc.govt.nz/
[13] MinterEllison. "FMA publishes research on AI in financial services." 2026. https://www.minterellison.co.nz/

