Notice & Comment

A Procedural Framework for Frontier-AI Cyber Risk Convenings: The Case of Anthropic’s Project Glasswing

On April 7, 2026, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened the chief executives of five systemically important banks to brief them privately on Claude Mythos Preview, a frontier AI model that Anthropic declined to release to the public. Anthropic made this decision upon finding in its internal testing that the model could discover latent software vulnerabilities at a scale and speed beyond any existing cybersecurity tool or human effort. Instead of launching the model to the public, Anthropic collaborated with the Federal government to make it available to a small, vetted set of companies for defensive purposes through a restricted AI software access program, entitled Project Glasswing. The April 7 convening disclosed these AI capabilities and their wide-ranging implications for the critical software which the country’s largest banks, along with firms across manufacturing, infrastructure, energy and healthcare, use to conduct core business operations. Though later reported by major media outlets, the meeting produced no rules, no written record, and no public statement.

Going forward, federal financial regulators in coordination with the Cybersecurity and Infrastructure Security Agency (CISA) should issue joint interagency guidance establishing a minimum procedural framework for such convenings: identifying the conditions that warrant one, specifying which institutions must attend, requiring a contemporaneous documentary record, and articulating the downstream obligations of attendees.

The April 7 Convening

Before the public launch of Project Glasswing, Anthropic had been in active consultations with the CISA regarding its program for providing select institutions supervised access to Mythos for defensive cybersecurity purposes. Furthermore, the company had privately briefed senior federal officials on the capabilities of its new frontier model. These consultations were motivated by the internal testing performance of Claude Mythos Preview, which had autonomously identified thousands of previously unknown vulnerabilities across every major operating system and web browser, including a software defect that had remained undetected in foundational software for 27 years. What made Anthropic’s findings alarming was not any single flaw but the pattern they revealed: Serious cybersecurity weaknesses had gone unnoticed in the software that financial, critical infrastructure, energy, and healthcare systems depend on. A frontier model like Mythos can surface them all at once.

Anthropic’s assessment was that the cybersecurity capabilities of this new class of frontier models could expose backdoors, vulnerabilities, and defects in major software packages that are used by key U.S. corporations, allowing malicious actors to exploit those weaknesses. Essentially, Mythos was deemed too risky and dangerous for general release. Instead of releasing the model, Anthropic created Project Glasswing: a restricted-access consortium through which a curated set of institutional partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, NVIDIA, and Palo Alto Networks received supervised access to the model for defensive security purposes, thereby allowing them to identify and remediate any backdoors and vulnerabilities that had remained latent and undetected by cybersecurity experts.

Federal regulators responded on April 7, 2026—the same day that Anthropic publicly unveiled Project Glasswing—by convening the chief executives of Bank of America, Citigroup, Goldman Sachs, Morgan Stanley, and Wells Fargo at Treasury headquarters (JPMorgan’s CEO had been invited but was unable to attend). The session was unannounced and generated no official output of any kind. Neither the Treasury nor the Federal Reserve released any account of what had been communicated, and both declined to respond to press inquiries. The attending institutions departed in possession of significant information from the two most senior financial regulators in the country, without any indication of what legal or operational obligations that information was intended to generate.

Legal Exposure Without Legal Form

The informality of the April 7 convening does not eliminate its legal consequences. Rather, it ensures that those consequences will be resolved without a contemporaneous record of what happened. Thus, three bodies of doctrine will be implicated if a significant cyber incident subsequently occurs at any institution that attended it.

First, under the board oversight framework established in In re Caremark International Inc. Derivative Litigation and extended in Marchand v. Barnhill and its successors, boards of Delaware corporations bear affirmative duties to maintain reporting systems through which material operational risks can be identified and transmitted upward. A board of directors satisfies these duties by making a good-faith effort to ensure that a monitoring system exists for a company’s most significant risks (including cybersecurity risks), and, critically, that it captures, escalates, and addresses the most credible warning signs. Marchand illustrates that a company’s board cannot ignore a red flag: once the information signaling a central risk surfaces, the oversight system must register it and the board must act. A sustained failure to maintain the monitoring system or to heed such a signal can expose the directors to personal liability.

Because no comparable set of facts has previously arisen, no court has yet resolved whether a direct warning from the Secretary of the Treasury and the Federal Reserve Chair constitutes the kind of red flag that a Marchand-compliant oversight system must register and the board must act upon. That unresolved question does not protect attending institutions against derivative claims; it merely ensures that any resolution will occur without the documentary record that would allow either party to establish what the meeting conveyed or what a board exercising appropriate oversight would have been expected to do in response.

Second, the SEC’s 2023 cybersecurity disclosure rule requires public companies to disclose material cybersecurity risks and to describe the board-level processes through which such risks are overseen. A private governmental briefing regarding a specific cyber threat from the Treasury Secretary and the Federal Reserve Chair is a credible source of material risk information. Without a written record, the disclosure counsel has no basis for evaluating whether existing disclosures remain adequate, and management has no documentation with which to establish that its assessment of materiality was considered rather than inadvertent. Should a subsequent incident give rise to investor claims that public filings failed to reflect information the chief executive received at the Treasury, the absence of any record of the convening substantially compromises the institution’s capacity to demonstrate the adequacy of its disclosure process.

