Japan's FSA Orders All Financial Firms to Prepare 'AI Malicious Use' Emergency Measures, Including System Shutdown Option

Japan's Financial Services Agency on the 22nd ordered all banks, securities firms, and insurers under its jurisdiction to consider emergency measures—including temporary system shutdowns—in response to the potential malicious use of the latest artificial intelligence, "Claude Mythos," developed by U.S. startup Anthropic, in cyberattacks. The extraordinary directive reflects the growing reality that AI capabilities have advanced so dramatically that traditional defense strategies may no longer suffice.
At the core of the order is a demand that financial institutions confront the possibility that even exhaustive defenses may fail to completely prevent an attack. The FSA instructed top management to take the lead in preemptively evaluating scenarios where IT systems become dysfunctional due to cyberattacks or where "systems must be proactively halted" to limit damage. It also required firms to clearly define the criteria for making such shutdown decisions.
The 'Defense vs. Offense' Dilemma Posed by Next-Generation AI
Claude Mythos is considered to possess vastly superior capabilities in discovering software and network vulnerabilities compared to conventional AI. The FSA's directive document highlighted the dual nature of this capability, noting that "while there is a risk it could be weaponized for cyberattacks, there is also the advantage that it can be used to identify flaws in existing systems and bolster defenses against attacks." The agency urged financial institutions to carry out intensive countermeasures within roughly one month.
Specifically, anticipating that AI could uncover a large number of vulnerabilities in a short time, potentially overwhelming system patching workloads, the order also calls for bolstering response personnel and reconfirming operational scopes with IT vendors responsible for system maintenance. Internet payment and online banking systems and other critical infrastructure directly tied to daily life and economic activity were designated as the highest priority for immediate action.
Heightened Alarm and Political-Level Engagement
The FSA had already convened a working group on May 14 comprised of executives from banks, financial institutions, and IT vendors to discuss the contents of this directive. Financial Services Minister Satsuki Katayama stated at a post-cabinet press conference on the 22nd that she "will continue to urge financial institutions to respond swiftly," underscoring that the government is monitoring the situation with a strong sense of crisis.
The directive emphasized that addressing next-generation AI must be treated as a critical enterprise-wide issue, not merely a technical department concern. It stressed the necessity of "implementing continuous countermeasures," indicating that one-off responses would be insufficient.
Trade-Offs with User Convenience
The most striking aspect of the order is that the FSA has explicitly endorsed "system shutdowns" as a legitimate tool, despite the direct impact on users. Normally, stable system operation is the top priority for financial institutions, and any outage risks undermining the trust of depositors and investors. However, the FSA explained that it "determined that avoiding large-scale system failures caused by attacks should take precedence." While acknowledging the potential for some level of inconvenience to users, the agency made clear it places greater priority on securing the overall stability of Japan's financial system.
Going forward, each financial institution will be forced to draft concrete procedures—based on its own system architecture and risk assessments—detailing which services to shut down, at what threshold, and who holds the authorization to do so.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.