🔐 In the space of barely 48 hours in early June, two of the world's largest economies gave very different answers to the same uncomfortable question: what do you do when a single AI model can find and exploit security holes faster than any human team alive?
On June 2, Washington asked AI labs to hand the government an early look at their most powerful systems. On June 3, Tokyo's digital minister said Japan should put those same systems to work — defending banks now, critical infrastructure next.
What Japan actually decided
On May 29, Financial Services Minister Satsuki Katayama confirmed that the Japanese government and the country's three megabanks — MUFG, SMBC and Mizuho — had obtained access to a new OpenAI model built to find and patch software vulnerabilities. Reporting identifies it as "GPT-5.5 Cyber." Katayama, who had just met OpenAI's chief strategy officer Jason Kwon, put it plainly: this was something to welcome from the standpoint of strengthening the cybersecurity of Japan's financial institutions.
Days later, on June 3, Digital Minister Hisashi Matsumoto went a step further. Letting banks use these tools was a start, he said, but the same access needs to widen to other infrastructure operators — the power, gas and telecom networks a serious cyberattack could knock out. Matsumoto is a former emergency physician who helped pioneer Japan's air-ambulance service and now also holds the cybersecurity brief.
The government is also trying to obtain access to Anthropic's Claude Mythos, the restricted model that set this whole chain in motion — though Katayama acknowledged that arrangement still has details to work out.
The model that triggered the scramble
To understand why a finance minister and a digital minister are suddenly talking about the same software, you have to start with Mythos.
Claude Mythos is Anthropic's most capable model, withheld from public release and shared only with a small set of vetted organizations precisely because of what it can do in security. In testing, it showed it could discover and exploit novel software vulnerabilities far faster than human researchers — the kind of capability that is a gift to a defender and a weapon in the wrong hands.
That dual-use problem is exactly what unsettled governments, and Japan's reflex has been to treat advanced AI as defensive infrastructure. In May, the trade ministry (METI) sat down with critical-infrastructure operators and asked power companies in particular to inventory their IT systems and report back within roughly a month. The National Cyber Security Office issued its own advisory about attacks accelerated by high-performance AI. The reasoning is blunt: if attackers will eventually hold these tools, defenders need them first.
The quieter story: a government learning to use AI at all
The cyber push sits on top of a slower shift that has been building for a year — Japan's bureaucracy actually adopting generative AI.
The Digital Agency runs an internal AI environment for civil servants with a very on-brand name: "Genai" (源内). It is a double pun — on "generative AI," and on Hiraga Gennai, an Edo-period inventor — carrying the hope that it becomes a place where AI-driven inventions gather. The agency has been adding frontier models from OpenAI to that toolkit, rolling it out across ministries, and exploring government-specific AI applications.
All of this runs under a notably light-touch legal regime. Japan's AI Promotion Act — the country's first AI-specific law — passed in May 2025 and took full effect that September. Crucially, it carries no penalties. It leans on transparency and voluntary effort by companies rather than punishment, with the stated national ambition of making Japan "the most AI-friendly country in the world" to develop and use the technology. The law grows out of the Hiroshima AI Process, the international framework Japan launched as G7 host in 2023.
The same question, three doors
Here is what makes early June 2026 worth pausing on. The same capability — frontier AI that supercharges cyber operations — produced three distinct policy reflexes within days.
The United States chose voluntarism. On June 2, an executive order set up a framework in which AI developers are asked, on a voluntary basis, to give the federal government access to "covered frontier models" up to 30 days before releasing them to other trusted partners, so the government can assess cybersecurity risk. The order explicitly refuses to create any mandatory licensing or pre-clearance. Washington's stance toward Anthropic in particular has been ambivalent — the Pentagon recently flagged the company as a supply-chain risk, even as the model it builds becomes a defensive prize elsewhere.
The European Union chose hard law. The EU AI Act, in force since 2024, hits its biggest milestone on August 2, 2026, when rules for high-risk systems and the enforcement machinery switch on. Providers of the most powerful models face obligations backed by fines that can reach a slice of global turnover.
Japan chose deployment. Rather than a new statute or a pre-release review system, Tokyo's move was operational: get defensive models into the hands of banks and infrastructure operators, quickly, under a soft-law framework that prizes speed over rules. The screening happens less through legislation than through procurement — what the government agrees to buy, and decides who else may use.
The dependency nobody has solved
The catch is hard to miss. Every model in this story — Mythos, OpenAI's cyber system — is American. Japan's defensive posture, for now, runs on frontier AI built in San Francisco.
That is the tension running through the whole region's AI strategy: lean on US models for real capability today, while pouring money into domestic alternatives for sovereignty tomorrow. It is a workable bet, but it leaves an open question about what happens if access terms change, costs climb, or the geopolitics shift.
There is a quieter domestic question, too. Wiring frontier AI into banks and power grids is one thing when the minister in charge is also the cybersecurity chief and a former ER doctor used to triage. It is another to scale that across an entire government without the missteps that usually come from moving fast.
Japan has decided the risk of moving slowly is the bigger one. Within two months, Europe's enforcement regime goes live, and the contrast will only sharpen.
In Japan, the instinct was to deploy first and regulate lightly. How is your country handling it — does your government reach first for new rules, or for the technology itself?
References
- https://www3.nhk.or.jp/news/html/20260603/k10015139871000.html
- https://www.itmedia.co.jp/news/articles/2605/29/news144.html
- https://www.nikkei.com/article/DGXZQOUB28AVE0Y6A520C2000000/
- https://www.meti.go.jp/press/2026/05/20260501001/20260501001.html
- https://www.digital.go.jp/news/e950673b-73eb-4f65-bf6a-339e4f0e7ef1
- https://www.gov-online.go.jp/hlj/ja/november_2025/november_2025-08.html
- https://www.presidency.ucsb.edu/documents/executive-order-promoting-advanced-artificial-intelligence-innovation-and-security
- https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
Global Discussion
4 comments