Third, Section 5 of the FTC Act, as construed in FTC v. Wyndham Worldwide Corp., reaches security practices that are unreasonable in light of the information available to the firm. A warning delivered in person by the Treasury Secretary and the Federal Reserve Chair plainly enlarges the information available to an attending institution. Should that institution later suffer a cybersecurity breach that could have been prevented by heeding the warning, the FTC or a plaintiff borrowing the Wyndham standard could contend that its cybersecurity posture was unreasonable precisely because it failed to act on a warning received at the highest level. Here too, the absence of any record of what was conveyed leaves the corporation exposed and unable to show what it reasonably understood the warning to require.

Across all three legal doctrines, the practical consequence of informality is that legal exposure will have to be resolved in adversarial proceedings, shaped by incomplete secondary evidence rather than by any official record.

The Case for Interagency Guidance

Precedent establishes that informal cyber-supervisory practices eventually require documentary formalization. The interagency incident notification rule finalized by the OCC, the Federal Reserve, and the FDIC in 2021 emerged from years of informal coordination over inconsistent cyber-incident reporting. The agencies eventually concluded the practice required the uniformity that only a formal rule could supply. The Transportation Security Administration’s (TSA) pipeline cybersecurity directives, issued after the Colonial Pipeline ransomware attack of May 2021, illustrate the costs of delayed formalization: emergency measures issued without adequate procedural specificity required iterative revision over two subsequent years. The April 7 convening is more acutely in need of formalization than either precedent because both the 2021 banking rule and the TSA directives responded to incidents with public factual records that courts and regulated parties could independently assess. The April 7 meeting was convened in response to a private technical briefing regarding an AI model’s capabilities, the factual basis of which remains undocumented, which leaves the grounds for the warning unverifiable by those most affected by its legal consequences.

Acting jointly with CISA, the Treasury, the Federal Reserve, the OCC, and the FDIC should therefore issue interagency guidance establishing a minimum procedural framework for frontier-AI cyber risk convenings. A joint interagency statement or supervisory letter is the appropriate instrument: it produces clear supervisory expectations without the procedural demands of notice-and-comment rulemaking, while preserving the confidentiality that makes private supervisory engagement viable. The guidance should address four elements.

First, it should articulate the conditions warranting a convening, including a credible technical assessment that an AI frontier model’s capabilities in vulnerability discovery or exploitation materially exceed the prior technological baseline, evidence that those capabilities have been exercised against software in active use at supervised institutions, and a determination that existing supervisory channels are inadequate. Articulating these conditions in advance would neither oblige the agencies to convene whenever the conditions are met nor limit their discretion to convene in other circumstances. It would simply give institutions fair notice of the kind of cybersecurity threat likely to prompt a convening, so they can prepare to respond appropriately.

Second, the agency guidance should specify participants by requiring the personal attendance of each institution’s senior executive officer. It should also define the mandatory institutional categories: at minimum, systemically important U.S. banks, other Financial Stability Oversight Council-designated systemically important financial institutions, and major organizations in the energy and healthcare sectors that the convening agencies identify based on exposure.

Third, it should require the convening agencies to produce a written summary distributed to attending organizations within a defined period. Confidential treatment under the bank examination privilege is available and appropriate, and the proposal requires no public disclosure.

Fourth, it should require attending organizations to transmit the summary to their board-level risk committee, document their responsive analysis, and incorporate the convening’s findings into their periodic cybersecurity risk assessment.

Conclusion

A carefully developed objection to this proposal might be that agencies have sound reasons to prefer undocumented supervisory engagement: written records are discoverable, they generate quasi-precedent, and they constrain future supervisory discretion. The difficulty is that this discretion has already been substantially compromised by the convening itself. The chief executives who attended departed knowing that they had received significant governmental communication, and their institutions’ legal advisers are currently constructing their own assessments of what it required, without input from the agencies that convened the meeting. Choosing not to produce a document only transfers the work of interpretation to private reconstructions the agencies cannot review or correct.

The April 7 convening is the first documented instance of a practice that will recur as AI capabilities continue to develop, and not only in financial services. Energy, healthcare, and transportation will each face the same issue. Banking received the first warning without the procedural architecture that would give it legal coherence. The framework proposed here is the minimum intervention required to supply that architecture. It does not expand the substantive authority of any agency, alter the obligations of any regulated institution, or require any public disclosure. It establishes only that when regulators summon institutions and deliver warnings, they should do so in a manner that generates a documentary record legible to the boards, counsel, and courts that will ultimately determine what those warnings required.

Ovais Rehman Shah is a Master’s degree candidate at Cornell Law School and holds an M.S. in Data Science and Applied Analytics from Columbia University.