Lloyds, HSBC and NatWest get OpenAI access amid mounting concerns

Some of Britain’s largest banks, including Lloyds Banking Group, Lloyds Bank, HSBC, Nationwide Building Society, NatWest Group, NatWest and Santander UK, are set to gain or expand access to OpenAI’s GPT-5.5 Cyber model as regulators intensify scrutiny of how financial institutions test, govern and secure AI-enabled systems.

The move comes amid growing concern among central banks and supervisors that advanced AI models are rapidly changing the economics of cyber security, vulnerability discovery and software assurance.

OpenAI confirmed it is opening GPT-5.5 Cyber to additional UK banks after rival Anthropic restricted access to its Claude Mythos Preview model, a complex AI-powered software system that has become the focus of urgent discussions among the Bank of England, Financial Conduct Authority, HM Treasury and the National Cyber Security Centre.

Both models are designed to uncover hidden weaknesses in software and infrastructure. According to the AI Security Institute, which evaluated both systems, GPT-5.5 Cyber and Mythos reached “a similar level of performance” in the tasks it assessed.

For QA, software testing and digital resilience teams, the significance extends far beyond access to a new AI tool. Recent regulatory discussions in the UK and Europe suggest supervisors increasingly view AI governance, cyber resilience, operational risk and software assurance as a single supervisory challenge.

‘Secure the world’s most critical software’

Anthropic’s Claude Mythos Preview has attracted particular attention after the company claimed it had identified “thousands of major vulnerabilities across operating systems, web browsers and other widely used software.” The company has also said the model is able “to secure the world’s most critical software.”

Andrew Bailey

That has prompted concerns among regulators that AI-powered vulnerability discovery could dramatically compress the time available for banks to test, patch and govern critical weaknesses before they become exploitable.

Bank of England Governor Andrew Bailey recently warned that resilience “can no longer be assumed, it must be proven,” while supervisory expectations increasingly require resilience to be “continuously tested, measured and evidenced.”

Those concerns have also emerged through the FCA’s AI Live Testing programme.

Ed Towers, head of department in the FCA’s advanced analytics and data science unit, recently said: “We’re providing a structured but flexible space where firms can test AI-driven services in real-world conditions, all with our regulatory support and oversight and help from our technical partner, Advai.”

He added that “through live testing we want to help UK innovators move safely beyond ‘POC paralysis’, or what is often described as ‘perpetual pilots’.”

The Bank of England in the City of London

OpenAI steps in

The latest development follows comments from Andrew Bailey, who said UK banks still could not access Anthropic’s Mythos model to test the security of their own digital systems and applications.

OpenAI has now moved to fill that gap.

George Osborne

Former UK Chancellor George Osborne, now a senior executive at OpenAI, told the BBC that the company did not want to “hide [5.5 Cyber] away or keep it to ourselves.”

“The key things with these tools is that they need to be in the hands of the right people,” Osborne said.

He added that “we want to make sure that the forces that are establishing order in our democracies have these tools, and the forces that want to disrupt us or commit crime, do not.”

The banks gaining access include Lloyds Banking Group, Lloyds Bank, HSBC and Nationwide Building Society. NatWest Group, NatWest and Santander UK already have access through existing arrangements.

Anthropic, meanwhile, is reportedly working to expand access to Mythos but maintains that its capabilities sit above those of GPT-5.5 Cyber and therefore require additional safeguards.

Regulators warning

The debate is unfolding against a backdrop of escalating regulatory concern about AI-driven threats.

The European Central Bank recently warned that advanced AI systems could dramatically reduce the time banks have to respond to newly disclosed vulnerabilities.

Frank Elderson, vice-chair of the ECB supervisory board, told the Financial Times: “There is a whole range of issues on cyber security that we have been engaging on with the banks for years which are all still valid, but given the progress in AI, they need to be dealt with faster.”


“In musical terms, I would say andante may have been good enough, but we need to go to presto.”

– Frank Elderson

Discussing software patching cycles, Elderson added: “It seems if one of the big software providers comes with a patch it is possible to reverse-engineer the vulnerability that the patch is supposed to patch, not in weeks but maybe in 30 minutes.”

“That means that once the patch is out, a bank needs to have processes in place to actually make sure that it applies these patches much faster than what is now seen as market practice.”

Silvia Forte

Silvia Forte, Senior Analyst ICT Risk Management at Deutsche Börse, echoed those concerns, saying that “AI-driven cyber threats evolve rapidly.”

She noted that Anthropic’s Mythos Preview is “an AI model reportedly capable of detecting software vulnerabilities far faster than traditional tools, already identifying thousands of critical flaws across major systems.”

According to Forte, “the time needed to exploit vulnerabilities, once measured in weeks, could shrink to as little as 30 minutes.”

Testing ‘not keeping pace’

Similar concerns are emerging globally. In Australia, prudential regulator APRA recently warned banks and insurers that governance, testing and resilience capabilities are struggling to keep up with the pace of AI adoption.

“The AI revolution presents tremendous opportunities for banks, insurers and superannuation trustees to deliver improved efficiency and enhanced customer services,” said APRA Member Therese McCarthy Hockey.

Therese McCarthy Hockey

“But we cannot be blind to the risks of such powerful technology, whether in our own hands or the hands of those with malign intent.”

APRA found that “governance, risk management, assurance and operational resilience practices are not keeping pace with the scale, speed, and complexity of AI adoption.”

“The systems and processes required to safely govern AI use aren’t keeping up.”

The regulator also warned that “the volume and speed of AI assisted software development is placing strain on the effectiveness of change and release management controls.”

McCarthy Hockey further identified “gaps in the scope and coverage of security testing programmes for both AI implementation and responding to the AI augmented threat environment.”

‘The clock is ticking’

For QA and software testing teams, the emergence of GPT-5.5 Cyber and Claude Mythos represents more than a new category of AI model.

Regulators increasingly expect firms to validate how AI-enabled systems behave in production-like environments, test resilience under real-world conditions, prove governance controls are functioning, and demonstrate that vulnerabilities can be identified, remediated and evidenced at speed.

As the FCA has emphasised, “We broadly define the AI system as: the actual AI model, information on the deployment context and core risks … governance and human in the loop considerations, evaluation techniques as well as the input and output controls.”

The growing availability of cyber-focused AI models to major banks suggests those expectations are only likely to intensify.

As Elderson warned: “This is something that is game-changing. We want banks to look into this seriously. The clock is ticking.”


WHY not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS