Financial infrastructure providers have spent the past two years selling banks on AI that talks to customers and automates back-office work. FIS just did something different: it turned a frontier AI model on itself, using it to hunt for weaknesses in the software that clears payments and runs core banking for thousands of institutions worldwide. The move signals a shift in how critical financial infrastructure gets secured, from AI as a product feature to AI as an internal security control.

What FIS and Anthropic actually announced

FIS has extended its partnership with Anthropic by joining Project Glasswing, a controlled-access initiative through which Anthropic makes its frontier models available to organizations that build or maintain foundational software, specifically for defensive security work. Under the initiative, FIS is testing Mythos 5, Anthropic’s most advanced model, against its own systems, the same infrastructure that clears payments, moves money and runs core banking for institutions across the industry. The company describes the work explicitly as separate from its existing commercial AI partnership with Anthropic, which sells AI-enabled products to FIS clients. Project Glasswing is about FIS applying frontier AI to its own house.

Why the distinction matters

Most fintech AI announcements describe a vendor selling a bank a new AI-powered feature: fraud scoring, a chat assistant, an underwriting model. This is not that. FIS is the vendor here, and the customer of the security work is FIS itself. The company has framed its rationale in market terms: it applies the same security standards to its own infrastructure that it sells to its clients, on the logic that a vulnerability in the software running core banking for thousands of institutions is a systemic risk, not a single-company problem.

Advertisement

FinTech Your brand belongs here. Reach the decision-makers who read FinTech every day. Premium placements across the site and newsletter. Advertise with us

The shift: security hardening becomes a frontier-AI use case

Frontier AI models have mostly entered financial services through customer-facing or analyst-facing products: chat interfaces, document summarization, transaction monitoring. Project Glasswing points to a different application entirely, using a large model’s ability to read and reason over large, complex codebases to find security flaws before an attacker does. FIS is one of the highest-profile financial infrastructure providers to publicly test this approach on production-critical systems, which makes its participation a signal other core-banking and payments-processing vendors will be watching closely, whether or not they say so publicly.

FIS has paired the technical work with existing industry security channels, citing its engagement with FS-ISAC, the Financial Services Sector Coordinating Council, and ongoing regulatory collaboration and intelligence-sharing. That framing matters: the company is positioning AI-assisted vulnerability discovery as an addition to established, auditable security processes, not a replacement for them.

What it means for the finance leader

For a bank or fintech that relies on FIS, or on any of the handful of vendors that run similar core infrastructure, the practical question is not whether your own institution uses AI, but whether your infrastructure vendor is using it to find its own weaknesses before someone else does. Vendor security reviews and due-diligence questionnaires built around legacy penetration-testing cadences will need an update: does the vendor have an AI-assisted vulnerability discovery program, how is it governed, and how does it complement rather than substitute for third-party audits and regulatory exams.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

There is a second-order implication for procurement and risk teams. As frontier models get tested against systemic financial infrastructure, the concentration risk in a small number of core-processing vendors becomes more visible, not less. A finance leader evaluating a core-banking or payments platform should be asking how the vendor’s security posture is evolving, not just what it looked like at the last audit cycle, and should treat a vendor’s willingness to disclose participation in programs like Project Glasswing as a data point on transparency, not just a marketing line.

What is still unverified

FIS has not disclosed specific metrics on vulnerabilities identified, systems scanned, or a timeline for expanding the program beyond its current scope. The company’s announcement names no third-party auditor confirming results, which means the claim of improved security currently rests on FIS’s own account of its internal testing. Institutions relying on FIS infrastructure should expect, and can reasonably request, more specificity as the initiative matures.

How to evaluate this if you are a vendor risk or security leader

  • Ask infrastructure vendors directly whether they participate in any frontier-model security testing program, and on what systems.
  • Treat AI-assisted vulnerability discovery as a supplement to, not a substitute for, independent penetration testing and regulatory exams.
  • Watch for other core-banking and payments vendors to follow with similar disclosures; a first mover in this specific application tends to be followed quickly once the approach is validated publicly.

The broader signal is that frontier AI’s most consequential near-term role in financial services may not be the chat interface a customer sees, but the security layer working underneath the systems that move the world’s money, a use case that FIS and Anthropic have just made a matter of public record rather than a quiet internal project. Other providers governing this same category of infrastructure, from payment processors to core-banking platforms, are the ones worth watching for the next disclosure, since the same systemic-risk logic FIS cited applies to all of them equally. Institutions that have already moved to governable, auditable AI for compliance work are likely to ask the same governance questions of this security use case: not just whether the model works, but whether its findings and its limits can be explained to a regulator.

Source: FIS