US Grants Access to Anthropic’s Claude Mutos for Three Japanese Megabanks
Japan secures permission to use Claude Mutos in cybersecurity work, allowing three megabanks to evaluate the AI model for system vulnerability detection and defensive measures.
The U.S. government has authorized access to Anthropic’s high-performance AI model Claude Mutos for three of Japan’s megabanks, multiple people familiar with the matter said, opening the way for the banks to test the model for cybersecurity uses. Claude Mutos, released this spring and previously limited by Anthropic because of concerns it could identify system weaknesses, is now expected to be evaluated or deployed to scan bank systems for vulnerabilities. The decision follows a period in which the U.S. moved to restrict the model’s use abroad and Anthropic suspended external access.
U.S. Decision Reverses Earlier Export Controls
The U.S. government initially designated Claude Mutos as subject to export controls in June to prevent potential misuse, ordering that the model not be made available to foreign users. Anthropic halted provision of the model to non-U.S. entities at that time, even limiting access for some domestic organizations. Sources say the new authorization specifically permits the three Japanese megabanks to obtain access under terms set by U.S. authorities.
The reversal comes after diplomatic engagement and technical discussions, according to people briefed on the exchanges. Japanese officials had lobbied the U.S. administration to allow financial institutions to use Claude Mutos for cyberdefense, arguing banks need advanced tools to identify and remediate system vulnerabilities before adversaries can exploit them.
Claude Mutos’ Capabilities and Reasons for Caution
Anthropic launched Claude Mutos earlier this year; the model demonstrated an unusually strong ability to analyze complex systems and surface hidden weaknesses. Those capabilities prompted the company to keep the model’s release limited, citing the risk that the same strengths could be turned to malicious ends. Security experts have warned that tools able to discover software or configuration flaws can accelerate cyberattacks if access is not tightly controlled.
Anthropic’s cautious approach and the U.S. export control designation reflected a wider regulatory concern about dual-use AI: models that offer valuable defensive functions can also reduce the effort required to plan and execute cyber intrusions. The U.S. move in June aimed to reduce that risk by restricting foreign access, but Washington has since made narrow exceptions under controlled conditions.
Banks Eye Vulnerability Detection and Full Evaluations
The three megabanks now face decisions about how to integrate Claude Mutos into their operations. Senior executives and security teams plan to test the model’s performance in controlled environments to gauge its ability to find software bugs, misconfigurations, and other systemic weaknesses. Sources say initial uses are likely to focus on internal vulnerability assessments rather than live scanning of customer-facing systems.
Officials at the banks will also assess compliance, auditability, and the legal implications of using a foreign-developed AI tool in critical infrastructure. Financial regulators in Japan have emphasized the need for transparency around tools that affect operational resilience, and banks will need to demonstrate robust safeguards before any broad deployment.
Government Role and Diplomatic Negotiations
Tokyo actively sought access to Claude Mutos, according to people involved in the discussions, pressing Washington to permit banks and other critical institutions to use the model for defensive purposes. The effort reflects growing recognition among industrialized countries that advanced AI tools can strengthen cyber defenses if shared under appropriate safeguards.
The U.S. decision appears to involve case-by-case approvals rather than a blanket lifting of export controls. That approach allows Washington to set conditions—such as limiting the scope of use, imposing monitoring requirements, or restricting downstream sharing—to try to balance security risks with legitimate defensive needs.
Security Experts Urge Strict Controls and Auditing
Cybersecurity specialists caution that even when used for defensive work, advanced AI models require strict governance to avoid inadvertent harm. They recommend comprehensive logging of queries, independent auditing of results, and staged testing that isolates sensitive systems. Such measures help ensure that vulnerability findings are handled responsibly and not exposed in ways that could be weaponized.
Banks will also need to plan for the operational implications of AI-driven findings, including prioritizing remediation and coordinating with regulators and customers where necessary. Effective incident-response processes and legal compliance frameworks remain crucial when novel technologies are introduced into critical financial infrastructure.
Implications for AI Governance and Industry Access
The case of Claude Mutos highlights the tension between securing powerful AI tools and enabling their beneficial uses. Narrow permissions for trusted institutions could become a model for future decisions about export-controlled AI systems, with governments weighing national security risks against the resilience gains for critical sectors.
Industry groups and policymakers will be watching how the three megabanks implement the model and whether the safeguards adopted by both governments and companies can prevent misuse while permitting constructive applications. The outcome may influence how other nations seek access to advanced AI under export-control regimes.
The banks have begun preparatory work to integrate Claude Mutos into controlled testing environments and plan further consultations with regulators and cybersecurity partners before any operational rollout.