📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

Big Bank CEOs summoned to Washington for Emergency Meeting on Anthropic

Bloomberg Television6:59

Transcription

So these almost every CEO of every big bank went. The only person missing, and according to your story, was Jamie Dimon, JPMorgan Chase. And he couldn't make it for some reason.

But why were five of the six big bank CEOs summoned by Fed Chair Jay Powell and Treasury Secretary Scott Bessant? Well, we know, Tim, that in the past few days, in the past few weeks even, concerns have been raised about the severity and the strength of this new model by Anthropic, this tool called Mythos. Mythos basically, Anthropic and Satirical essentially use it to detect extreme vulnerabilities in things like web browsers and security systems. It presents a whole new level of cyber risk for countries, for companies, for huge institutions. And Anthropic have admitted that they know the severity of this. They have acknowledged and they're taking it very, very seriously. They've had a limited rollout for testing purposes among a select group of companies. We know JPMorgan is one of those that's public. There are about 40 other companies as well who are on the list, not all of them public, who are getting early access to this and testing it out. But the information security teams have access to this.

But essentially, what this shows, and bear in mind, some of their top executives were already in D.C. for lobbying meetings on Monday. But this was a meeting that was sort of tacked on to that. It was a very unusual meeting in that you had Scott Bessant and Jay Powell. Remember, the central bank, the Federal Reserve, has taken pains in the past few years to establish its independence from the political side of government. But together, you have the central bank chair and the treasury secretary having a joint meeting, showing how important this is across the department, across the U.S. government for financial stability and for the security of the U.S. economy.

What is your understanding of what was really at the heart of the concern that both Bessant and Powell had? Was it just general, like, we need to be careful because there's now a more powerful cyber, I guess, criminal out there? Not criminals, I don't want to say criminal, but a cyber tool that we're vulnerable to? Or were there more specifics of like, this could actually happen? Here's a specific risk that maybe was flagged?

Yeah, we're certainly continuing to look into this, that's for sure. But one thing to bear in mind, right, is the context, the wider context here. You have around these tools, you have Iran, you have China, you have Russia all creating their own cyber tools, their own capabilities at the same time. Here is something that's been developed on U.S. soil that have already been partial leaks by some of these, by Anthropic itself, as we know, that are creating questions around the security of the capability. So basically, what the government is essentially saying to these banks is, "Hey, like, you guys are the most systemically important institutions in some ways that we have in this country. You, of anyone, need to be the most defended, you know, in case of potential risks." Not just by this own tool that you will be getting access to. JPMorgan has access to it. We know that other companies are getting access to it soon as well. And that is, to them, sort of the core of this. Like, can you test this? Can you make sure? Can you help us evaluate its own risk and the risk that we might face from elsewhere as well?

And can they? Well, that's a delicate question right now. Obviously, these banks have been keeping this meeting extremely confidential. I mean, this was the result of a few days of reporting. In your piece, it mentions none of them even commented to you. None of the banks commented to us on this. It was very, very tightly held. And I think it seems to be more of a directive from the top down to the CEOs directly, a direct appeal to say, "Hey, you need to be taking this super seriously internally."

So what can you tell us about the way that banks do keep our money safe in an environment where they could be at risk from these new tools?

Yeah, I mean, that's a great question. I mean, we know banks aren't perfect by any means. In fact, some of them have the worst tech. Decisions, you know, I've come on this show before to talk about, you know, fat fingers at Citigroup, for instance. A lot of banks with crunchy technology, let's say, to be generous. We all know, even from a retail perspective, many people listening to this show will know that their own bank is far from perfect when it comes to technology. So the urgency of this is really not lost on these companies. They are reflective on this.

The Federal Reserve, you know, has a huge role in particular in its supervisory role looking internally at banks. They are the ones that have staff often inside the banks' offices who are looking at their capabilities, looking at their systems, looking at their defenses here. And they've obviously been evaluating that and evaluating the new tools and the new capabilities that are both available to these companies, but also to people who might want to hack these companies. And have decided that, look, the equation and the balance that stands right now is serious. Then after this needs to have, like, a top-down, extremely detailed and serious approach to what's going on here.

Is there a potential that that approach would ever turn into maybe new rules and regulation for banks?

I think that's quite possible. I think there's chatter around that, you know, across sectors about how different companies might respond. Questions of best practice. You know, as we all know across Wall Street right now, a lot of banks have public partnerships of certain companies are trying out lots of different tools internally, whether that's for their engineers, their junior analysts, all this kind of thing. They are already playing around in the sandboxes as it is. But I think it's only inevitable that at some point there will be some formalization of what's required.

Todd, I think what's particularly chilling in a scenario like this is just because one American company has this technology now doesn't necessarily mean that other companies won't get it soon and that it won't easily fall into the wrong hands at some point soon. I think people are pretty shocked about how quickly this tech moves, but no question, everything's moving in the direction where it just gets better, better and more impressive and more impressive. What happens then? It seems like this is always going to be a race between sort of the bad actors and the ones who are trying to keep this stuff safe.

Yeah, I mean, you're right. It's not just Anthropic's own tools, but who could replicate that, right? A lot of this, a lot of source code is open source. China and Russia, Iran are also developing open source tools, at least China is for sure. And this stuff is readily available. So it's not just the case of whether Anthropic itself is secure, but it's who can replicate what Anthropic has and what can the U.S. economy learn from what Anthropic has in order to defend itself against what other companies might have and other states might have?