Japanese banks adopt AI to fight cyber threats

Japan’s largest banks are adopting artificial intelligence to counter cyberthreats that outpace human analysts.
Mizuho, MUFG, and Sumitomo Mitsui Banking Corporation received government clearance to use advanced AI tools from U.S. tech companies, including Alphabet’s Google and Anthropic.
AI models designed to find flaws before attackers do
The banks will deploy Anthropic’s Claude Mythos, a model that identifies and fixes software vulnerabilities almost instantly. That speed carries a risk: hackers could use the same technology to create exploits just as quickly.
OpenAI has also pledged future access to its GPT-5.5-Cyber model for select Japanese financial institutions. The change in strategy moves away from blocking every attack toward detecting and containing them faster.
Finance Minister Satsuki Katayama stated the issue affects all companies and economic actors. She emphasized making sound choices that serve the national interest.
Katayama pointed out that Alphabet’s existing data centers in Japan gave the company an edge in the partnership. The government’s decision came after a joint emergency directive issued in May by the Japan Financial Services Agency and the Bank of Japan, which warned that traditional monitoring methods lag behind AI-driven threats.
Related: Alibaba shares surge on AI chip unit plans
Regulators push for zero-trust security
The May 22 directive required banks to adopt a model that treats every access request as potentially malicious. It also advised allocating resources based on risk instead of trying to protect all systems equally.
The step followed international warnings, including one from the UK AI Security Institute and a financial stability review by the Banco de España. Both noted the widening gap between attack speed and human response times.
Japan’s Project YATA-Shield, a government cyber defense initiative, has also sped up AI tool adoption. The project focuses on improving rapid detection and recovery rather than absolute prevention.
This method differs from older security models that relied on perimeter defenses. Now, resilience depends more on how quickly a breach can be contained and systems restored.
The reliance on U.S. technology raises concerns about long-term dependence.
A single successful attack on a major bank could disrupt payments or trigger market instability. With AI attacks growing more advanced, Japan’s financial sector is betting that the best defense is an equally capable offense.