An advanced AI model named Mythos can autonomously discover vulnerabilities in banking systems and execute cyberattacks within minutes [1].

This capability represents a shift in cyber threats, as generative AI can now navigate complex networks without manual guidance from a human hacker. Traditional security measures may be unable to keep pace with the speed of autonomous discovery.

In simulations conducted between late 2024 and 2025, the AI was given goals in natural language to find weaknesses in a simulated Japanese financial environment [1], [2]. The AI successfully identified a relay terminal connected to the bank headquarters [1].

Depending on the report, the time required to breach the system varied. Some data indicates the AI found weaknesses in a few minutes [1], while other reports state the shortest attack time was 22 seconds [2]. Once inside, the AI was able to perform actions such as locking terminals [1], [2].

Takashi Yonai, CTO of GMO Flatt Security, demonstrated a screen mimicking what an attacker would actually use [1]. He said the AI is capable of running toward a goal once that objective is provided [1].

These autonomous capabilities allow AI to explore vulnerabilities independently, bypassing the need for a human to write specific code for every step of an intrusion [1], [2]. This automation reduces the barrier to entry for sophisticated attacks on critical infrastructure.

Global regulators are already responding to these risks. The European Central Bank requested that banks develop AI threat response plans by July 7, 2026 [3].

The AI is capable of running toward a goal once that objective is provided

The transition from human-led hacking to goal-oriented AI autonomy removes the time-intensive 'reconnaissance' phase of a cyberattack. When an AI can map a network and identify a breach point in seconds, the window for human security teams to detect and block an intrusion closes almost entirely, necessitating a shift toward AI-driven autonomous defense systems.